Return sanitized error messages for 4xx/5xx; log full stack traces server-side only and never expose them to clients.
Why This Matters
Leaking stack traces, SQL, file paths, or framework versions hands attackers a map of your internals and aids targeted exploitation.
Related Rules
Catch this automatically on every PR
BeforeMerge scans your pull requests against this rule and dozens more. Get actionable feedback before code ships.