Browse Source

Change uses that are NonceScript to ScriptNonce

pull/16496/head
Salih 3 years ago
parent
commit
d3853c2b3b
  1. 2
      framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs
  2. 2
      framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs
  3. 8
      framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs
  4. 10
      framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs

2
framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs

@ -52,7 +52,7 @@ public class AbpTagHelperStyleService : AbpTagHelperResourceService
if (preload || Options.PreloadStylesByDefault || Options.PreloadStyles.Any(x => file.StartsWith(x, StringComparison.OrdinalIgnoreCase)))
{
output.Content.AppendHtml(SecurityHeadersOptions.UseContentSecurityPolicyNonce
output.Content.AppendHtml(SecurityHeadersOptions.UseContentSecurityPolicyScriptNonce
? $"<link rel=\"preload\" href=\"{viewContext.GetUrlHelper().Content(file.EnsureStartsWith('~'))}\" as=\"style\" abp-csp-style />{Environment.NewLine}"
: $"<link rel=\"preload\" href=\"{viewContext.GetUrlHelper().Content(file.EnsureStartsWith('~'))}\" as=\"style\" onload=\"this.rel='stylesheet'\" />{Environment.NewLine}");
}

2
framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/NonceScriptTagHelper.cs → framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs

@ -7,7 +7,7 @@ namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.TagHelpers;
[HtmlTargetElement("script")]
[HtmlTargetElement("body")]
public class NonceScriptTagHelper : AbpTagHelper
public class ScriptNonceTagHelper : AbpTagHelper
{
[HtmlAttributeNotBound]
[ViewContext]

8
framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs

@ -38,14 +38,14 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency
|| !Options.Value.UseContentSecurityPolicyHeader
|| await AlwaysIgnoreContentTypes(context)
|| context.GetEndpoint() == null
|| Options.Value.IgnoredNonceScriptPaths.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/'))))
|| Options.Value.IgnoredScriptNoncePaths.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/'))))
{
AddOtherHeaders(context);
await next.Invoke(context);
return;
}
if (Options.Value.UseContentSecurityPolicyNonce)
if (Options.Value.UseContentSecurityPolicyScriptNonce)
{
var randomValue = Guid.NewGuid().ToString("N");
context.Items.Add(AbpAspNetCoreConsts.ScriptNonceKey, randomValue);
@ -80,7 +80,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency
private async Task<bool> AlwaysIgnoreContentTypes(HttpContext context)
{
foreach (var selector in Options.Value.IgnoredNonceScriptSelectors)
foreach (var selector in Options.Value.IgnoredScriptNonceSelectors)
{
if(await selector(context))
{
@ -101,7 +101,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency
protected virtual string BuildContentSecurityPolicyValue(HttpContext context)
{
if (!(Options.Value.UseContentSecurityPolicyNonce &&
if (!(Options.Value.UseContentSecurityPolicyScriptNonce &&
context.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) &&
nonce is string nonceValue && !string.IsNullOrEmpty(nonceValue)))
{

10
framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs

@ -9,21 +9,21 @@ public class AbpSecurityHeadersOptions
{
public bool UseContentSecurityPolicyHeader { get; set; }
public bool UseContentSecurityPolicyNonce { get; set; }
public bool UseContentSecurityPolicyScriptNonce { get; set; }
public Dictionary<string, IEnumerable<string>> ContentSecurityPolicyValues { get; }
public Dictionary<string, string> Headers { get; }
public List<Func<HttpContext, Task<bool>>> IgnoredNonceScriptSelectors { get; }
public List<Func<HttpContext, Task<bool>>> IgnoredScriptNonceSelectors { get; }
public List<string> IgnoredNonceScriptPaths { get; }
public List<string> IgnoredScriptNoncePaths { get; }
public AbpSecurityHeadersOptions()
{
Headers = new Dictionary<string, string>();
ContentSecurityPolicyValues = new Dictionary<string, IEnumerable<string>>();
IgnoredNonceScriptSelectors = new List<Func<HttpContext, Task<bool>>>();
IgnoredNonceScriptPaths = new List<string>();
IgnoredScriptNonceSelectors = new List<Func<HttpContext, Task<bool>>>();
IgnoredScriptNoncePaths = new List<string>();
}
}

Loading…
Cancel
Save