Showing posts with label Exception Handling. Show all posts
Showing posts with label Exception Handling. Show all posts

Tuesday, May 13, 2014

MVC Exception Handling

This is a followup post to my original post about simple .NET exception handling.

The ASP.NET MVC Framework contains an attribute named HandleErrorAttribute.  You can decorate a controller or an action simply by typing <HandleError> above the controller or action definition.  If an unhandled exception occurs anywhere in the scope decorated with HandleErrorAttribute, MVC will display a view named "Error" to the user automatically.  Typically, this view is generated for you when you create a new MVC application and is placed in the Shared folder.  The HandleErrorAttribute will only work if you have customErrors turned on in your web.config.  HandleErrorAttribute works great but it doesn't log.  In order to add this functionality to the attribute you need to create a new class that inherits from the HandleErrorAttribute like this:

    Public Class HandleErrorAndLogAttribute
        Inherits HandleErrorAttribute

        Public Overrides Sub OnException(filterContext As ExceptionContext)

            If Not filterContext.ExceptionHandled Then

                Dim MyException As Exception = filterContext.Exception
                
                ...

                'Logging code goes here

                ...
 
                MyBase.OnException(filterContext)

            End If

            'filterContext.Result = New ViewResult With {.ViewName = "Error"}

        End Sub

    End Class

Now, if you want to use your new attribute, you would just type <HandleErrorAndLog>.  You can globally apply this attribute to everything in your application by editing the FilterConfig.vb file like this:

Public Module FilterConfig
    Public Sub RegisterGlobalFilters(ByVal filters As GlobalFilterCollection)
        'filters.Add(New HandleErrorAttribute())
        filters.Add(New HandleErrorAndLogAttribute())
    End Sub
End Module

Apparently, there are certain exceptions that this attribute does not handle such as HTTP exceptions that occur outside of the MVC context.  To ensure these errors are handled, you should also log errors in the MvcApplication_Error event of the Global.asax.vb file.  Be sure to set the defaultRedirect attribute of the customErrors node in the web.config file to the Error View.  You will need to create an action method that will display the Error view when it is redirected in this way..

Friday, December 20, 2013

Simple and secure exception handling for .NET web applications

It is best practice not to display details of an exception on the page visible to anyone.  To hide these details, simply add the following to your web.config.
<configuration>
  <system.web>
    <customErrors mode="On" defaultRedirect="WebPages/ErrorPage.aspx"></customErrors>
  </system.web>
</configuration>
You can also change the mode attribute to "RemoteOnly" to only hide errors if viewing the site on a machine other than the web server.  The redirect simply takes the users to a page other than the "yellow screen of death" page that ASP provides.

It is also imperative to add a Global.asax file to your web application project.  You'll want to log anything that fires off the Application_Error event since these represent any unhandled exceptions and the details will no longer be visible on the screen.  Something like this will accomplish that:
Sub Application_Error(ByVal sender As Object, ByVal e As EventArgs)
    ' Fires when an error occurs

    Dim MyException As Exception = Server.GetLastError()

    ' Log the exception details here.
End Sub