Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Asp.Net Core

ASP.NET Core: Why a Custom Middleware Never Runs for Static File Requests

- 06.09.26 - ErcanOPAK

⚙️ Your Custom Middleware Never Actually Runs for Static File Requests

A custom middleware is registered to log, authenticate, or modify every request – but requests for static files (images, CSS, JS) sail through completely untouched, because `UseStaticFiles()` short-circuits the pipeline and returns the file directly the moment it finds a match, without ever calling `next()` to continue on to whatever middleware comes after it.

🔎 The Problem

var app = builder.Build();

app.UseStaticFiles();          // <- handles /images/logo.png and returns immediately

app.Use(async (context, next) =>
{
    Console.WriteLine($"Request: {context.Request.Path}");
    await next();
});

app.MapControllers();

// Requests for actual files under wwwroot (e.g. /images/logo.png) never
// reach the logging middleware below UseStaticFiles - because
// UseStaticFiles ends the pipeline right there once it finds a matching
// file, it never calls next().

✅ Fix: Order Middleware by What Actually Needs to See Every Request

  • Move any middleware that must run for EVERY request – logging, authentication checks, custom headers – to BEFORE `UseStaticFiles()` in the pipeline, so it executes regardless of whether the request ends up being served as a static file.
  • If the goal is specifically to apply logic only to non-static requests (e.g., API routes), the current order is actually correct – the fix here is about matching pipeline order to actual intent, not always moving things earlier.

⚠️ The General Rule for ASP.NET Core Middleware Order

  • Middleware order is not just a style choice – it directly determines which requests each piece of the pipeline ever sees, since any middleware can choose to short-circuit and never call `next()`. Reading the pipeline top-to-bottom as “what runs before what, and what might stop early” is the only reliable way to reason about it.
  • `UseStaticFiles`, `UseRouting`, `UseAuthentication`, `UseAuthorization`, and `UseEndpoints`/`MapControllers` all have well-documented required relative ordering for exactly this reason – moving one without understanding why it was placed there is a common source of these silent gaps.

Middleware order isn’t a suggestion – it’s the actual list of who gets asked, and anything placed after a shortcut simply never gets a turn.

— Backend Architect

Related posts:

.NET Core: Build Background Tasks with Worker Services

.NET Core: Advanced Dependency Injection Patterns

Why Minimal APIs Improve Cold Start

Post Views: 3

Post navigation

HTML5: Fix a Drag-and-Drop File Upload That Silently Does Nothing on Drop
Windows 11: Fix an External Hard Drive That Disconnects Under Heavy Read/Write

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (951)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (624)
  • Add Constraint to SQL Table to ensure email contains @ (590)
  • Average of all values in a column that are not zero in SQL (553)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (526)
  • Find numbers with more than two decimal places in SQL (468)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps
  • Photoshop: Fix a Color Profile Mismatch That Makes Printed Output Look Nothing Like What You Saw On Screen
  • WordPress: Fix Search Results That Return Pages From a Theme You Deactivated Months Ago
  • Visual Studio: Fix a Test Project That Builds Fine Alone but Fails to Discover Any Tests After a NuGet Restore
  • ASP.NET Core: Fix a File Upload That Times Out on Slow Connections Only Because Kestrel’s Minimum Data Rate Feature Kicked In
  • JavaScript: Fix an Array Destructuring Default Value That Silently Never Applies Because null Was Passed Instead of Undefined

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (951)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com