Field Manual PHP / Laravel reference
← Security

Secure error handling

Safe errors reveal useful client information without internal details.

What it is

Safe errors reveal useful client information without internal details.

When to use it

Translate known errors; report unexpected ones privately.

Syntax

// Bad: return response()->json(["error" => $e->getMessage()]);
// Good: stable safe message + request ID

Example

try {
    $service->perform($input);
} catch (KnownConflict $e) {
    return response()->json(["error" => "operation_conflict"], 409);
}
// Unexpected exceptions propagate to Laravel reporting.
// Keep APP_DEBUG=false for sensitive environments.

Common mistakes

Do not catch every exception and return success; logging the entire exception can still expose secrets.

Related topics

Null handlingError responsesError handling