Browse Source

Change uses that are NonceScript to ScriptNonce

pull/16496/head
Salih 3 years ago
parent
commit
d3853c2b3b
  1. 2
      framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs
  2. 2
      framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs
  3. 8
      framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs
  4. 10
      framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs

2
framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs

@ -52,7 +52,7 @@ public class AbpTagHelperStyleService : AbpTagHelperResourceService
if (preload || Options.PreloadStylesByDefault || Options.PreloadStyles.Any(x => file.StartsWith(x, StringComparison.OrdinalIgnoreCase))) if (preload || Options.PreloadStylesByDefault || Options.PreloadStyles.Any(x => file.StartsWith(x, StringComparison.OrdinalIgnoreCase)))
{ {
output.Content.AppendHtml(SecurityHeadersOptions.UseContentSecurityPolicyNonce output.Content.AppendHtml(SecurityHeadersOptions.UseContentSecurityPolicyScriptNonce
? $"<link rel=\"preload\" href=\"{viewContext.GetUrlHelper().Content(file.EnsureStartsWith('~'))}\" as=\"style\" abp-csp-style />{Environment.NewLine}" ? $"<link rel=\"preload\" href=\"{viewContext.GetUrlHelper().Content(file.EnsureStartsWith('~'))}\" as=\"style\" abp-csp-style />{Environment.NewLine}"
: $"<link rel=\"preload\" href=\"{viewContext.GetUrlHelper().Content(file.EnsureStartsWith('~'))}\" as=\"style\" onload=\"this.rel='stylesheet'\" />{Environment.NewLine}"); : $"<link rel=\"preload\" href=\"{viewContext.GetUrlHelper().Content(file.EnsureStartsWith('~'))}\" as=\"style\" onload=\"this.rel='stylesheet'\" />{Environment.NewLine}");
} }

2
framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/NonceScriptTagHelper.cs → framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/ScriptNonceTagHelper.cs

@ -7,7 +7,7 @@ namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.TagHelpers;
[HtmlTargetElement("script")] [HtmlTargetElement("script")]
[HtmlTargetElement("body")] [HtmlTargetElement("body")]
public class NonceScriptTagHelper : AbpTagHelper public class ScriptNonceTagHelper : AbpTagHelper
{ {
[HtmlAttributeNotBound] [HtmlAttributeNotBound]
[ViewContext] [ViewContext]

8
framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersMiddleware.cs

@ -38,14 +38,14 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency
|| !Options.Value.UseContentSecurityPolicyHeader || !Options.Value.UseContentSecurityPolicyHeader
|| await AlwaysIgnoreContentTypes(context) || await AlwaysIgnoreContentTypes(context)
|| context.GetEndpoint() == null || context.GetEndpoint() == null
|| Options.Value.IgnoredNonceScriptPaths.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/')))) || Options.Value.IgnoredScriptNoncePaths.Any(x => context.Request.Path.StartsWithSegments(x.EnsureStartsWith('/'))))
{ {
AddOtherHeaders(context); AddOtherHeaders(context);
await next.Invoke(context); await next.Invoke(context);
return; return;
} }
if (Options.Value.UseContentSecurityPolicyNonce) if (Options.Value.UseContentSecurityPolicyScriptNonce)
{ {
var randomValue = Guid.NewGuid().ToString("N"); var randomValue = Guid.NewGuid().ToString("N");
context.Items.Add(AbpAspNetCoreConsts.ScriptNonceKey, randomValue); context.Items.Add(AbpAspNetCoreConsts.ScriptNonceKey, randomValue);
@ -80,7 +80,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency
private async Task<bool> AlwaysIgnoreContentTypes(HttpContext context) private async Task<bool> AlwaysIgnoreContentTypes(HttpContext context)
{ {
foreach (var selector in Options.Value.IgnoredNonceScriptSelectors) foreach (var selector in Options.Value.IgnoredScriptNonceSelectors)
{ {
if(await selector(context)) if(await selector(context))
{ {
@ -101,7 +101,7 @@ public class AbpSecurityHeadersMiddleware : IMiddleware, ITransientDependency
protected virtual string BuildContentSecurityPolicyValue(HttpContext context) protected virtual string BuildContentSecurityPolicyValue(HttpContext context)
{ {
if (!(Options.Value.UseContentSecurityPolicyNonce && if (!(Options.Value.UseContentSecurityPolicyScriptNonce &&
context.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) && context.Items.TryGetValue(AbpAspNetCoreConsts.ScriptNonceKey, out var nonce) &&
nonce is string nonceValue && !string.IsNullOrEmpty(nonceValue))) nonce is string nonceValue && !string.IsNullOrEmpty(nonceValue)))
{ {

10
framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/AbpSecurityHeadersOptions.cs

@ -9,21 +9,21 @@ public class AbpSecurityHeadersOptions
{ {
public bool UseContentSecurityPolicyHeader { get; set; } public bool UseContentSecurityPolicyHeader { get; set; }
public bool UseContentSecurityPolicyNonce { get; set; } public bool UseContentSecurityPolicyScriptNonce { get; set; }
public Dictionary<string, IEnumerable<string>> ContentSecurityPolicyValues { get; } public Dictionary<string, IEnumerable<string>> ContentSecurityPolicyValues { get; }
public Dictionary<string, string> Headers { get; } public Dictionary<string, string> Headers { get; }
public List<Func<HttpContext, Task<bool>>> IgnoredNonceScriptSelectors { get; } public List<Func<HttpContext, Task<bool>>> IgnoredScriptNonceSelectors { get; }
public List<string> IgnoredNonceScriptPaths { get; } public List<string> IgnoredScriptNoncePaths { get; }
public AbpSecurityHeadersOptions() public AbpSecurityHeadersOptions()
{ {
Headers = new Dictionary<string, string>(); Headers = new Dictionary<string, string>();
ContentSecurityPolicyValues = new Dictionary<string, IEnumerable<string>>(); ContentSecurityPolicyValues = new Dictionary<string, IEnumerable<string>>();
IgnoredNonceScriptSelectors = new List<Func<HttpContext, Task<bool>>>(); IgnoredScriptNonceSelectors = new List<Func<HttpContext, Task<bool>>>();
IgnoredNonceScriptPaths = new List<string>(); IgnoredScriptNoncePaths = new List<string>();
} }
} }

Loading…
Cancel
Save