SurePassID Identity Provider

Write Sensitive Diagnostic Trace Implementation & Usage


1. Purpose

WriteSensitiveDiagnosticTrace(string message) is a config-gated diagnostic logging method. It behaves like the existing WriteDiagnosticTrace, except the message is written only when an operator explicitly opts in via a config parameter. It exists to keep PII and security tokens (full SAML assertions, signed responses, and raw AuthnRequests) out of production trace logs by default, while still allowing deep debugging on demand.


2. Implementation

How it works

  1. Reads the boolean config parameter Saml2.TraceSensitiveData (default false). via SurePassConfiguration.GetConfigParameterBool(...).
  2. If the flag is false (or absent) → returns immediately (no-op, nothing logged).
  3. If the flag is true → writes to trace file.

3. Configuration parameter

Parameter Type Default Effect
Saml2.TraceSensitiveData bool false When true, full SAML assertion/response/request bodies are written to trace logs. When false/absent, those specific traces are suppressed.
  • Resolved through the standard SurePassConfiguration.GetConfigParameterBool(name, defaultValue) mechanism (same pattern as other Saml2.* flags such as Saml2.RemoveSsoGroupPrefix).
  • Secure by default: omit the setting entirely in production to keep sensitive traces off.
  • Enable only temporarily for troubleshooting, then remove/disable.

Note: This flag only controls the sensitive payload traces. Normal non-sensitive flow/status traces (via WriteDiagnosticTrace) are unaffected and continue to log whenever tracing is enabled.


4. Usage guidance

Use when the message contains, or may contain:

  • Full or partial SAML assertions / responses / requests
  • Bearer tokens, session tokens, security artifacts
  • PII (subject/NameID, email, user attributes)

Use the normal trace when the message is operational/flow-only:

  • Method entry/exit markers, decision branches, status, non-sensitive identifiers.

5. Verification checklist

  • With Saml2.TraceSensitiveData unset/false: trace logs contain flow/status lines but no assertion/response/request XML.
  • With Saml2.TraceSensitiveData=true: full payloads appear (for debugging only).
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com