Table of Contents

Class SecurityHeadersTests

Namespace
ProjectTemplate.Web.Tests
Assembly
ProjectTemplate.Web.Tests.dll

Provides integration tests for configurable security header middleware behavior.

public sealed class SecurityHeadersTests
Inheritance
SecurityHeadersTests
Inherited Members

Methods

DefaultSecurityHeaders_AreApplied()

Verifies that default security headers are applied when security headers are enabled.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 21)]
public Task DefaultSecurityHeaders_AreApplied()

Returns

Task

A task that represents the asynchronous test operation.

DisabledContentSecurityPolicy_DoesNotEmitContentSecurityPolicyHeader()

Verifies that the Content-Security-Policy header is not emitted when disabled.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 54)]
public Task DisabledContentSecurityPolicy_DoesNotEmitContentSecurityPolicyHeader()

Returns

Task

A task that represents the asynchronous test operation.

DisabledCrossOriginHeaders_DoNotEmitCrossOriginHeaders()

Verifies that cross-origin headers are not emitted when disabled.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 100)]
public Task DisabledCrossOriginHeaders_DoNotEmitCrossOriginHeaders()

Returns

Task

A task that represents the asynchronous test operation.

DisabledPermissionsPolicy_DoesNotEmitPermissionsPolicyHeader()

Verifies that the Permissions-Policy header is not emitted when disabled.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 77)]
public Task DisabledPermissionsPolicy_DoesNotEmitPermissionsPolicyHeader()

Returns

Task

A task that represents the asynchronous test operation.

DisabledSecurityHeaders_DoNotEmitSecurityHeaders()

Verifies that no security headers are emitted when security headers are globally disabled.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 165)]
public Task DisabledSecurityHeaders_DoNotEmitSecurityHeaders()

Returns

Task

A task that represents the asynchronous test operation.

ExcludedPathPrefixes_ApplyOnlyNoSniffSecurityHeader(string)

Verifies that configured excluded path prefixes receive only the X-Content-Type-Options header.

[Theory("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 187)]
[InlineData(new object?[] { "/health" })]
[InlineData(new object?[] { "/health/ready" })]
[InlineData(new object?[] { "/health/live" })]
[InlineData(new object?[] { "/metrics" })]
public Task ExcludedPathPrefixes_ApplyOnlyNoSniffSecurityHeader(string path)

Parameters

path string

The excluded request path to verify.

Returns

Task

A task that represents the asynchronous test operation.

SecurityHeaders_CspEnabledWithEmptyPolicy_FailsStartup()

Verifies that startup validation fails when Content-Security-Policy is enabled but no policy value is configured.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 143)]
public void SecurityHeaders_CspEnabledWithEmptyPolicy_FailsStartup()

SecurityHeaders_InvalidExcludedPathPrefix_FailsStartup()

Verifies that startup validation fails when an excluded security-header path prefix does not start with '/'.

[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 123)]
public void SecurityHeaders_InvalidExcludedPathPrefix_FailsStartup()