Pro tip: caught my own API leaking keys in error responses after a client pinged me at 11pm
A client emailed me at 11pm saying their scanner lit up on our staging endpoint. Turned out our error handler was dumping the full request object, including the auth header, straight into the 500 response body. Wrapped it in a sanitizer that strips headers before logging and we were clean by 2am. Anyone got a good checklist for catching stuff like this before a customer does?