Class ApplicationSecurityHeadersOptions
- Namespace
- ProjectTemplate.Web.Options
- Assembly
- ProjectTemplate.Web.dll
Options to control which security-related HTTP headers are applied by the application.
public sealed class ApplicationSecurityHeadersOptions
- Inheritance
-
ApplicationSecurityHeadersOptions
- Inherited Members
Fields
SectionName
Gets the configuration section name used to bind security header settings.
public const string SectionName = "ProjectTemplate:SecurityHeaders"
Field Value
Properties
ContentSecurityPolicy
Gets or sets the Content-Security-Policy header value applied to responses.
public string ContentSecurityPolicy { get; set; }
Property Value
EnableContentSecurityPolicy
Gets or sets a value indicating whether the Content-Security-Policy header is applied.
public bool EnableContentSecurityPolicy { get; set; }
Property Value
EnableCrossOriginHeaders
Gets or sets a value indicating whether cross-origin related headers are applied.
public bool EnableCrossOriginHeaders { get; set; }
Property Value
EnablePermissionsPolicy
Gets or sets a value indicating whether the Permissions-Policy header is applied.
public bool EnablePermissionsPolicy { get; set; }
Property Value
Enabled
Gets or sets a value indicating whether security headers are enabled.
public bool Enabled { get; set; }
Property Value
ExcludedPathPrefixes
Gets or sets path prefixes that are excluded from applying the security headers.
public List<string> ExcludedPathPrefixes { get; set; }
Property Value
Remarks
A configured list replaces these defaults rather than extending them. A blank configured entry is ignored, so a later configuration source can remove an inherited entry by overriding its index with an empty value.
PermissionsPolicy
Gets or sets the Permissions-Policy header value applied to responses. Set EnablePermissionsPolicy to false to omit the header.
public string PermissionsPolicy { get; set; }