I have a simple website form through which a can input data (name, address, password, whatever - it is not important). I use a jQuery ajax call to send the submitted data to a PHP file that in turn, validates the data and adds it to a database.
Does returning mysqli_error() in the ajax results pose a security risk? For example, an error message may expose the database name or field names in the console log.
Is it acceptable in production or should I could send all errors to file with error_log().