Log the state transition and a safe correlation identifier before logging the payload. A swap failure rarely requires every authentication header, signature and wallet-related field to appear in a general-purpose log stream.
OWASP's logging guidance identifies sensitive material that should be excluded or protected. For swap applications, treat API secrets, passphrases, private keys, seed phrases and reusable signed orders as particularly important exclusions.
Keep a small diagnostic record
A proposed failure event contains timestamp, application version, provider, chain, operation stage, documented error code, latency and request ID. If a payload is necessary for a hard-to-reproduce problem, store a restricted reference with a retention policy rather than copying it into every analytics system.
Public blockchain data still deserves thoughtful handling. Linking a wallet address to an IP address, account email or browsing session creates a new association. Use only what the operational question requires.
Redact before serialization
Redaction at the display layer is too late if the raw object already reached a log collector. Apply an allowlist when constructing events. Handle nested fields and exception objects, because HTTP libraries often attach complete request configurations to errors.
Do not trust remote error text as safe log formatting. Bound its length and neutralize control characters so a token name or upstream message cannot fabricate extra log records.
Verify the negative requirement
Run fixtures containing obvious synthetic secret markers in headers, request bodies and nested exceptions. Inspect captured logs and exported traces for those markers. Also confirm that useful request IDs remain available; deleting every detail may protect secrets but leave incidents impossible to diagnose.
Revisit the policy when adding a new provider or signing mode. A field called payload can change from harmless route metadata to a transferable authorization artifact.
Sources & verification (1)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- Logging Cheat Sheet
Redaction, sensitive data and safe logging
https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html