Table of Contents

Class SecurityHeadersExtensions

Namespace
ProjectTemplate.Web.Extensions
Assembly
ProjectTemplate.Web.dll

Provides extension methods to register and enable security headers functionality.

public static class SecurityHeadersExtensions
Inheritance
SecurityHeadersExtensions
Inherited Members

Methods

AddApplicationSecurityHeaders(IServiceCollection, IConfiguration)

Registers the ApplicationSecurityHeadersOptions configuration section with the DI container.

public static IServiceCollection AddApplicationSecurityHeaders(this IServiceCollection services, IConfiguration configuration)

Parameters

services IServiceCollection

The service collection to add the configuration to.

configuration IConfiguration

The application configuration containing the "SecurityHeaders" section.

Returns

IServiceCollection

The original IServiceCollection for chaining.

UseApplicationHsts(WebApplication)

Adds HTTP Strict Transport Security (HSTS) outside the development environment.

public static WebApplication UseApplicationHsts(this WebApplication app)

Parameters

app WebApplication

The WebApplication used to configure the request pipeline.

Returns

WebApplication

The same WebApplication instance for chaining.

Remarks

HSTS is skipped in development so browsers do not pin localhost to HTTPS. UseProblemDetails registers it between the exception handler and the status-code page branches, ahead of HTTPS redirection.

UseApplicationSecurityHeaders(IApplicationBuilder)

Adds the security headers middleware to the application's request pipeline.

public static IApplicationBuilder UseApplicationSecurityHeaders(this IApplicationBuilder app)

Parameters

app IApplicationBuilder

The application builder used to configure the request pipeline.

Returns

IApplicationBuilder

The original IApplicationBuilder for chaining.