eliminate all errors written to browser

2 views
Skip to first unread message

David Hoover

unread,
Nov 24, 2015, 12:07:05 PM11/24/15
to genome...@soe.ucsc.edu
Is there any way of completely eliminating the writing of all errors to the browser? That is, only log to Apache log, but simply to give a 500 error to the browser? We need to prevent cross-site scripting attacks.

David Hoover
HPC @ NIH

Luvina Guruvadoo

unread,
Dec 1, 2015, 2:41:07 PM12/1/15
to David Hoover, genome...@soe.ucsc.edu
Hello David,

Thank you for the suggestion. One of our engineers has implemented a temporary solution that will go out with our next software release scheduled for December 15th. This will allow you to add an option to your hg.conf which will show 500 errors instead of "very early" error messages. We can notify you once this has been released.

If you have any further questions, please reply to genome...@soe.ucsc.edu. All messages sent to that address are archived on a publicly-accessible forum. If your question includes sensitive data, you may send it instead to genom...@soe.ucsc.edu.

- - -
Luvina Guruvadoo
UCSC Genome Bioinformatics Group


--



Reply all
Reply to author
Forward
0 new messages