Or is there more there than authorization that I should be thinking about?
(Obviously I'm not talking about logging cleartext passwords, which don't belong in the database either.)
Or is there more there than authorization that I should be thinking about?
(Obviously I'm not talking about logging cleartext passwords, which don't belong in the database either.)
Unless there is a valid use case for logging PII (and I can’t think of any which can’t be engineered around) then I think it’s best to avoid it in principle.
I think of it as the same as logging passwords, keys or tokens.
Second is potential for DDoS (either intentionally or unintentionally).
Third is possibility of "oopsies" via me intentionally or unintentionally including my passwords/sensitive info/what have you in the POST body. Now you have to add branch to look for and scrub sensitive info in your logger -- otherwise my PII has now been logged (and if I were a massive asshole looking for a quick payday, I could throw up a fuss).
It's fine in dev, but shouldn't be in prod. Too much liability.