3 ms·
also don’t be shy: * without disclosing sensitive info, add details to error messages * where possible make errors actionable, eg hint at solutions
by thund 4y ago
also don’t be shy:
* without disclosing sensitive info, add details to error messages
* where possible make errors actionable, eg hint at solutions
- EvanAnderson 4y agoStrong agreement. As a long-time sysadmin I despise "shy" error messages. Don't make me break out strace / Process Monitor / etc to figure out what specific file your generic "File not found" message is referring to.
- ryandrake 4y agoOr, the currently fashionable, yet maddeningly useless: "Something went wrong" with no other explanation. Thanks, error message writer, for absolutely nothing.
- e-clinton 4y agoReally? I’ve always felt like too much detail could further empower a potential attacker.
- EvanAnderson 4y agoI would concede that there is a distinction between error messages meant for the general public vs. sysadmins. Make sure the log the sysadmin sees has actionable information in it, please!
- blooalien 4y agoI've always felt that user-facing error messages should be simple, clear, to-the-point, and should include a simple explanation how to contact the author, and where to find and send any relevant "user-local" log information which might be helpful.