diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs index 674581dfe5..2ac299959a 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs @@ -1,7 +1,4 @@ -using System.Collections.Generic; -using Microsoft.Extensions.DependencyInjection; -using Microsoft.Extensions.Options; -using Volo.Abp.AspNetCore.Mvc.UI.Bundling; +using Volo.Abp.AspNetCore.Mvc.UI.Bundling; using Volo.Abp.AspNetCore.Mvc.UI.Packages.Bootstrap; using Volo.Abp.AspNetCore.Mvc.UI.Packages.BootstrapDatepicker; using Volo.Abp.AspNetCore.Mvc.UI.Packages.BootstrapDaterangepicker; @@ -16,7 +13,6 @@ using Volo.Abp.AspNetCore.Mvc.UI.Packages.Select2; using Volo.Abp.AspNetCore.Mvc.UI.Packages.SweetAlert2; using Volo.Abp.AspNetCore.Mvc.UI.Packages.Timeago; using Volo.Abp.AspNetCore.Mvc.UI.Packages.Toastr; -using Volo.Abp.AspNetCore.Security; using Volo.Abp.Modularity; namespace Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared.Bundling; @@ -53,11 +49,6 @@ public class SharedThemeGlobalScriptContributor : BundleContributor "/libs/abp/aspnetcore-mvc-ui-theme-shared/datatables/datatables-extensions.js", "/libs/abp/aspnetcore-mvc-ui-theme-shared/sweetalert2/abp-sweetalert2.js", "/libs/abp/aspnetcore-mvc-ui-theme-shared/toastr/abp-toastr.js" - }); - - if (context.ServiceProvider.GetRequiredService>().Value.UseContentSecurityPolicyNonce) - { - context.Files.AddIfNotContains("/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js"); - } + }); } } diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/bootstrap/dom-event-handlers.js b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/bootstrap/dom-event-handlers.js index 945df5d0c6..27ca6cfd97 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/bootstrap/dom-event-handlers.js +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/bootstrap/dom-event-handlers.js @@ -754,6 +754,10 @@ }); } + abp.dom.initializers.initializeAbpCspStyles = function ($abpCspStyles){ + $abpCspStyles.attr("rel", "stylesheet"); + } + abp.dom.onNodeAdded(function (args) { abp.dom.initializers.initializeToolTips(args.$el.findWithSelf('[data-toggle="tooltip"]')); abp.dom.initializers.initializePopovers(args.$el.findWithSelf('[data-toggle="popover"]')); @@ -761,6 +765,7 @@ abp.dom.initializers.initializeForms(args.$el.findWithSelf('form'), true); abp.dom.initializers.initializeScript(args.$el); abp.dom.initializers.initializeAutocompleteSelects(args.$el.findWithSelf('.auto-complete-select')); + abp.dom.initializers.initializeAbpCspStyles($("link[abp-csp-style]")); }); abp.dom.onNodeRemoved(function (args) { @@ -782,7 +787,7 @@ abp.dom.initializers.initializeForms($('form')); abp.dom.initializers.initializeAutocompleteSelects($('.auto-complete-select')); $('[data-auto-focus="true"]').first().findWithSelf('input,select').focus(); - + abp.dom.initializers.initializeAbpCspStyles($("link[abp-csp-style]")); }); })(jQuery); diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js deleted file mode 100644 index 102c115c25..0000000000 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js +++ /dev/null @@ -1,4 +0,0 @@ -$(function (){ - let preLoads = $("link[abp-csp-style]"); - preLoads.attr("rel", "stylesheet"); -}) \ No newline at end of file diff --git a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs index 88162c9bc1..e84b3a5419 100644 --- a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs +++ b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs @@ -3,8 +3,6 @@ using System.Collections.Generic; using System.Linq; using System.Threading.Tasks; using Microsoft.AspNetCore.Http; -using Microsoft.AspNetCore.Mvc.Controllers; -using Microsoft.AspNetCore.Mvc.RazorPages; using Microsoft.Extensions.Options; using Microsoft.Extensions.Primitives; using Volo.Abp.DependencyInjection; @@ -36,8 +34,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency var requestAcceptTypeHtml = context.Request.Headers["Accept"].Any(x => x.Contains("text/html") || x.Contains("*/*") || x.Contains("application/xhtml+xml")); - if (!requestAcceptTypeHtml || !Options.Value.UseContentSecurityPolicyHeader || - Options.Value.IgnoredUrls.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/'))) || context.GetEndpoint() == null) + if (!requestAcceptTypeHtml || !Options.Value.UseContentSecurityPolicyHeader || await AlwaysIgnoreContentTypes(context) || context.GetEndpoint() == null) { await next.Invoke(context); return; @@ -78,6 +75,19 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency await next.Invoke(context); } + + private async Task AlwaysIgnoreContentTypes(HttpContext context) + { + foreach (var selector in Options.Value.AlwaysIgnoreSecurityHeadersSelectors) + { + if(await selector(context)) + { + return true; + } + } + + return false; + } private void AddOtherHeaders(HttpContext context) { diff --git a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs index 70ae136edc..1674b5bf31 100644 --- a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs +++ b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs @@ -1,4 +1,7 @@ +using System; using System.Collections.Generic; +using System.Threading.Tasks; +using Microsoft.AspNetCore.Http; namespace Volo.Abp.AspNetCore.Security; @@ -12,12 +15,12 @@ public class AbpSecurityHeadersOptions public Dictionary Headers { get; } - public List IgnoredUrls { get; } + public List>> AlwaysIgnoreSecurityHeadersSelectors { get; } public AbpSecurityHeadersOptions() { Headers = new Dictionary(); ContentSecurityPolicyValueDictionary = new Dictionary>(); - IgnoredUrls = new List (); + AlwaysIgnoreSecurityHeadersSelectors = new List>>(); } }