Global Exception Handling
Why This Is Asked
Production-grade applications must handle errors gracefully without leaking sensitive information. This question tests your ability to centralize error logic instead of littering your code with try-catch blocks.
Key Concepts
- Centralization: A single location to catch and log all unhandled exceptions.
- User Experience: Returning a consistent error response format to the client.
- Security: Preventing raw stack traces from reaching the end-user.
- Implementation: Usually done via Middleware (ASP.NET Core), Exception Filters, or ControllerAdvice (Spring).
Answers by Technology
+ Add VariantExpected Answer (.NET 10 / C# 14)
In modern ASP.NET Core, global exception handling is implemented using the IExceptionHandler interface (introduced in .NET 8) or custom middleware.
Real-time Example: When any service throws an UnauthorizedException, the global handler catches it, logs the event, and returns a 401 Unauthorized JSON response with a friendly message.
Why It Matters
It prevents the application from crashing and ensures the client always receives a structured response (like ProblemDetails) instead of an ugly HTML error page or a raw stack trace, which is a security risk.
Code Example
public class GlobalExceptionHandler : IExceptionHandler
{
public async ValueTask<bool> TryHandleAsync(
HttpContext httpContext, Exception exception, CancellationToken cancellationToken)
{
var response = new { Message = "An unexpected error occurred." };
httpContext.Response.StatusCode = 500;
await httpContext.Response.WriteAsJsonAsync(response, cancellationToken);
return true; // Exception handled
}
}
// Registration in Program.cs
// builder.Services.AddExceptionHandler<GlobalExceptionHandler>();
// app.UseExceptionHandler(_ => { });
Common Mistakes
- Leaking sensitive info: Returning
exception.Messageorexception.StackTracein production. - Not logging: Catching the exception but failing to log it for developers to see.
Follow-up Questions
- What is
ProblemDetails? (Answer: A standardized JSON format for returning machine-readable error details in HTTP responses). - Middleware vs Exception Filters? (Answer: Middleware handles everything in the pipe; Filters only handle exceptions within the MVC/Controller context).
Expected Answer (Java 26 / Spring Boot)
In Spring Boot, global exception handling is primarily done using the @ControllerAdvice and @ExceptionHandler annotations.
Real-time Example: Creating a RestResponseEntityExceptionHandler that catches EntityNotFoundException and returns a 404 Not Found with a custom error body.
Why It Matters
Centralized error handling ensures that no matter where an error occurs in your application, the client always gets a consistent, secure, and clean response. It avoids the need for repetitive try-catch blocks in every controller method.
Code Example
@ControllerAdvice
public class GlobalExceptionHandler {
@ExceptionHandler(value = { IllegalArgumentException.class })
protected ResponseEntity<Object> handleConflict(RuntimeException ex, WebRequest request) {
String bodyOfResponse = "Invalid arguments provided.";
return new ResponseEntity<>(bodyOfResponse, HttpStatus.BAD_REQUEST);
}
}
Common Mistakes
- Catching
Exception.class: Catching the root Exception class can hide bugs and prevent specific handlers from running. Always try to catch specific exceptions. - Security Leaks: Returning the internal error message or stack trace to the user, which might reveal database structure or library versions.
Follow-up Questions
ErrorControllervs@ControllerAdvice? (Answer:ErrorControllerhandles errors outside of the Spring MVC context, like 404s for non-existent routes).- What is
ProblemDetail? (Answer: Introduced in Spring Boot 3 / RFC 7807, it’s the standardized way to return API error details).
Expected Answer (PHP 8.5 / Laravel)
In Laravel, all exceptions are handled by the App\Exceptions\Handler class (or in newer versions, via bootstrap/app.php configurations).
Real-time Example: Catching a ModelNotFoundException globally and returning a custom 404 JSON response for API requests, instead of the default HTML error page.
Why It Matters
Global handling prevents your app from leaking technical details (like database queries or file paths) when an error occurs. It also allows you to integrate with third-party monitoring tools like Sentry or Bugsnag in one place.
Code Example
// In bootstrap/app.php (Laravel 11+)
->withExceptions(function (Exceptions $exceptions) {
$exceptions->render(function (NotFoundHttpException $e, Request $request) {
if ($request->is('api/*')) {
return response()->json([
'message' => 'Record not found.'
], 404);
}
});
})
Common Mistakes
- Displaying errors in production: Having
APP_DEBUG=truein production is a critical security vulnerability. - Not logging: Using a global handler to “silence” errors without logging them for developers to fix.
Follow-up Questions
- What is the ‘report’ method? (Answer: The method used to log exceptions or send them to external services like Sentry).
- What is ‘render’? (Answer: The method responsible for converting an exception into an HTTP response).