From f29e61444009f6ea7c737ad1d4dc5bd06429bded Mon Sep 17 00:00:00 2001 From: Engincan VESKE <43685404+EngincanV@users.noreply.github.com> Date: Tue, 6 Jun 2023 09:40:45 +0300 Subject: [PATCH] Update POST.md --- .../Blog-Posts/2023-06-05 v7_3_Preview/POST.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/docs/en/Blog-Posts/2023-06-05 v7_3_Preview/POST.md b/docs/en/Blog-Posts/2023-06-05 v7_3_Preview/POST.md index d79a1cb490..6ed4087dd4 100644 --- a/docs/en/Blog-Posts/2023-06-05 v7_3_Preview/POST.md +++ b/docs/en/Blog-Posts/2023-06-05 v7_3_Preview/POST.md @@ -49,6 +49,7 @@ In this section, I will introduce some major features released in this version. * ABP CLI: switch-to-local command * Monitoring Distributed Events * Ordering of the Local Event Handlers +* Nonce attribute support for Content Security Policy (CSP) * Other News ### Introducing the Volo.Abp.Imaging packages @@ -117,6 +118,22 @@ By default, all event handlers have an order value of 0. Thus, if you want to ta > See the documentation to learn more: [https://docs.abp.io/en/abp/7.3/Local-Event-Bus](https://docs.abp.io/en/abp/7.3/Local-Event-Bus) +### Nonce attribute support for Content Security Policy (CSP) + +ABP Framework supports adding unique value to nonce attribute for script tags which can be used by Content Security Policy to determine whether or not a given fetch will be allowed to proceed for a given element. In other words, it provides a mechanism to execute only correct script tags with the correct nonce value. + +This feature is disabled by default. You can enable it by setting the *UseContentSecurityPolicyScriptNonce* property of the `AbpSecurityHeadersOptions` class to **true**: + +```csharp +Configure(options => +{ + //adding script-src nonce + options.UseContentSecurityPolicyScriptNonce = true; //false by default +}); +``` + +> See the [Security Headers](https://docs.abp.io/en/abp/7.3/UI/AspNetCore/Security-Headers) documentation for more information. + ### Other News * Upgraded the [Blazorise](https://blazorise.com/) library to v1.2.3 for Blazor UI. After the upgrade, ensure that all Blazorise-related packages are using v1.2.3 in your application.