Class SecurityHeadersTests
- Namespace
- ProjectTemplate.Web.Tests
- Assembly
- ProjectTemplate.Web.Tests.dll
Provides integration tests for configurable security header middleware behavior.
public sealed class SecurityHeadersTests
- Inheritance
-
SecurityHeadersTests
- Inherited Members
Methods
DefaultSecurityHeaders_AreApplied()
Verifies that default security headers are applied when security headers are enabled.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 21)]
public Task DefaultSecurityHeaders_AreApplied()
Returns
- Task
A task that represents the asynchronous test operation.
DisabledContentSecurityPolicy_DoesNotEmitContentSecurityPolicyHeader()
Verifies that the Content-Security-Policy header is not emitted when disabled.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 54)]
public Task DisabledContentSecurityPolicy_DoesNotEmitContentSecurityPolicyHeader()
Returns
- Task
A task that represents the asynchronous test operation.
DisabledCrossOriginHeaders_DoNotEmitCrossOriginHeaders()
Verifies that cross-origin headers are not emitted when disabled.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 100)]
public Task DisabledCrossOriginHeaders_DoNotEmitCrossOriginHeaders()
Returns
- Task
A task that represents the asynchronous test operation.
DisabledPermissionsPolicy_DoesNotEmitPermissionsPolicyHeader()
Verifies that the Permissions-Policy header is not emitted when disabled.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 77)]
public Task DisabledPermissionsPolicy_DoesNotEmitPermissionsPolicyHeader()
Returns
- Task
A task that represents the asynchronous test operation.
DisabledSecurityHeaders_DoNotEmitSecurityHeaders()
Verifies that no security headers are emitted when security headers are globally disabled.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 165)]
public Task DisabledSecurityHeaders_DoNotEmitSecurityHeaders()
Returns
- Task
A task that represents the asynchronous test operation.
ExcludedPathPrefixes_ApplyOnlyNoSniffSecurityHeader(string)
Verifies that configured excluded path prefixes receive only the X-Content-Type-Options header.
[Theory("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 187)]
[InlineData(new object?[] { "/health" })]
[InlineData(new object?[] { "/health/ready" })]
[InlineData(new object?[] { "/health/live" })]
[InlineData(new object?[] { "/metrics" })]
public Task ExcludedPathPrefixes_ApplyOnlyNoSniffSecurityHeader(string path)
Parameters
pathstringThe excluded request path to verify.
Returns
- Task
A task that represents the asynchronous test operation.
SecurityHeaders_CspEnabledWithEmptyPolicy_FailsStartup()
Verifies that startup validation fails when Content-Security-Policy is enabled but no policy value is configured.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 143)]
public void SecurityHeaders_CspEnabledWithEmptyPolicy_FailsStartup()
SecurityHeaders_InvalidExcludedPathPrefix_FailsStartup()
Verifies that startup validation fails when an excluded security-header path prefix does not start with '/'.
[Fact("/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/tests/ProjectTemplate.Web.Tests/SecurityHeadersTests.cs", 123)]
public void SecurityHeaders_InvalidExcludedPathPrefix_FailsStartup()