proposal-system/api/src/ProposalSystem.Api/Middleware/GlobalExceptionHandler.cs
Adam Moussa 9d856a9619
Some checks failed
Deploy / Deploy to AWS (push) Has been cancelled
Phase 3 audit fixes: FIX-01–47, accessibility NITs, code quality NITs [skip deploy]
## Summary
Implements Phase 3 of the AUDIT-2026-05-20 findings:
- 29 FIX-severity items across API, web, infra, and lambdas
- 7 accessibility NITs (aria-labels, document titles)
- 4 code quality NITs (deduplication, constants extraction)

Key changes:
- API: N+1 fix, pagination clamping, idempotent transitions, upload confirm endpoint, revision TotalBidAmount carry-forward
- Web: confirmation dialogs, currency formatting, error states, date range filters, document titles
- Infra: S3 CORS lockdown, API Gateway throttling, AOSS network policy fix, CI concurrency
- Lambdas: skip empty suggestions, remove status side-effect
- Scripts: post-deploy health check

## Test plan
- [x] tsc --noEmit (web + infra)
- [x] dotnet build (api)
- [x] ruff check + format (lambdas)
- [x] Cross-review via orchestrator (no blockers)

[skip deploy]
2026-05-20 19:38:36 -04:00

94 lines
2.8 KiB
C#

using System.Net;
using System.Text.Json;
using FluentValidation;
using Microsoft.AspNetCore.Mvc;
namespace ProposalSystem.Api.Middleware;
public class GlobalExceptionHandler : IMiddleware
{
private readonly ILogger<GlobalExceptionHandler> _logger;
public GlobalExceptionHandler(ILogger<GlobalExceptionHandler> logger)
{
_logger = logger;
}
public async Task InvokeAsync(HttpContext context, RequestDelegate next)
{
try
{
await next(context);
}
catch (Exception ex)
{
await HandleExceptionAsync(context, ex);
}
}
private async Task HandleExceptionAsync(HttpContext context, Exception exception)
{
var (statusCode, problemDetails) = exception switch
{
ValidationException validationEx => (
HttpStatusCode.BadRequest,
new ProblemDetails
{
Status = 400,
Title = "Validation Error",
Detail = string.Join("; ", validationEx.Errors.Select(e => e.ErrorMessage)),
}
),
KeyNotFoundException => (
HttpStatusCode.NotFound,
new ProblemDetails
{
Status = 404,
Title = "Not Found",
Detail = exception.Message,
}
),
UnauthorizedAccessException => (
HttpStatusCode.Unauthorized,
new ProblemDetails
{
Status = 401,
Title = "Unauthorized",
Detail = "Authentication required",
}
),
InvalidOperationException => (
HttpStatusCode.BadRequest,
new ProblemDetails
{
Status = 400,
Title = "Invalid Operation",
Detail = exception.Message,
}
),
_ => (
HttpStatusCode.InternalServerError,
new ProblemDetails
{
Status = 500,
Title = "Internal Server Error",
Detail = "An unexpected error occurred",
}
),
};
if (statusCode == HttpStatusCode.InternalServerError)
{
_logger.LogError(exception, "Unhandled exception");
}
context.Response.StatusCode = (int)statusCode;
context.Response.ContentType = "application/problem+json";
await context.Response.WriteAsync(
JsonSerializer.Serialize(problemDetails, new JsonSerializerOptions
{
PropertyNamingPolicy = JsonNamingPolicy.CamelCase,
}));
}
}