Comments (8)
You may create a custom middleware and add this header. You can take a look at https://stackoverflow.com/a/37395430
from aspnetboilerplate.
You may create a custom middleware and add this header. You can take a look at https://stackoverflow.com/a/37395430
I have added middleware in my code but still didn't work.
here is my middleware:
app.Use(async (context, next) =>
{
context.Response.GetTypedHeaders().CacheControl =
new Microsoft.Net.Http.Headers.CacheControlHeaderValue()
{
NoStore = true,
NoCache = true,
};
context.Response.Headers["Expires"] = "0";
context.Response.Headers["Pragma"] = "no-cache";
context.Response.Headers["Content-Security-Policy"] = "default-src 'self'; " +
"script-src 'self' 'unsafe-inline' ; " +
"style-src 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com ;" +
"font-src 'self' fonts.googleapis.com fonts.gstatic.com ; " +
"img-src 'self' validator.swagger.io data:;" +
"connect-src 'self' ws: wss:;";
context.Response.Headers["Referrer-Policy"] = "no-referrer";
context.Response.Headers["Permissions-Policy"] = "geolocation=(), camera=(), microphone=(), display-capture=(), fullscreen=(), web-share=()";
context.Response.Headers["X-Frame-Options"] = "SAMEORIGIN";
context.Response.Headers["X-Content-Type-Options"] = "nosniff";
context.Response.Headers["Strict-Transport-Security"] = "max-age=31536000; includeSubDomains";
await next();
});
from aspnetboilerplate.
Does this work on a raw ASP.NET Core project ?
from aspnetboilerplate.
Does this work on a raw ASP.NET Core project ?
Yes, When I create a new Project, from ASP.Net Core 7 no issue detected on snyk.
What makes me wonder is why this solution/project reads as ASP.NET Web API
from aspnetboilerplate.
Could you share the website URL of the tool you used ? I mean snyk.
from aspnetboilerplate.
Could you share the website URL of the tool you used ? I mean snyk.
Here's is the link https://snyk.io/
You can register and use for free,
And download and install extension for your IDE (in my case VS 2022) or use extension manager form VS 2022.
from aspnetboilerplate.
I think I have a Solution for this issue, but didn't know what the impacts are for the existing application.
Just Delete the file "app.config" on the ".Web.Host" Project.
Hope it's Help
from aspnetboilerplate.
@frogerdevs you are right, this file is not used anymore.
from aspnetboilerplate.
Related Issues (20)
- Interceptors not firing HOT 2
- MultiDbContext does not work with the Migrator project
- ABP v9.2.2 backend job caused the database connection to remain unreleased HOT 2
- Diffrent Web.Host project all application service show two project. HOT 4
- multiple pod redis access problem HOT 6
- AbpUsers creatoruserid is sometimes the id of another user HOT 1
- Can't create component 'xxxx.Settings.ActivityTypeAppService' as it has dependencies to be satisfied. HOT 2
- Question: Extend/Modify Property in Abp Table HOT 3
- Error resolving ChatUserStateWatcher HOT 2
- Support for angular 18 HOT 1
- ABP's efcorerepository implementation uses efcore's batch deletion API HOT 1
- Cross-Origin Request Blocked - in my Angular app HOT 4
- AbpModuleManager Shutting down Per Request HOT 11
- AddRazorRuntimeCompilation() breaks CSS isolation in .NET core
- Feature Request To Add Navigation Property To UserRole entity HOT 1
- Any option to config cross-origin in aspnetboilerplate? HOT 3
- Error in using IRepository<TEntity>: The type 'Client' cannot be used as type parameter 'TEntity' in the generic type or method IRepository<TEntity> HOT 4
- File not find error
- interface issue HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from aspnetboilerplate.