Secure error handling
Safe errors reveal useful client information without internal details.
What it is
Safe errors reveal useful client information without internal details.
When to use it
Translate known errors; report unexpected ones privately.
Syntax
// Bad: return response()->json(["error" => $e->getMessage()]);
// Good: stable safe message + request IDExample
try {
$service->perform($input);
} catch (KnownConflict $e) {
return response()->json(["error" => "operation_conflict"], 409);
}
// Unexpected exceptions propagate to Laravel reporting.
// Keep APP_DEBUG=false for sensitive environments.Common mistakes
Do not catch every exception and return success; logging the entire exception can still expose secrets.