juunas11/aspnetcore-security-headers
Middleware for adding security headers to an ASP.NET Core application.
C#MIT
Issues
- 0
- 1
- 3
Support new "report-to" directive and header.
#40 opened by jpknoll - 0
- 0
Using Nonces with Blazor
#77 opened by Clive321A - 1
- 0
- 4
Using SHA. How do I use it?
#69 opened by gatecrasher63 - 1
Appending nonce to scripts added as strings
#71 opened by jplatfordquba - 9
'unsafe-inline' is ignored if either a hash or nonce value is present in the source list
#31 opened by ace37 - 1
Access the nonce value
#61 opened by tlnorwood - 1
Add CspReport Object
#54 opened by Matti-Koopa - 1
- 1
- 1
- 2
add nonce attribute for devextreme components
#64 opened by Thabot011 - 1
- 1
Alternative syntax
#70 opened by gatecrasher63 - 11
Nonce not working in asp.net core mvc
#45 opened by Ephaltes - 2
Nonce is empty
#68 opened by spaasis - 4
- 1
Add support for report-sample
#53 opened by j-hudecek - 1
What about 'data' URIs?
#36 opened by Zettersten - 2
<div asp-validation-summary="All" ></div>
#52 opened by V4A001 - 1
X-Content-Security-Policy
#2 opened by Gaulomatic - 3
asp.net core 2.1 UseHsts() naming conflict
#20 opened by dotnetshadow - 3
Usage with a single page application
#51 opened by TheKnarf - 2
Add a tag helper to automatically put SHA hash into CSP - alternative to nonce
#47 opened by shand-obs - 1
Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive:
#49 opened by vankampenp - 1
Add report options to UseXXssProtection
#48 opened by jamesharling - 2
.NET Core 3.0 Issues
#46 opened by MCFHTAGENTS - 0
- 3
- 7
Add Security Headers in Response.OnStarting
#39 opened by agilenut - 1
- 1
Partial view issue
#35 opened by JandosKh - 3
CSP manifest-src directive not supported
#32 opened by marcwittke - 0
Add support for all security headers
#28 opened by jcox86 - 5
Strict-dynamic support for frames
#25 opened by cfletcher - 2
Add support for `prefetch-src`
#26 opened by MrMDavidson - 3
ArgumentException: An item with the same key has already been added. Key: Strict-Transport-Security
#23 opened by hades200082 - 5
Add Nonce support for other HTML elements that might have an inline style element
#21 opened by hades200082 - 4
System.Argument Exception when using CSP middleware with UseStatusCodePagesWithReExecute middleware
#19 opened by mattparry43 - 4
RandomNumberGenerator.GetBytes is not thread-safe
#18 opened by Flavien - 1
Support base-uri directive
#17 opened by Flavien - 0
- 1
- 2
upgrade-insecure-requests
#10 opened by ajeckmans - 4
Core 2.0 upgrade
#6 opened by xperiandri - 4
HstsOptions should work with Timespan class
#4 opened by MovGP0