Certain API endpoints in privacyIDEA return overly specific error messages that could allow attackers to…
Certain API endpoints in privacyIDEA return overly specific error messages that could allow attackers to…: a task in LegoFlow-SWE (Harbor dataset). We need the ability to hide those specific error messages through a policy‑based mechanism. When the relevant policy is active, the endpoints should…
The task
We need the ability to hide those specific error messages through a policy‑based mechanism. When the relevant policy is active, the endpoints should return **generic error messages** that do not reveal internal details. The HTTP status codes must remain the same whether the policy is active or not.
Part of Lego-X/LegoFlow-SWE.