Putting detailed REST error message in HTTP Warning header, good/bad idea?

前端 未结 6 1222
鱼传尺愫
鱼传尺愫 2020-12-29 01:52

We are developing a standard REST service using HTTP status codes as its response code if something went wrong. (e.g. invalid user input would return \"400 Bad Request\" to

6条回答
  •  青春惊慌失措
    2020-12-29 02:13

    Wherever you put your feedback, whether in the message body (content) or in a Warning header, be careful to avoid giving any information that might be helpful to an attacker doing penetration testing on your system.

    Sometimes less info is better.

提交回复
热议问题