What is the best practice for CF error handling when it comes to handling 500 errors that happen before application.cfc or application.cfm are processed?
e
Evil Ware
05/09/2024, 3:54 PM
This depends on your application. With OnRequestStart, for example, you could check to see if the requested "page" exists and then do something else if it doesn't.
q
quetwo
05/09/2024, 6:57 PM
Your application.cfc/ application.cfm should be processed before your page gets processed, which would be processed before a 500 error is generated. The only chance for a 500 error otherwise is if Tomcat itself or your http connector throws it. There really isn't a way to catch those, however.
👍 1
d
Dave Merrill
05/09/2024, 7:03 PM
@TEMann What sorts of errors are you seeing like that?
t
TEMann
05/09/2024, 9:12 PM
Our security team is trying to access application.cfm directly and getting the CF excpetion error page informing that application.cfm is reserved and cannot be accessed directly. The response is a 500 error.
c
cfvonner
05/09/2024, 9:41 PM
What would you prefer to have happen instead of seeing the 500 error?
cfvonner
05/09/2024, 9:43 PM
Depending on your web server, you could rewrite or redirect calls to application.cfm to a static error page, or treat them as a 403 error (Forbidden).