Improper error handling in parameters url, w, and q (unauthenticated and wallet-connected)
Malformed values supplied via url, w, and q surfaced specific Next.js error strings ('q parameter must be a number between 1 and 100', 'requested resource isn't a valid image', and similar) that leaked implementation details to anyone probing the surface.
Description
Malformed values supplied via the url, w, and q parameters returned specific error strings disclosing internal validation rules and framework details:
"q" parameter (quality) must be a number between 1 and 100
"w" parameter (width) of 6400 is not allowed
The requested resource isn't a valid image.
These messages disclose internal validation rules and framework details that accelerate reconnaissance for follow-on probing.
Impact
Information disclosure. Lowers the cost for an attacker to map the validation surface and craft follow-on payloads.
Recommendation
Normalize all validation error responses to a single safe schema (generic message, no field-specific internals leaked). Catch unexpected exceptions globally and return a controlled 4xx/5xx with no leakage. Log full traces server-side, not in client responses.
Dedprz: Acknowledged. Zealynx: Acknowledged.