Security
RespKit never includes the raw value of err.Error() in a client message by default. Unrecognized errors receive the general INTERNAL_ERROR code and status 500. Use stable domain errors instead of exposing raw messages from databases or external providers.
Keep debug messages disabled in production
resp.WithExposeInternalErrors(true) adds the original error text as debug_message. An error can contain SQL queries, credentials, internal paths, hostnames, or personal data.
// Use only in an isolated local development process.
api, err := resp.New(resp.WithExposeInternalErrors(true))Do not enable this option on an internet-accessible server or based on a request header or user input. Prefer structured server-side logging with appropriate access controls.
Report a security issue
Use GitHub's private reporting form or email m.saleh.solahudin@gmail.com. Include the affected version and steps to reproduce when possible. Do not publish credentials, user data, production logs, or exploit details in a public issue.
Dependabot alerts are enabled for the repository. Maintainers should review alerts for every module, including dependencies used only by integration tests.
