Table of Contents

FrameworkOptions

Description

Controls which services and middleware are registered at startup. Passed to Application.Start, Application.Build or the extension API.

Features

All options default to sensible values — only override what you need.

Middleware toggles:

  • UseAuthentication — default true
  • UseAuthorization — default true
  • UseForwardedHeaders — default true
  • UseHttpsRedirection — default false
  • UseHsts — default false
  • UseOutputCache — default true
  • UseGzipResponseCompression — default true
  • UseBrotliResponseCompression — default false
  • UseDeveloperPage — default true
  • UseStatusCodeLogger — default true
  • UseStaticFilePolicy — default true
  • UseSecurityPolicy — default true
  • UseResponseCaching — default true
  • UseDataProtectionPolicy — default false

Static files:

  • StaticFilesClientCacheSeconds — default 604800 (7 days)
  • StaticRequestPaths — custom static file root paths

Views:

  • ViewLocations — custom view location formats
  • ViewLocationExpander — custom IViewLocationExpander implementation
  • ApplicationParts — additional assemblies scanned for controllers

Behavior

UseSecurityPolicy only adds security headers in production — non-production environments allow all content freely to simplify local development and testing.

UseDataProtectionPolicy generates a single key file in the parent of ContentRoot valid for 100 years — copy it to all environments and gitignore it. Required for EncryptUsingKeyRing and DecryptUsingKeyRing and for cookie encryption across multiple instances.

Caveats

  • UseDataProtectionPolicy is false by default — keys are stored in-memory only, meaning auth cookies are lost on app restart and won't work across multiple instances. Enable it to persist keys to disk.
  • UseHsts and UseHttpsRedirection are both false by default — enable only if your hosting environment does not handle HTTPS termination upstream
  • StaticRequestPaths requires UseStaticFilePolicy to be true
Tip

Enable UseDataProtectionPolicy in production if you use cookie authentication or run multiple instances — otherwise users will be logged out on every restart. Copy the generated key file to all environments and gitignore it.

Usage

var options = new FrameworkOptions();

Application.Start<Hooks>(AppType.Web, options, AppHosting.Kestrel);