Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Asp.Net Core

ASP.NET Core: Fix the ‘Response Already Started’ Exception That Crashes Custom Middleware

- 31.08.26 | 31.08.26 - ErcanOPAK

⚙️ Custom Middleware Crashing With No Clear Reason?

Custom middleware that tries to modify response headers or status codes AFTER the response body has started writing throws InvalidOperationException: Headers are read-only, response has already started — a timing bug that’s easy to introduce and confusing to diagnose from the exception message alone.

🐞 The Problem

public class ErrorHandlingMiddleware
{
    private readonly RequestDelegate _next;
    public ErrorHandlingMiddleware(RequestDelegate next) => _next = next;

    public async Task InvokeAsync(HttpContext context)
    {
        try
        {
            await _next(context); // downstream middleware already wrote to the response
        }
        catch (Exception ex)
        {
            context.Response.StatusCode = 500; // throws: response already started
            await context.Response.WriteAsync("An error occurred.");
        }
    }
}

🔍 Why This Happens

Once ANY bytes of the response body have been written to the
underlying network stream, the status code and headers are locked
- HTTP fundamentally requires headers to be sent before the body,
so ASP.NET Core can't quietly rewrite them after the fact. If a
downstream middleware/action already streamed part of a response
before throwing, your catch block's attempt to set StatusCode = 500
comes too late.

✅ The Fix: Check HasStarted Before Modifying the Response

  • If the response has already started, you can no longer change the status code or headers — the best you can do is log it and let the connection close as-is.
  • For a reliable global error page, put this middleware as early as possible in the pipeline (first, or very close to it) so less code runs before it can catch things.

🛡️ Defensive Version

public async Task InvokeAsync(HttpContext context)
{
    try
    {
        await _next(context);
    }
    catch (Exception ex)
    {
        _logger.LogError(ex, "Unhandled exception");

        if (!context.Response.HasStarted)
        {
            context.Response.Clear();
            context.Response.StatusCode = 500;
            await context.Response.WriteAsync("An error occurred.");
        }
        else
        {
            // Can't modify the response anymore - the best option
            // left is to log it and rethrow so the host logs it too.
            throw;
        }
    }
}

⚠️ Also Use the Built-In Exception Handler

  • app.UseExceptionHandler(“/error”) (registered early in Program.cs) handles most of this correctly out of the box — only write custom middleware when you need behavior it doesn’t provide.

“Response already started” isn’t a bug in your error handling logic — it’s ASP.NET Core enforcing an HTTP rule that was always true; the fix is checking HasStarted before assuming you still have control.

— Backend Architect

Related posts:

IHostedService vs BackgroundService

Step-by-Step: Structured Logging in ASP.NET Core with Serilog

ASP.NET Core: Why an IOptionsSnapshot Injected Into a Singleton Silently Freezes on Its First Config...

Post Views: 1

Post navigation

HTML5: Fix Forms That Submit Twice When Users Double-Click Submit
C#: Why Catching Exception Instead of a Specific Type Hides the Bug You Actually Need to See

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (624)
  • Add Constraint to SQL Table to ensure email contains @ (590)
  • Average of all values in a column that are not zero in SQL (553)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (526)
  • Find numbers with more than two decimal places in SQL (468)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps
  • Photoshop: Fix a Color Profile Mismatch That Makes Printed Output Look Nothing Like What You Saw On Screen
  • WordPress: Fix Search Results That Return Pages From a Theme You Deactivated Months Ago
  • Visual Studio: Fix a Test Project That Builds Fine Alone but Fails to Discover Any Tests After a NuGet Restore
  • ASP.NET Core: Fix a File Upload That Times Out on Slow Connections Only Because Kestrel’s Minimum Data Rate Feature Kicked In
  • JavaScript: Fix an Array Destructuring Default Value That Silently Never Applies Because null Was Passed Instead of Undefined

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com