Description
debugger statements or temporary logs of request data left in production may expose internal state, personal information or authentication flows. A debugger statement may pause execution when a debugger is attached and active.
Potential impact
- Sensitive request data may appear in logs or console output.
- Debugger breakpoints may unexpectedly interrupt production processing.
Remediation
- Remove
debuggerstatements and temporary debug logs from production code. - Use structured logging and secret-redaction policies for diagnostics that are still needed.
Examples
Before
javascript
app.get("/profile", (req, res) => {
console.log("profile request", req.body);
res.end();
});
After
javascript
app.get("/profile", (req, res) => {
auditLogger.info({ userId: req.session.user.id }, "profile viewed");
res.end();
});
Explanation:
- Before: Debug logging can expose the request body and sensitive internal information. A leftover
debuggerstatement can also pause execution when a debugger is active. - After: Only the required event and user identifier are logged instead of the entire body. An authenticated session and
auditLoggerare assumed. User identifiers may also be personal data, so limit log access and retention.