Skip to content

Configure CSP in appsettings.json but want to set OnSendingHeader #76

Description

@litera

I would like to configure CSP in the appsettings.json but as the title suggests also prevent adding the header for some requests that don't make sense (similar to how it's described in the docs to omit the response header on API requests).

I set the configuration using

services.Configure<CspOptions>(configuration.GetSection("Csp"));

and in order to configure OnSendingHeader in the UseCsp:

app.UseCsp(cspBuilder =>
{
    cspBuilder.OnSendingHeader = ctx =>
    {
        ctx.ShouldNotSend = /* boolean condition */
        return Task.Completed;
    }
});

which overrides the CSP options defined in the appsettings.json which IMO is a bug. If the options are already configured, the UseCsp call with the builder parameter should not generate empty CSP which it does.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions