mirror of https://github.com/abpframework/abp.git
2 changed files with 23 additions and 20 deletions
@ -0,0 +1,23 @@ |
|||||
|
using Microsoft.AspNetCore.Mvc.Rendering; |
||||
|
using Microsoft.AspNetCore.Mvc.ViewFeatures; |
||||
|
using Microsoft.AspNetCore.Razor.TagHelpers; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Mvc.UI.Bootstrap.TagHelpers.Script; |
||||
|
|
||||
|
|
||||
|
[HtmlTargetElement("script", Attributes = "abp-nonce")] |
||||
|
public class AbpNonceTagHelper : AbpTagHelper |
||||
|
{ |
||||
|
[HtmlAttributeNotBound] |
||||
|
[ViewContext] |
||||
|
public ViewContext ViewContext { get; set; } |
||||
|
|
||||
|
public override void Process(TagHelperContext context, TagHelperOutput output) |
||||
|
{ |
||||
|
output.Attributes.RemoveAll("abp-nonce"); |
||||
|
if (ViewContext.HttpContext.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceString && !string.IsNullOrEmpty(nonceString)) |
||||
|
{ |
||||
|
output.Attributes.Add("nonce", nonceString); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
@ -1,20 +0,0 @@ |
|||||
using Microsoft.AspNetCore.Html; |
|
||||
using Microsoft.AspNetCore.Mvc.Rendering; |
|
||||
using Microsoft.AspNetCore.Mvc.ViewFeatures; |
|
||||
|
|
||||
namespace Volo.Abp.AspNetCore.Security; |
|
||||
|
|
||||
public static class NonceHtmlHelper |
|
||||
{ |
|
||||
public static IHtmlContent ScriptWithNonce(this HtmlHelper htmlHelper, string scriptUrl) |
|
||||
{ |
|
||||
var tagBuilder = new TagBuilder("script"); |
|
||||
tagBuilder.Attributes.Add("src", scriptUrl); |
|
||||
if(htmlHelper.ViewContext.HttpContext.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceString && !string.IsNullOrEmpty(nonceString)) |
|
||||
{ |
|
||||
tagBuilder.Attributes.Add("nonce", nonceString); |
|
||||
} |
|
||||
|
|
||||
return tagBuilder; |
|
||||
} |
|
||||
} |
|
||||
Loading…
Reference in new issue