What’s a bit scary is that depending on abstraction (ORM / service layer), it could be as simple as the difference of returning User instead of UserResponse.
The engineers could have easily known better and it was a bad autocomplete / model choice with tests that only asserted the needed fields were there.
It’s easy to bash the devs on how egregious this was, but depending on the system very little might need to “go wrong” for this to happen.
Curious what kinds of strategies other folks use to protect against this.
Annotations / lint rules for using models with sensitive data? Tests that check and fail on fields that shouldn’t be there? Comprehensive / sensitive tests for checking for sensitive fields?