< Summary

Information
Class: ProjectTemplate.Web.Extensions.SecurityHeadersExtensions
Assembly: ProjectTemplate.Web
File(s): /home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Extensions/SecurityHeadersExtensions.cs
Line coverage
100%
Covered lines: 30
Uncovered lines: 0
Coverable lines: 30
Total lines: 83
Line coverage: 100%
Branch coverage
100%
Covered branches: 2
Total branches: 2
Branch coverage: 100%
Method coverage

Feature is only available for sponsors

Upgrade to PRO version

Metrics

MethodBranch coverage Crap Score Cyclomatic complexity Line coverage
AddApplicationSecurityHeaders(...)100%11100%
UseApplicationSecurityHeaders(...)100%11100%
UseApplicationHsts(...)100%22100%

File(s)

/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Extensions/SecurityHeadersExtensions.cs

#LineLine coverage
 1using ProjectTemplate.Web.Middleware;
 2using ProjectTemplate.Web.Options;
 3
 4namespace ProjectTemplate.Web.Extensions;
 5
 6/// <summary>
 7/// Provides extension methods to register and enable security headers functionality.
 8/// </summary>
 9public static class SecurityHeadersExtensions
 10{
 11    /// <summary>
 12    /// Registers the <see cref="ApplicationSecurityHeadersOptions"/> configuration section with the DI container.
 13    /// </summary>
 14    /// <param name="services">The service collection to add the configuration to.</param>
 15    /// <param name="configuration">The application configuration containing the "SecurityHeaders" section.</param>
 16    /// <returns>The original <see cref="IServiceCollection"/> for chaining.</returns>
 17    public static IServiceCollection AddApplicationSecurityHeaders(
 18        this IServiceCollection services,
 19        IConfiguration configuration)
 20    {
 11521        IConfigurationSection section = configuration.GetSection(ApplicationSecurityHeadersOptions.SectionName);
 22
 11523        services
 11524            .AddOptions<ApplicationSecurityHeadersOptions>()
 11525            .Bind(section)
 11526            .Configure(options => ConfigurationListBinding.ReplaceWithConfiguredValues(
 11527                options.ExcludedPathPrefixes,
 11528                section.GetSection(nameof(ApplicationSecurityHeadersOptions.ExcludedPathPrefixes))))
 11529            .Validate(
 11530                options =>
 11531                    !options.EnableContentSecurityPolicy ||
 11532                    !string.IsNullOrWhiteSpace(options.ContentSecurityPolicy),
 11533                "ProjectTemplate:SecurityHeaders:ContentSecurityPolicy is required when CSP is enabled.")
 11534            .Validate(
 11535                options =>
 11536                    !options.EnablePermissionsPolicy ||
 11537                    !string.IsNullOrWhiteSpace(options.PermissionsPolicy),
 11538                "ProjectTemplate:SecurityHeaders:PermissionsPolicy is required when Permissions-Policy is enabled.")
 11539            .Validate(
 11540                options =>
 11541                    options.ExcludedPathPrefixes.All(path =>
 11542                        !string.IsNullOrWhiteSpace(path) &&
 11543                        path.StartsWith('/')),
 11544                "ProjectTemplate:SecurityHeaders:ExcludedPathPrefixes values must start with '/'.")
 11545            .ValidateOnStart();
 46
 11547        return services;
 48    }
 49
 50    /// <summary>
 51    /// Adds the security headers middleware to the application's request pipeline.
 52    /// </summary>
 53    /// <param name="app">The application builder used to configure the request pipeline.</param>
 54    /// <returns>The original <see cref="IApplicationBuilder"/> for chaining.</returns>
 55    public static IApplicationBuilder UseApplicationSecurityHeaders(
 56        this IApplicationBuilder app)
 57    {
 10758        return app.UseMiddleware<SecurityHeadersMiddleware>();
 59    }
 60
 61    /// <summary>
 62    /// Adds HTTP Strict Transport Security (HSTS) outside the development environment.
 63    /// </summary>
 64    /// <remarks>
 65    /// HSTS is skipped in development so browsers do not pin localhost to HTTPS. <c>UseProblemDetails</c> registers
 66    /// it between the exception handler and the status-code page branches, ahead of HTTPS redirection.
 67    /// </remarks>
 68    /// <param name="app">The <see cref="WebApplication"/> used to configure the request pipeline.</param>
 69    /// <returns>The same <see cref="WebApplication"/> instance for chaining.</returns>
 70    public static WebApplication UseApplicationHsts(
 71        this WebApplication app)
 72    {
 10973        ArgumentNullException.ThrowIfNull(app);
 74
 10975        if (!app.Environment.IsDevelopment())
 76        {
 10877            app.UseHsts();
 78        }
 79
 10980        return app;
 81    }
 82}
 83