Summary
Request IDs are useful only if clients can correlate them with failures. SecuScan should make that correlation obvious in error payloads as well as headers.
Scope
- Decide where request IDs belong in structured error responses.
- Apply the contract consistently across validation errors and server errors.
- Add regression tests for the chosen shape.
Acceptance criteria
Summary
Request IDs are useful only if clients can correlate them with failures. SecuScan should make that correlation obvious in error payloads as well as headers.
Scope
Acceptance criteria