I would like to configure CSP in the appsettings.json but as the title suggests also prevent adding the header for some requests that don't make sense (similar to how it's described in the docs to omit the response header on API requests).
I set the configuration using
services.Configure<CspOptions>(configuration.GetSection("Csp"));
and in order to configure OnSendingHeader in the UseCsp:
app.UseCsp(cspBuilder =>
{
cspBuilder.OnSendingHeader = ctx =>
{
ctx.ShouldNotSend = /* boolean condition */
return Task.Completed;
}
});
which overrides the CSP options defined in the appsettings.json which IMO is a bug. If the options are already configured, the UseCsp call with the builder parameter should not generate empty CSP which it does.
I would like to configure CSP in the appsettings.json but as the title suggests also prevent adding the header for some requests that don't make sense (similar to how it's described in the docs to omit the response header on API requests).
I set the configuration using
and in order to configure
OnSendingHeaderin theUseCsp:which overrides the CSP options defined in the appsettings.json which IMO is a bug. If the options are already configured, the
UseCspcall with the builder parameter should not generate empty CSP which it does.