< Summary

Information
Class: ProjectTemplate.Web.Extensions.PipelineExtensions
Assembly: ProjectTemplate.Web
File(s): /home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Extensions/PipelineExtensions.cs
Line coverage
100%
Covered lines: 13
Uncovered lines: 0
Coverable lines: 13
Total lines: 65
Line coverage: 100%
Branch coverage
N/A
Covered branches: 0
Total branches: 0
Branch coverage: N/A
Method coverage

Feature is only available for sponsors

Upgrade to PRO version

Metrics

MethodBranch coverage Crap Score Cyclomatic complexity Line coverage
UseApplicationPipeline(...)100%11100%

File(s)

/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Extensions/PipelineExtensions.cs

#LineLine coverage
 1using ProjectTemplate.Web.Authentication.Extensions;
 2using ProjectTemplate.Web.ErrorHandling;
 3
 4namespace ProjectTemplate.Web.Extensions;
 5
 6/// <summary>
 7/// Provides extension methods to configure the application's middleware pipeline
 8/// with a predefined, order-sensitive sequence suitable for this template.
 9/// </summary>
 10public static class PipelineExtensions
 11{
 12    /// <summary>
 13    /// Configures the middleware pipeline for the specified <see cref="WebApplication"/>.
 14    /// The ordering includes forwarded headers, request logging, exception handling,
 15    /// security headers, HTTPS redirection, static files, routing, rate limiting, and
 16    /// (optionally) authentication/authorization and endpoint mapping.
 17    /// </summary>
 18    /// <param name="app">The <see cref="WebApplication"/> to configure.</param>
 19    /// <returns>The same <see cref="WebApplication"/> instance for chaining.</returns>
 20    public static WebApplication UseApplicationPipeline(this WebApplication app)
 21    {
 22        // Keep this sequence aligned with ADR-0002 and the middleware documentation.
 23        // Move order-sensitive middleware only after reviewing the documented invariants.
 24
 25        // 1. Proxy/load balancer correction must happen early.
 11026        app.UseApplicationForwardedHeaders();
 27
 28        // 2. Structured request logging should see corrected scheme, host, and client IP.
 10729        app.UseApplicationRequestLogging();
 30
 31        // 3. Centralized exception and status-code handling. This is the single registration: it adds the
 32        //    developer exception page or the production exception handler and HSTS (UseApplicationHsts, outside
 33        //    development), then branches status-code handling between Problem Details responses and the
 34        //    re-executed browser error page.
 10735        app.UseProblemDetails();
 36
 37        // 4. Optional security response headers.
 10738        app.UseApplicationSecurityHeaders();
 39
 40        // 5. HTTPS enforcement.
 10741        app.UseHttpsRedirection();
 42
 43        // 6. Static files before routing if using MVC/Razor UI.
 10744        app.UseStaticFiles();
 45
 46        // 7. Routing.
 10747        app.UseRouting();
 48
 49        // CORS is intentionally not enabled by default in the template. If your app needs cross-origin
 50        // access, register an explicit policy with AddCors and insert UseCors between routing and auth.
 51
 52        // 8. Rate limiting after routing when endpoint-specific policies are used.
 10753        app.UseRateLimiter();
 54
 55        // 9. Authentication and authorization.
 10756        app.UseApplicationAuthentication();
 10057        app.UseAuthorization();
 58
 59        // 10. Endpoint mapping.
 10060        app.MapControllers();
 9861        app.MapRazorPages();
 62
 9863        return app;
 64    }
 65}