Skip to content

Commit d27cebf

Browse files
committed
Updating security headers
1 parent e26ea85 commit d27cebf

2 files changed

Lines changed: 1 addition & 8 deletions

File tree

content/StsServerIdentity/Filters/SecurityHeadersAttribute.cs

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,6 @@ public override void OnResultExecuting(ResultExecutingContext context)
1313
var result = context.Result;
1414
if (result is ViewResult)
1515
{
16-
var featurePolicy = "accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'; usb 'none'";
17-
18-
if (!context.HttpContext.Response.Headers.ContainsKey("feature-policy"))
19-
{
20-
context.HttpContext.Response.Headers.Add("feature-policy", featurePolicy);
21-
}
22-
2316
if (!context.HttpContext.Response.Headers.ContainsKey("X-Content-Type-Options"))
2417
{
2518
context.HttpContext.Response.Headers.Add("X-Content-Type-Options", "nosniff");

content/StsServerIdentity/SecurityHeadersDefinitions.cs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ public static HeaderPolicyCollection GetHeaderPolicyCollection(bool isDev)
3333
builder.AddFontSrc().Self();
3434
builder.AddStyleSrc().Self().UnsafeInline();
3535
builder.AddBaseUri().Self();
36-
builder.AddScriptSrc().UnsafeInline(); //.WithNonce();
36+
builder.AddScriptSrc().Self().UnsafeInline(); //.WithNonce();
3737
builder.AddFrameAncestors().Self();
3838
// builder.AddCustomDirective("require-trusted-types-for", "'script'");
3939
})

0 commit comments

Comments
 (0)