FirstHack Learn
Log in Sign up free
Lessons in this course 0/6 All courses Secure Coding Practices

Cyber Security

Progress0 / 6 lessons
  1. 1. Never trust user input
  2. 2. SQL injection and parameterised queries
  3. 3. XSS and output encoding
  4. 4. Secrets management in code
  5. 5. Dependency and supply-chain hygiene
  6. 6. Logging and error handling without leaks

Courses › Secure Coding Practices

Logging and error handling without leaks

Tell the user nothing useful, tell your logs everything, and keep secrets out of both.

12 min read · Lesson 6 of 6 · Pro

Two audiences, two messages

When something fails, two different people need to know, and they need very different things.

The user needs to know it failed, that it was not their fault, and what to do next. Nothing more.

The developer needs the stack trace, the input, the request id, the time, and enough to reproduce it.

Most security leaks in error handling come from sending the developer's message to the user.

What a leaked error gives away

The rest of this lesson is Pro

The free lessons of Secure Coding Practices finish what they start — read those first if you have not. This one goes further, and it is part of the paid half.

A pass opens the paid lessons of every course, the mock test papers and the company-wise series. It ends on its own date; nothing renews by itself.

Get a pass — from ₹29 for 7 days

Already bought one? Log in.