Expose only the data needed by the frontend
Do not expose unnecessary data in your HTTP responses.
With the astronomical rise of vibe coding and non-technical folks shipping software, it’s become apparent that now more than ever, we need to be aware of very insecure software flooding the market.
One of the mistakes I’m seeing now and again is developers exposing too much data (than what’s required in the frontend).
There’s no excuse for having a record’s updated_at, deleted_at and created_at fields in your API responses if the
frontend doesn’t need them.

Response from a blogging platform’s API showing unnecessary fields exposed
This is unfortunately a very common mistake that more often than not leads to security vulnerabilities and performance issues.
APIs are doorways to the data you’re storing and ultimately to your client’s business as well. They are a very detailed description of the client’s business processes, as well.
How does business xyz handle my data when I sign up? How do they process payments? How do they handle refunds?
For example, by looking at a certain fintech startup’s API responses, I was able to map at the different processes and verifications they have in place while handling a payment.
Take an instance of the image above (it is from a blogging platform’s API). The API response contains data in this format:
| |
Suppose I’m a malicious user and I want to read a premium article without paying for it. What could I do?
I could get my authentication token, then try sending a PATCH request to the articles endpoint changing the isPremium field to
true. I could keep doing this for all premium articles that I want to read.
We certainly don’t need to expose some fields for example createdAt, updatedAt, authorId, categoryId, etc. if
they are not being used in the frontend.
How do we achieve this?
We can reduce the fields to the absolute minimum required by the frontend. For example:
| |
This can be achieved by preparing response structures or using serialization libraries that allow you to define which fields to include or exclude in the API responses.
For example in Go, you can declare response structs that only include the necessary fields:
| |
Then map your data models to these response structs before sending them to the frontend.
| |
This way, we can be sure that only the necessary data is sent to the frontend, reducing the risk of exposing sensitive information.
In any case, you have a software project that you would like us to discuss, reach out via hello@terraconsults.co