Debug code left in production

Debug code left in production

Description

debugger statements or temporary logs of request data left in production may expose internal state, personal information or authentication flows. A debugger statement may pause execution when a debugger is attached and active.

Potential impact

  • Sensitive request data may appear in logs or console output.
  • Debugger breakpoints may unexpectedly interrupt production processing.

Remediation

  • Remove debugger statements and temporary debug logs from production code.
  • Use structured logging and secret-redaction policies for diagnostics that are still needed.

Examples

Before

javascript
app.get("/profile", (req, res) => {
  console.log("profile request", req.body);
  res.end();
});

After

javascript
app.get("/profile", (req, res) => {
  auditLogger.info({ userId: req.session.user.id }, "profile viewed");
  res.end();
});

Explanation:

  • Before: Debug logging can expose the request body and sensitive internal information. A leftover debugger statement can also pause execution when a debugger is active.
  • After: Only the required event and user identifier are logged instead of the entire body. An authenticated session and auditLogger are assumed. User identifiers may also be personal data, so limit log access and retention.

References