mirror of https://github.com/abpframework/abp.git
committed by
GitHub
11 changed files with 199 additions and 15 deletions
@ -0,0 +1,22 @@ |
|||||
|
using Microsoft.AspNetCore.Mvc.Rendering; |
||||
|
using Microsoft.AspNetCore.Mvc.ViewFeatures; |
||||
|
using Microsoft.AspNetCore.Razor.TagHelpers; |
||||
|
using Volo.Abp.AspNetCore.Mvc.UI.Bootstrap.TagHelpers; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.TagHelpers; |
||||
|
|
||||
|
[HtmlTargetElement("script")] |
||||
|
[HtmlTargetElement("body")] |
||||
|
public class ScriptNonceTagHelper : AbpTagHelper |
||||
|
{ |
||||
|
[HtmlAttributeNotBound] |
||||
|
[ViewContext] |
||||
|
public ViewContext ViewContext { get; set; } |
||||
|
public override void Process(TagHelperContext context, TagHelperOutput output) |
||||
|
{ |
||||
|
if (ViewContext.HttpContext.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceString && !string.IsNullOrEmpty(nonceString)) |
||||
|
{ |
||||
|
output.Attributes.Add("nonce", nonceString); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
@ -0,0 +1,23 @@ |
|||||
|
using Microsoft.AspNetCore.Html; |
||||
|
using Microsoft.AspNetCore.Mvc.Rendering; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Security; |
||||
|
|
||||
|
public static class AbpSecurityHeaderNonceHelper |
||||
|
{ |
||||
|
public static string GetScriptNonce(this IHtmlHelper htmlHelper) |
||||
|
{ |
||||
|
if (htmlHelper.ViewContext.HttpContext.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceString && !string.IsNullOrEmpty(nonceString)) |
||||
|
{ |
||||
|
return nonceString; |
||||
|
} |
||||
|
|
||||
|
return string.Empty; |
||||
|
} |
||||
|
|
||||
|
public static IHtmlContent GetScriptNonceAttribute(this IHtmlHelper htmlHelper) |
||||
|
{ |
||||
|
var nonce = htmlHelper.GetScriptNonce(); |
||||
|
return nonce == string.Empty ? HtmlString.Empty : new HtmlString($"nonce=\"{nonce}\""); |
||||
|
} |
||||
|
} |
||||
@ -1,17 +1,29 @@ |
|||||
|
using System; |
||||
using System.Collections.Generic; |
using System.Collections.Generic; |
||||
|
using System.Threading.Tasks; |
||||
|
using Microsoft.AspNetCore.Http; |
||||
|
|
||||
namespace Volo.Abp.AspNetCore.Security; |
namespace Volo.Abp.AspNetCore.Security; |
||||
|
|
||||
public class AbpSecurityHeadersOptions |
public class AbpSecurityHeadersOptions |
||||
{ |
{ |
||||
public bool UseContentSecurityPolicyHeader { get; set; } |
public bool UseContentSecurityPolicyHeader { get; set; } |
||||
|
|
||||
|
public bool UseContentSecurityPolicyScriptNonce { get; set; } |
||||
|
|
||||
public string ContentSecurityPolicyValue { get; set; } |
public Dictionary<string, IEnumerable<string>> ContentSecurityPolicyValues { get; } |
||||
|
|
||||
public Dictionary<string, string> Headers { get; } |
public Dictionary<string, string> Headers { get; } |
||||
|
|
||||
|
public List<Func<HttpContext, Task<bool>>> IgnoredScriptNonceSelectors { get; } |
||||
|
|
||||
|
public List<string> IgnoredScriptNoncePaths { get; } |
||||
|
|
||||
public AbpSecurityHeadersOptions() |
public AbpSecurityHeadersOptions() |
||||
{ |
{ |
||||
Headers = new Dictionary<string, string>(); |
Headers = new Dictionary<string, string>(); |
||||
|
ContentSecurityPolicyValues = new Dictionary<string, IEnumerable<string>>(); |
||||
|
IgnoredScriptNonceSelectors = new List<Func<HttpContext, Task<bool>>>(); |
||||
|
IgnoredScriptNoncePaths = new List<string>(); |
||||
} |
} |
||||
} |
} |
||||
|
|||||
Loading…
Reference in new issue