Courses ›
Secure Coding Practices
Logging and error handling without leaks
Tell the user nothing useful, tell your logs everything, and keep secrets out of both.
12 min read
·
Lesson 6 of 6
·
Pro
Two audiences, two messages
When something fails, two different people need to know, and they need very different things.
The user needs to know it failed, that it was not their fault, and what to do next. Nothing more.
The developer needs the stack trace, the input, the request id, the time, and enough to reproduce it.
Most security leaks in error handling come from sending the developer's message to the user.
What a leaked error gives away
The rest of this lesson is Pro
The free lessons of Secure Coding Practices finish what
they start — read those first if you have not. This one goes further, and it
is part of the paid half.
A pass opens the paid lessons of every course, the mock test papers
and the company-wise series. It ends on its own date; nothing renews by itself.
Get a pass — from
₹29 for 7 days
Already bought one? Log in.