Have your responses in the form of
res.status(403).send({ success: false, msg: 'publish-post-error/unauthorized-token' });
Why? idk :p
It just helps reading the messages in the front end to have shorter but more descriptive messages. Sometimes you won't work as full stack...