committed by
GitHub
7 changed files with 427 additions and 170 deletions
@ -1,16 +1,20 @@ |
|||
<!DOCTYPE html> |
|||
<html lang="en"> |
|||
<head> |
|||
<meta charset="utf-8" /> |
|||
<title>EShopOnAbp</title> |
|||
<base href="/" /> |
|||
|
|||
<meta name="viewport" content="width=device-width, initial-scale=1" /> |
|||
<link rel="icon" type="image/x-icon" href="favicon.ico" /> |
|||
</head> |
|||
<body class="bg-light"> |
|||
<app-root> |
|||
<div class="donut centered"></div> |
|||
</app-root> |
|||
</body> |
|||
<head> |
|||
<meta charset="utf-8" /> |
|||
<meta http-equiv="Content-Security-Policy" content="upgrade-insecure-requests"> |
|||
<title>EShopOnAbp</title> |
|||
<base href="/" /> |
|||
|
|||
<meta name="viewport" content="width=device-width, initial-scale=1" /> |
|||
<link rel="icon" type="image/x-icon" href="favicon.ico" /> |
|||
</head> |
|||
|
|||
<body class="bg-light"> |
|||
<app-root> |
|||
<div class="donut centered"></div> |
|||
</app-root> |
|||
</body> |
|||
|
|||
</html> |
|||
|
|||
@ -0,0 +1,70 @@ |
|||
using Microsoft.AspNetCore.Builder; |
|||
using Microsoft.AspNetCore.Http; |
|||
|
|||
namespace Microsoft.Extensions.DependencyInjection |
|||
{ |
|||
public static class SameSiteCookiesServiceCollectionExtensions |
|||
{ |
|||
public static IServiceCollection AddSameSiteCookiePolicy(this IServiceCollection services) |
|||
{ |
|||
services.Configure<CookiePolicyOptions>(options => |
|||
{ |
|||
options.MinimumSameSitePolicy = SameSiteMode.Unspecified; |
|||
options.OnAppendCookie = cookieContext => |
|||
CheckSameSite(cookieContext.Context, cookieContext.CookieOptions); |
|||
options.OnDeleteCookie = cookieContext => |
|||
CheckSameSite(cookieContext.Context, cookieContext.CookieOptions); |
|||
}); |
|||
|
|||
return services; |
|||
} |
|||
|
|||
private static void CheckSameSite(HttpContext httpContext, CookieOptions options) |
|||
{ |
|||
if (options.SameSite == SameSiteMode.None) |
|||
{ |
|||
var userAgent = httpContext.Request.Headers["User-Agent"].ToString(); |
|||
if (!httpContext.Request.IsHttps || DisallowsSameSiteNone(userAgent)) |
|||
{ |
|||
// For .NET Core < 3.1 set SameSite = (SameSiteMode)(-1)
|
|||
options.SameSite = SameSiteMode.Unspecified; |
|||
} |
|||
} |
|||
} |
|||
|
|||
private static bool DisallowsSameSiteNone(string userAgent) |
|||
{ |
|||
// Cover all iOS based browsers here. This includes:
|
|||
// - Safari on iOS 12 for iPhone, iPod Touch, iPad
|
|||
// - WkWebview on iOS 12 for iPhone, iPod Touch, iPad
|
|||
// - Chrome on iOS 12 for iPhone, iPod Touch, iPad
|
|||
// All of which are broken by SameSite=None, because they use the iOS networking stack
|
|||
if (userAgent.Contains("CPU iPhone OS 12") || userAgent.Contains("iPad; CPU OS 12")) |
|||
{ |
|||
return true; |
|||
} |
|||
|
|||
// Cover Mac OS X based browsers that use the Mac OS networking stack. This includes:
|
|||
// - Safari on Mac OS X.
|
|||
// This does not include:
|
|||
// - Chrome on Mac OS X
|
|||
// Because they do not use the Mac OS networking stack.
|
|||
if (userAgent.Contains("Macintosh; Intel Mac OS X 10_14") && |
|||
userAgent.Contains("Version/") && userAgent.Contains("Safari")) |
|||
{ |
|||
return true; |
|||
} |
|||
|
|||
// Cover Chrome 50-69, because some versions are broken by SameSite=None,
|
|||
// and none in this range require it.
|
|||
// Note: this covers some pre-Chromium Edge versions,
|
|||
// but pre-Chromium Edge does not require SameSite=None.
|
|||
if (userAgent.Contains("Chrome/5") || userAgent.Contains("Chrome/6")) |
|||
{ |
|||
return true; |
|||
} |
|||
|
|||
return false; |
|||
} |
|||
} |
|||
} |
|||
@ -1,15 +1,174 @@ |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name administration-service; |
|||
server_name eshop-st-administration; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-key.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://administration-service:80; |
|||
proxy_pass http://eshop-st-administration:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-identity; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-identity:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-authserver; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-authserver:80; |
|||
proxy_set_header Host $host; |
|||
add_header from-ingress true; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-web; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-web:80; |
|||
proxy_set_header Host $host; |
|||
|
|||
proxy_buffer_size 128k; |
|||
proxy_buffers 4 256k; |
|||
proxy_busy_buffers_size 256k; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-public-web; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-public-web:80; |
|||
proxy_set_header Host $host; |
|||
|
|||
proxy_buffer_size 128k; |
|||
proxy_buffers 4 256k; |
|||
proxy_busy_buffers_size 256k; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-basket; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-basket:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-catalog; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-catalog:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-ordering; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-ordering:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-payment; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-payment:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-gateway-web-public; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-gateway-web-public:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
server { |
|||
listen 80; |
|||
listen 443 ssl; |
|||
server_name eshop-st-gateway-web; |
|||
|
|||
ssl_certificate /etc/nginx/certs/app-cert.pem; |
|||
ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; |
|||
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
|||
ssl_prefer_server_ciphers on; |
|||
|
|||
location / { |
|||
proxy_pass http://eshop-st-gateway-web:80; |
|||
proxy_set_header Host $host; |
|||
} |
|||
} |
|||
@ -0,0 +1,23 @@ |
|||
{ |
|||
"production": true, |
|||
"application": { |
|||
"baseUrl":"https://eshop-st-web", |
|||
"name": "EShopOnAbp", |
|||
"logoUrl": "" |
|||
}, |
|||
"oAuthConfig": { |
|||
"issuer": "https://eshop-st-authserver", |
|||
"redirectUri": "https://eshop-st-web", |
|||
"clientId": "Web", |
|||
"responseType": "code", |
|||
"scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService", |
|||
"strictDiscoveryDocumentValidation": false, |
|||
"requireHttps": false |
|||
}, |
|||
"apis": { |
|||
"default": { |
|||
"url": "https://eshop-st-gateway-web", |
|||
"rootNamespace": "EShopOnAbp" |
|||
} |
|||
} |
|||
} |
|||
Loading…
Reference in new issue