3 ms·
Just today I was writing a json response to an incorrect login. I had the option to discern and inform that the username was not correct, that the password was
by J_cst 3y ago
Just today I was writing a json response to an incorrect login.
I had the option to discern and inform that the username was not correct, that the password was not correct, or both were not correct.
I deliberately decided that I'd code and supply a single error message stating that there were 'something wrong with the credentials supplied'. So I stayed generic in order not to give additional info to any malicious user... so I believe there's at least one good reason to use a generic error message. Am I wrong?
- BoppreH 3y agoThat's ok, though I usually don't bother hiding this type of information. It's very hard to build an API where there's not a single endpoint that reveals whether a user exists or not (can I register with that email? can I send it a message? can I load its avatar?). And the user experience is affected, especially if they have multiple usernames.