All threads / Overly Detailed Internal Error Messages

Ask A Question

Notifications

You’re not receiving notifications from this thread.

Overly Detailed Internal Error Messages

Chong Hwi asked in Rails

Errors which previously caused stack traces to be shown now only show the following generic error:
"The page you were looking for doesn't exist." However, the server responded with the response code "500 Internal Server Error". This is dangerous as an attacker can deduce the kind of input that causes the server to behave erratically.

I need help for the configuration to keep the generic error, but respond with response code 2XX or 3XX to close this Finding.

Join the discussion

Want to stay up-to-date with Ruby on Rails?

Join 38,558+ developers who get early access to new tutorials, screencasts, articles, and more.

    We care about the protection of your data. Read our Privacy Policy.

    logo Created with Sketch.

    Ruby on Rails tutorials, guides, and screencasts for web developers learning Ruby, Rails, Javascript, Turbolinks, Stimulus.js, Vue.js, and more. Icons by Icons8

    © 2020 GoRails, LLC. All rights reserved.