SurePassID Identity Provider
Write Sensitive Diagnostic Trace Implementation & Usage
1. Purpose
WriteSensitiveDiagnosticTrace(string message) is a
config-gated diagnostic logging method. It behaves like
the existing WriteDiagnosticTrace, except the message is
written only when an operator explicitly opts in via a
config parameter. It exists to keep PII and security
tokens (full SAML assertions, signed responses, and raw
AuthnRequests) out of production trace logs by default, while still
allowing deep debugging on demand.
2. Implementation
How it works
- Reads the boolean config parameter
Saml2.TraceSensitiveData(defaultfalse). viaSurePassConfiguration.GetConfigParameterBool(...). - If the flag is
false(or absent) → returns immediately (no-op, nothing logged). - If the flag is
true→ writes to trace file.
3. Configuration parameter
| Parameter | Type | Default | Effect |
|---|---|---|---|
Saml2.TraceSensitiveData |
bool | false |
When true, full SAML assertion/response/request bodies
are written to trace logs. When false/absent, those
specific traces are suppressed. |
- Resolved through the standard
SurePassConfiguration.GetConfigParameterBool(name, defaultValue)mechanism (same pattern as otherSaml2.*flags such asSaml2.RemoveSsoGroupPrefix). - Secure by default: omit the setting entirely in production to keep sensitive traces off.
- Enable only temporarily for troubleshooting, then remove/disable.
Note: This flag only controls the sensitive payload traces. Normal non-sensitive flow/status traces (via
WriteDiagnosticTrace) are unaffected and continue to log whenever tracing is enabled.
4. Usage guidance
Use when the message contains, or may contain:
- Full or partial SAML assertions / responses / requests
- Bearer tokens, session tokens, security artifacts
- PII (subject/NameID, email, user attributes)
Use the normal trace when the message
is operational/flow-only:
- Method entry/exit markers, decision branches, status, non-sensitive identifiers.
5. Verification checklist
- With
Saml2.TraceSensitiveDataunset/false: trace logs contain flow/status lines but no assertion/response/request XML. - With
Saml2.TraceSensitiveData=true: full payloads appear (for debugging only).
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com