Table of Contents

Class ApplicationSecurityHeadersOptions

Namespace
ProjectTemplate.Web.Options
Assembly
ProjectTemplate.Web.dll

Options to control which security-related HTTP headers are applied by the application.

public sealed class ApplicationSecurityHeadersOptions
Inheritance
ApplicationSecurityHeadersOptions
Inherited Members

Fields

SectionName

Gets the configuration section name used to bind security header settings.

public const string SectionName = "ProjectTemplate:SecurityHeaders"

Field Value

string

Properties

ContentSecurityPolicy

Gets or sets the Content-Security-Policy header value applied to responses.

public string ContentSecurityPolicy { get; set; }

Property Value

string

EnableContentSecurityPolicy

Gets or sets a value indicating whether the Content-Security-Policy header is applied.

public bool EnableContentSecurityPolicy { get; set; }

Property Value

bool

EnableCrossOriginHeaders

Gets or sets a value indicating whether cross-origin related headers are applied.

public bool EnableCrossOriginHeaders { get; set; }

Property Value

bool

EnablePermissionsPolicy

Gets or sets a value indicating whether the Permissions-Policy header is applied.

public bool EnablePermissionsPolicy { get; set; }

Property Value

bool

Enabled

Gets or sets a value indicating whether security headers are enabled.

public bool Enabled { get; set; }

Property Value

bool

ExcludedPathPrefixes

Gets or sets path prefixes that are excluded from applying the security headers.

public List<string> ExcludedPathPrefixes { get; set; }

Property Value

List<string>

Remarks

A configured list replaces these defaults rather than extending them. A blank configured entry is ignored, so a later configuration source can remove an inherited entry by overriding its index with an empty value.

PermissionsPolicy

Gets or sets the Permissions-Policy header value applied to responses. Set EnablePermissionsPolicy to false to omit the header.

public string PermissionsPolicy { get; set; }

Property Value

string