From fc6f75f47280d98c599cfcfbed3275581f589617 Mon Sep 17 00:00:00 2001 From: Salih Date: Fri, 5 May 2023 11:13:33 +0300 Subject: [PATCH] Add abp-csp-loader script if UseContentSecurityPolicyNonce is true --- .../AbpPreloadStyleLoadScriptContributor.cs | 11 ----------- .../Bundling/TagHelpers/AbpTagHelperStyleService.cs | 10 ++++++++-- .../Bundling/SharedThemeGlobalScriptContributor.cs | 12 +++++++++++- ...preload-style-load.js => abp-csp-style-loader.js} | 2 +- 4 files changed, 20 insertions(+), 15 deletions(-) delete mode 100644 framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/Contributors/AbpPreloadStyleLoadScriptContributor.cs rename framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/{preload-style-load.js => abp-csp-style-loader.js} (51%) diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/Contributors/AbpPreloadStyleLoadScriptContributor.cs b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/Contributors/AbpPreloadStyleLoadScriptContributor.cs deleted file mode 100644 index c258e89e09..0000000000 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/Contributors/AbpPreloadStyleLoadScriptContributor.cs +++ /dev/null @@ -1,11 +0,0 @@ -using System.Collections.Generic; - -namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.Contributors; - -public class AbpPreloadStyleLoadScriptContributor : BundleContributor -{ - public override void ConfigureBundle(BundleConfigurationContext context) - { - context.Files.AddIfNotContains("/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/preload-style-load.js"); - } -} \ No newline at end of file diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs index 5869699f1e..f399a62e10 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Bundling/Volo/Abp/AspNetCore/Mvc/UI/Bundling/TagHelpers/AbpTagHelperStyleService.cs @@ -8,19 +8,23 @@ using Microsoft.AspNetCore.Mvc.ViewFeatures; using Microsoft.AspNetCore.Razor.TagHelpers; using Microsoft.Extensions.Hosting; using Microsoft.Extensions.Options; +using Volo.Abp.AspNetCore.Security; namespace Volo.Abp.AspNetCore.Mvc.UI.Bundling.TagHelpers; public class AbpTagHelperStyleService : AbpTagHelperResourceService { + private readonly IOptions _securityHeadersOptions; public AbpTagHelperStyleService( IBundleManager bundleManager, IOptions options, - IWebHostEnvironment hostingEnvironment) : base( + IWebHostEnvironment hostingEnvironment, + IOptions securityHeadersOptions) : base( bundleManager, options, hostingEnvironment) { + _securityHeadersOptions = securityHeadersOptions; } protected override void CreateBundle(string bundleName, List bundleItems) @@ -48,7 +52,9 @@ public class AbpTagHelperStyleService : AbpTagHelperResourceService if (preload || Options.PreloadStylesByDefault || Options.PreloadStyles.Any(x => file.StartsWith(x, StringComparison.OrdinalIgnoreCase))) { - output.Content.AppendHtml($"{Environment.NewLine}"); + output.Content.AppendHtml(_securityHeadersOptions.Value.UseContentSecurityPolicyNonce + ? $"{Environment.NewLine}" + : $"{Environment.NewLine}"); } else { diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs index 2127b3f43a..674581dfe5 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/Bundling/SharedThemeGlobalScriptContributor.cs @@ -1,4 +1,7 @@ -using Volo.Abp.AspNetCore.Mvc.UI.Bundling; +using System.Collections.Generic; +using Microsoft.Extensions.DependencyInjection; +using Microsoft.Extensions.Options; +using Volo.Abp.AspNetCore.Mvc.UI.Bundling; using Volo.Abp.AspNetCore.Mvc.UI.Packages.Bootstrap; using Volo.Abp.AspNetCore.Mvc.UI.Packages.BootstrapDatepicker; using Volo.Abp.AspNetCore.Mvc.UI.Packages.BootstrapDaterangepicker; @@ -13,6 +16,7 @@ using Volo.Abp.AspNetCore.Mvc.UI.Packages.Select2; using Volo.Abp.AspNetCore.Mvc.UI.Packages.SweetAlert2; using Volo.Abp.AspNetCore.Mvc.UI.Packages.Timeago; using Volo.Abp.AspNetCore.Mvc.UI.Packages.Toastr; +using Volo.Abp.AspNetCore.Security; using Volo.Abp.Modularity; namespace Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared.Bundling; @@ -35,6 +39,7 @@ namespace Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared.Bundling; )] public class SharedThemeGlobalScriptContributor : BundleContributor { + public override void ConfigureBundle(BundleConfigurationContext context) { context.Files.AddRange(new[] @@ -49,5 +54,10 @@ public class SharedThemeGlobalScriptContributor : BundleContributor "/libs/abp/aspnetcore-mvc-ui-theme-shared/sweetalert2/abp-sweetalert2.js", "/libs/abp/aspnetcore-mvc-ui-theme-shared/toastr/abp-toastr.js" }); + + if (context.ServiceProvider.GetRequiredService>().Value.UseContentSecurityPolicyNonce) + { + context.Files.AddIfNotContains("/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js"); + } } } diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/preload-style-load.js b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js similarity index 51% rename from framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/preload-style-load.js rename to framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js index 9e7770e44a..102c115c25 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/preload-style-load.js +++ b/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Shared/wwwroot/libs/abp/aspnetcore-mvc-ui-theme-shared/csp/abp-csp-style-loader.js @@ -1,4 +1,4 @@ $(function (){ - let preLoads = $("link[rel=preload][as=style]"); + let preLoads = $("link[abp-csp-style]"); preLoads.attr("rel", "stylesheet"); }) \ No newline at end of file