| | | 1 | | using ProjectTemplate.Web.Authentication.Extensions; |
| | | 2 | | using ProjectTemplate.Web.ErrorHandling; |
| | | 3 | | |
| | | 4 | | namespace ProjectTemplate.Web.Extensions; |
| | | 5 | | |
| | | 6 | | /// <summary> |
| | | 7 | | /// Provides extension methods to configure the application's middleware pipeline |
| | | 8 | | /// with a predefined, order-sensitive sequence suitable for this template. |
| | | 9 | | /// </summary> |
| | | 10 | | public static class PipelineExtensions |
| | | 11 | | { |
| | | 12 | | /// <summary> |
| | | 13 | | /// Configures the middleware pipeline for the specified <see cref="WebApplication"/>. |
| | | 14 | | /// The ordering includes forwarded headers, request logging, exception handling, |
| | | 15 | | /// security headers, HTTPS redirection, static files, routing, rate limiting, and |
| | | 16 | | /// (optionally) authentication/authorization and endpoint mapping. |
| | | 17 | | /// </summary> |
| | | 18 | | /// <param name="app">The <see cref="WebApplication"/> to configure.</param> |
| | | 19 | | /// <returns>The same <see cref="WebApplication"/> instance for chaining.</returns> |
| | | 20 | | public static WebApplication UseApplicationPipeline(this WebApplication app) |
| | | 21 | | { |
| | | 22 | | // Keep this sequence aligned with ADR-0002 and the middleware documentation. |
| | | 23 | | // Move order-sensitive middleware only after reviewing the documented invariants. |
| | | 24 | | |
| | | 25 | | // 1. Proxy/load balancer correction must happen early. |
| | 110 | 26 | | app.UseApplicationForwardedHeaders(); |
| | | 27 | | |
| | | 28 | | // 2. Structured request logging should see corrected scheme, host, and client IP. |
| | 107 | 29 | | app.UseApplicationRequestLogging(); |
| | | 30 | | |
| | | 31 | | // 3. Centralized exception and status-code handling. This is the single registration: it adds the |
| | | 32 | | // developer exception page or the production exception handler and HSTS (UseApplicationHsts, outside |
| | | 33 | | // development), then branches status-code handling between Problem Details responses and the |
| | | 34 | | // re-executed browser error page. |
| | 107 | 35 | | app.UseProblemDetails(); |
| | | 36 | | |
| | | 37 | | // 4. Optional security response headers. |
| | 107 | 38 | | app.UseApplicationSecurityHeaders(); |
| | | 39 | | |
| | | 40 | | // 5. HTTPS enforcement. |
| | 107 | 41 | | app.UseHttpsRedirection(); |
| | | 42 | | |
| | | 43 | | // 6. Static files before routing if using MVC/Razor UI. |
| | 107 | 44 | | app.UseStaticFiles(); |
| | | 45 | | |
| | | 46 | | // 7. Routing. |
| | 107 | 47 | | app.UseRouting(); |
| | | 48 | | |
| | | 49 | | // CORS is intentionally not enabled by default in the template. If your app needs cross-origin |
| | | 50 | | // access, register an explicit policy with AddCors and insert UseCors between routing and auth. |
| | | 51 | | |
| | | 52 | | // 8. Rate limiting after routing when endpoint-specific policies are used. |
| | 107 | 53 | | app.UseRateLimiter(); |
| | | 54 | | |
| | | 55 | | // 9. Authentication and authorization. |
| | 107 | 56 | | app.UseApplicationAuthentication(); |
| | 100 | 57 | | app.UseAuthorization(); |
| | | 58 | | |
| | | 59 | | // 10. Endpoint mapping. |
| | 100 | 60 | | app.MapControllers(); |
| | 98 | 61 | | app.MapRazorPages(); |
| | | 62 | | |
| | 98 | 63 | | return app; |
| | | 64 | | } |
| | | 65 | | } |