mirror of https://github.com/abpframework/abp.git
committed by
GitHub
11 changed files with 199 additions and 15 deletions
@ -0,0 +1,22 @@ |
|||
using Microsoft.AspNetCore.Mvc.Rendering; |
|||
using Microsoft.AspNetCore.Mvc.ViewFeatures; |
|||
using Microsoft.AspNetCore.Razor.TagHelpers; |
|||
using Volo.Abp.AspNetCore.Mvc.UI.Bootstrap.TagHelpers; |
|||
|
|||
namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.TagHelpers; |
|||
|
|||
[HtmlTargetElement("script")] |
|||
[HtmlTargetElement("body")] |
|||
public class ScriptNonceTagHelper : AbpTagHelper |
|||
{ |
|||
[HtmlAttributeNotBound] |
|||
[ViewContext] |
|||
public ViewContext ViewContext { get; set; } |
|||
public override void Process(TagHelperContext context, TagHelperOutput output) |
|||
{ |
|||
if (ViewContext.HttpContext.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceString && !string.IsNullOrEmpty(nonceString)) |
|||
{ |
|||
output.Attributes.Add("nonce", nonceString); |
|||
} |
|||
} |
|||
} |
|||
@ -0,0 +1,23 @@ |
|||
using Microsoft.AspNetCore.Html; |
|||
using Microsoft.AspNetCore.Mvc.Rendering; |
|||
|
|||
namespace Volo.Abp.AspNetCore.Security; |
|||
|
|||
public static class AbpSecurityHeaderNonceHelper |
|||
{ |
|||
public static string GetScriptNonce(this IHtmlHelper htmlHelper) |
|||
{ |
|||
if (htmlHelper.ViewContext.HttpContext.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceString && !string.IsNullOrEmpty(nonceString)) |
|||
{ |
|||
return nonceString; |
|||
} |
|||
|
|||
return string.Empty; |
|||
} |
|||
|
|||
public static IHtmlContent GetScriptNonceAttribute(this IHtmlHelper htmlHelper) |
|||
{ |
|||
var nonce = htmlHelper.GetScriptNonce(); |
|||
return nonce == string.Empty ? HtmlString.Empty : new HtmlString($"nonce=\"{nonce}\""); |
|||
} |
|||
} |
|||
@ -1,17 +1,29 @@ |
|||
using System; |
|||
using System.Collections.Generic; |
|||
using System.Threading.Tasks; |
|||
using Microsoft.AspNetCore.Http; |
|||
|
|||
namespace Volo.Abp.AspNetCore.Security; |
|||
|
|||
public class AbpSecurityHeadersOptions |
|||
{ |
|||
public bool UseContentSecurityPolicyHeader { get; set; } |
|||
|
|||
public bool UseContentSecurityPolicyScriptNonce { get; set; } |
|||
|
|||
public string ContentSecurityPolicyValue { get; set; } |
|||
public Dictionary<string, IEnumerable<string>> ContentSecurityPolicyValues { get; } |
|||
|
|||
public Dictionary<string, string> Headers { get; } |
|||
|
|||
public List<Func<HttpContext, Task<bool>>> IgnoredScriptNonceSelectors { get; } |
|||
|
|||
public List<string> IgnoredScriptNoncePaths { get; } |
|||
|
|||
public AbpSecurityHeadersOptions() |
|||
{ |
|||
Headers = new Dictionary<string, string>(); |
|||
ContentSecurityPolicyValues = new Dictionary<string, IEnumerable<string>>(); |
|||
IgnoredScriptNonceSelectors = new List<Func<HttpContext, Task<bool>>>(); |
|||
IgnoredScriptNoncePaths = new List<string>(); |
|||
} |
|||
} |
|||
|
|||
Loading…
Reference in new issue