Skip to content

Security headers (CSP, XFO, X-Content-Type-Options) #35

@unrealbg

Description

@unrealbg

Problem

Missing standard hardened security headers (CSP, XFO, X-Content-Type-Options, etc.).

Proposal

  • Add middleware to append CSP, X-Frame-Options, SameSite, X-Content-Type-Options headers.
  • CSP blocks inline scripts but allows required sources.
  • Document CSP exceptions for Blazor.
  • Target good rating on securityheaders.com.

Alternatives considered

  • Use default ASP.NET Core headers only.

Acceptance criteria

  • CSP blocks inline scripts; allow required sources
  • X-Frame-Options/SameSite/XCTO set
  • Good rating on securityheaders.com

Technical notes

  • Middleware to append headers
  • Document CSP exceptions for Blazor

Risks

  • CSP misconfiguration may break app functionality.

Additional context

Labels: security

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions