< Summary

Information
Class: ProjectTemplate.Web.Options.ApplicationSecurityHeadersOptions
Assembly: ProjectTemplate.Web
File(s): /home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Options/ApplicationSecurityHeadersOptions.cs
Line coverage
100%
Covered lines: 13
Uncovered lines: 0
Coverable lines: 13
Total lines: 65
Line coverage: 100%
Branch coverage
N/A
Covered branches: 0
Total branches: 0
Branch coverage: N/A
Method coverage

Feature is only available for sponsors

Upgrade to PRO version

Metrics

MethodBranch coverage Crap Score Cyclomatic complexity Line coverage
.ctor()100%11100%

File(s)

/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Options/ApplicationSecurityHeadersOptions.cs

#LineLine coverage
 1namespace ProjectTemplate.Web.Options;
 2
 3/// <summary>
 4/// Options to control which security-related HTTP headers are applied by the application.
 5/// </summary>
 6public sealed class ApplicationSecurityHeadersOptions
 7{
 8    /// <summary>
 9    /// Gets the configuration section name used to bind security header settings.
 10    /// </summary>
 11    public const string SectionName = "ProjectTemplate:SecurityHeaders";
 12
 13    /// <summary>
 14    /// Gets or sets a value indicating whether security headers are enabled.
 15    /// </summary>
 16    public bool Enabled { get; set; } = true;
 17
 18    /// <summary>
 19    /// Gets or sets a value indicating whether the Content-Security-Policy header is applied.
 20    /// </summary>
 21    public bool EnableContentSecurityPolicy { get; set; } = true;
 22
 23    /// <summary>
 24    /// Gets or sets a value indicating whether the Permissions-Policy header is applied.
 25    /// </summary>
 26    public bool EnablePermissionsPolicy { get; set; } = true;
 27
 28    /// <summary>
 29    /// Gets or sets a value indicating whether cross-origin related headers are applied.
 30    /// </summary>
 31    public bool EnableCrossOriginHeaders { get; set; } = true;
 32
 33    /// <summary>
 34    /// Gets or sets the Content-Security-Policy header value applied to responses.
 35    /// </summary>
 36    public string ContentSecurityPolicy { get; set; } =
 20137        "default-src 'self'; " +
 20138        "base-uri 'self'; " +
 20139        "object-src 'none'; " +
 20140        "frame-ancestors 'none'; " +
 20141        "form-action 'self'; " +
 20142        "img-src 'self' data:; " +
 20143        "script-src 'self'; " +
 20144        "style-src 'self';";
 45
 46    /// <summary>
 47    /// Gets or sets the Permissions-Policy header value applied to responses.
 48    /// Set EnablePermissionsPolicy to false to omit the header.
 49    /// </summary>
 50    public string PermissionsPolicy { get; set; } =
 20151        "camera=(), microphone=(), geolocation=(), payment=(), usb=(), fullscreen=(self)";
 52
 53    /// <summary>
 54    /// Gets or sets path prefixes that are excluded from applying the security headers.
 55    /// </summary>
 56    /// <remarks>
 57    /// A configured list replaces these defaults rather than extending them. A blank configured entry is ignored, so a
 58    /// later configuration source can remove an inherited entry by overriding its index with an empty value.
 59    /// </remarks>
 60    public List<string> ExcludedPathPrefixes { get; set; } =
 20161    [
 20162            "/health",
 20163            "/metrics"
 20164    ];
 65}

Methods/Properties

.ctor()