4 ms·
Letting an uncaught exception error reach the user is generally bad. It risks exposing secrets / confidential information to the user and any returned client si
by theginger 3y ago
Letting an uncaught exception error reach the user is generally bad. It risks exposing secrets / confidential information to the user and any returned client side secrets risk getting into intermediary caches.
The biggest risk is the user input being returned in the response creating an XSS (cross site scripting) risk. This is a very common source of reflected XSS vulnerabilities.
You should always catch exceptions like this so you can at the very least sanitize them for XSS. This is already built in to some frameworks. If you are using something that doesn't you need to do it yourself and it's probably easier to just strip it all in production, you just need to make sure you are still setting an appropriate status code.
- jiggawatts 3y agoWho said anything about letting exceptions reaching the users!? The exception needs to bubble up to the request pipeline, which will set an integer error code, and then... redirect to a generic "sorry we broke" error page. Showing the full exception stack trace and other sensitive bits and pieces is for local debug mode, not for production.
- javajosh 3y ago...and there should be a guid assigned to the problem, in the logs, and possibly visible to the end user.
- jiggawatts 3y agoThe APM does that for you. Open Telemetry, Application Insights, New Relic, etc… will all stamp the request with a unique id and associate any errors with it.
- thrashh 3y agoI think it’s cute you think most developers let exceptions rise. Most developers I notice just catch the error right away and make the function return something non-sensible like a 0 for a string value function. Slightly better developers just let the exceptions bubble. The rare breed looks at what exceptions are being thrown, decides which ones to handle at which stack level, and repackages them as needed when the error cannot be handled that deep in that stack due to a lack of context. Then they write framework-level exception handlers for errors that rise to the top because they cannot be corrected at a higher stack level to give users specific error messages with user-correctable actions without revealing anything sensitive. “Your image is too small, wanker.”
- vel0city 3y agoGotta love these though: catch {};
- rjbwork 3y agoPokemon!
- hu3 3y agoAhhh the Visual Basic days of: On Error Resume Next In the first line of every function. It's tells the Interpreter: "Shhhh, it's fine. Just ignore errors. Division by zero? No worries. It's Fiiiiine. Try to access inexistent index of an array? Who cares, it's Friday!"
- janderland 3y agoJust a reminder that you don’t need to be patronizing to get your point across. Calling someone “cute” is a bit much.