From d3853c2b3b24bb993fe7eb0bfd3434f5517e0c20 Mon Sep 17 00:00:00 2001 From: Salih Date: Fri, 26 May 2023 17:47:12 +0300 Subject: [PATCH] Change uses that are NonceScript to ScriptNonce --- .../UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs | 2 +- ...NonceScriptTagHelper.cs => ScriptNonceTagHelper.cs} | 2 +- .../Security/AbpSecurityHeadersMiddleware.cs | 8 ++++---- .../AspNetCore/Security/AbpSecurityHeadersOptions.cs | 10 +++++----- 4 files changed, 11 insertions(+), 11 deletions(-) rename framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/{NonceScriptTagHelper.cs => ScriptNonceTagHelper.cs} (93%) diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs index 6089fbd383..0f68433f4c 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs @@ -52,7 +52,7 @@ public class AbpTagHelperStyleService : AbpTagHelperResourceService if (preload || Options.PreloadStylesByDefault || Options.PreloadStyles.Any(x => file.StartsWith(x, StringComparison.OrdinalIgnoreCase))) { - output.Content.AppendHtml(SecurityHeadersOptions.UseContentSecurityPolicyNonce + output.Content.AppendHtml(SecurityHeadersOptions.UseContentSecurityPolicyScriptNonce ? $"{Environment.NewLine}" : $"{Environment.NewLine}"); } diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/NonceScriptTagHelper.cs b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs similarity index 93% rename from framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/NonceScriptTagHelper.cs rename to framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs index 335f7a8aeb..6c29c81073 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/NonceScriptTagHelper.cs +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs @@ -7,7 +7,7 @@ namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.TagHelpers; [HtmlTargetElement("script")] [HtmlTargetElement("body")] -public class NonceScriptTagHelper : AbpTagHelper +public class ScriptNonceTagHelper : AbpTagHelper { [HtmlAttributeNotBound] [ViewContext] diff --git a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs index ea60375fce..5e20edff17 100644 --- a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs +++ b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs @@ -38,14 +38,14 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency || !Options.Value.UseContentSecurityPolicyHeader || await AlwaysIgnoreContentTypes(context) || context.GetEndpoint() == null - || Options.Value.IgnoredNonceScriptPaths.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/')))) + || Options.Value.IgnoredScriptNoncePaths.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/')))) { AddOtherHeaders(context); await next.Invoke(context); return; } - if (Options.Value.UseContentSecurityPolicyNonce) + if (Options.Value.UseContentSecurityPolicyScriptNonce) { var randomValue = Guid.NewGuid().ToString("N"); context.Items.Add(AbpAspNetCoreConsts.ScriptNonceKey, randomValue); @@ -80,7 +80,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency private async Task AlwaysIgnoreContentTypes(HttpContext context) { - foreach (var selector in Options.Value.IgnoredNonceScriptSelectors) + foreach (var selector in Options.Value.IgnoredScriptNonceSelectors) { if(await selector(context)) { @@ -101,7 +101,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency protected virtual string BuildContentSecurityPolicyValue(HttpContext context) { - if (!(Options.Value.UseContentSecurityPolicyNonce && + if (!(Options.Value.UseContentSecurityPolicyScriptNonce && context.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && nonce is string nonceValue && !string.IsNullOrEmpty(nonceValue))) { diff --git a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs index 7ec8dc453f..427aa9ad9a 100644 --- a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs +++ b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs @@ -9,21 +9,21 @@ public class AbpSecurityHeadersOptions { public bool UseContentSecurityPolicyHeader { get; set; } - public bool UseContentSecurityPolicyNonce { get; set; } + public bool UseContentSecurityPolicyScriptNonce { get; set; } public Dictionary> ContentSecurityPolicyValues { get; } public Dictionary Headers { get; } - public List>> IgnoredNonceScriptSelectors { get; } + public List>> IgnoredScriptNonceSelectors { get; } - public List IgnoredNonceScriptPaths { get; } + public List IgnoredScriptNoncePaths { get; } public AbpSecurityHeadersOptions() { Headers = new Dictionary(); ContentSecurityPolicyValues = new Dictionary>(); - IgnoredNonceScriptSelectors = new List>>(); - IgnoredNonceScriptPaths = new List(); + IgnoredScriptNonceSelectors = new List>>(); + IgnoredScriptNoncePaths = new List(); } }