| | | 1 | | using ProjectTemplate.Web.Middleware; |
| | | 2 | | using ProjectTemplate.Web.Options; |
| | | 3 | | |
| | | 4 | | namespace ProjectTemplate.Web.Extensions; |
| | | 5 | | |
| | | 6 | | /// <summary> |
| | | 7 | | /// Provides extension methods to register and enable security headers functionality. |
| | | 8 | | /// </summary> |
| | | 9 | | public static class SecurityHeadersExtensions |
| | | 10 | | { |
| | | 11 | | /// <summary> |
| | | 12 | | /// Registers the <see cref="ApplicationSecurityHeadersOptions"/> configuration section with the DI container. |
| | | 13 | | /// </summary> |
| | | 14 | | /// <param name="services">The service collection to add the configuration to.</param> |
| | | 15 | | /// <param name="configuration">The application configuration containing the "SecurityHeaders" section.</param> |
| | | 16 | | /// <returns>The original <see cref="IServiceCollection"/> for chaining.</returns> |
| | | 17 | | public static IServiceCollection AddApplicationSecurityHeaders( |
| | | 18 | | this IServiceCollection services, |
| | | 19 | | IConfiguration configuration) |
| | | 20 | | { |
| | 115 | 21 | | IConfigurationSection section = configuration.GetSection(ApplicationSecurityHeadersOptions.SectionName); |
| | | 22 | | |
| | 115 | 23 | | services |
| | 115 | 24 | | .AddOptions<ApplicationSecurityHeadersOptions>() |
| | 115 | 25 | | .Bind(section) |
| | 115 | 26 | | .Configure(options => ConfigurationListBinding.ReplaceWithConfiguredValues( |
| | 115 | 27 | | options.ExcludedPathPrefixes, |
| | 115 | 28 | | section.GetSection(nameof(ApplicationSecurityHeadersOptions.ExcludedPathPrefixes)))) |
| | 115 | 29 | | .Validate( |
| | 115 | 30 | | options => |
| | 115 | 31 | | !options.EnableContentSecurityPolicy || |
| | 115 | 32 | | !string.IsNullOrWhiteSpace(options.ContentSecurityPolicy), |
| | 115 | 33 | | "ProjectTemplate:SecurityHeaders:ContentSecurityPolicy is required when CSP is enabled.") |
| | 115 | 34 | | .Validate( |
| | 115 | 35 | | options => |
| | 115 | 36 | | !options.EnablePermissionsPolicy || |
| | 115 | 37 | | !string.IsNullOrWhiteSpace(options.PermissionsPolicy), |
| | 115 | 38 | | "ProjectTemplate:SecurityHeaders:PermissionsPolicy is required when Permissions-Policy is enabled.") |
| | 115 | 39 | | .Validate( |
| | 115 | 40 | | options => |
| | 115 | 41 | | options.ExcludedPathPrefixes.All(path => |
| | 115 | 42 | | !string.IsNullOrWhiteSpace(path) && |
| | 115 | 43 | | path.StartsWith('/')), |
| | 115 | 44 | | "ProjectTemplate:SecurityHeaders:ExcludedPathPrefixes values must start with '/'.") |
| | 115 | 45 | | .ValidateOnStart(); |
| | | 46 | | |
| | 115 | 47 | | return services; |
| | | 48 | | } |
| | | 49 | | |
| | | 50 | | /// <summary> |
| | | 51 | | /// Adds the security headers middleware to the application's request pipeline. |
| | | 52 | | /// </summary> |
| | | 53 | | /// <param name="app">The application builder used to configure the request pipeline.</param> |
| | | 54 | | /// <returns>The original <see cref="IApplicationBuilder"/> for chaining.</returns> |
| | | 55 | | public static IApplicationBuilder UseApplicationSecurityHeaders( |
| | | 56 | | this IApplicationBuilder app) |
| | | 57 | | { |
| | 107 | 58 | | return app.UseMiddleware<SecurityHeadersMiddleware>(); |
| | | 59 | | } |
| | | 60 | | |
| | | 61 | | /// <summary> |
| | | 62 | | /// Adds HTTP Strict Transport Security (HSTS) outside the development environment. |
| | | 63 | | /// </summary> |
| | | 64 | | /// <remarks> |
| | | 65 | | /// HSTS is skipped in development so browsers do not pin localhost to HTTPS. <c>UseProblemDetails</c> registers |
| | | 66 | | /// it between the exception handler and the status-code page branches, ahead of HTTPS redirection. |
| | | 67 | | /// </remarks> |
| | | 68 | | /// <param name="app">The <see cref="WebApplication"/> used to configure the request pipeline.</param> |
| | | 69 | | /// <returns>The same <see cref="WebApplication"/> instance for chaining.</returns> |
| | | 70 | | public static WebApplication UseApplicationHsts( |
| | | 71 | | this WebApplication app) |
| | | 72 | | { |
| | 109 | 73 | | ArgumentNullException.ThrowIfNull(app); |
| | | 74 | | |
| | 109 | 75 | | if (!app.Environment.IsDevelopment()) |
| | | 76 | | { |
| | 108 | 77 | | app.UseHsts(); |
| | | 78 | | } |
| | | 79 | | |
| | 109 | 80 | | return app; |
| | | 81 | | } |
| | | 82 | | } |
| | | 83 | | |