Security
Description
The framework adds a baseline of security behaviors out of the box — not a substitute for proper security testing, but a reasonable starting point.
Features
Request blocking: Requests to sensitive paths and file extensions are blocked automatically — see Static Files for the full list.
Security headers (production only):
X-Content-Type-Options: nosniff— all responsesStrict-Transport-Security: max-age=2592000; includeSubDomains— always sent, browsers respect it only over HTTPSReferrer-Policy: strict-origin-when-cross-origin— on non-file requestsContent-Security-Policy— web responses only:- All sources allowed (
default-src *) - Plugin embedding blocked (
object-src 'none') - Base URI restricted to same origin (
base-uri 'self') - Iframing restricted to your domain and subdomains (
frame-ancestors)
- All sources allowed (
Bot and crawler blocking:
UserAgentFilter attribute blocks known bots and crawlers when applied to a controller or action.
Encryption: AES CBC, AES GCM and RSA available out of the box — see Encryption.
What the framework does NOT do
- Penetration testing
- Vulnerability scanning
- OWASP compliance verification
- Security auditing
- Whitelist or validate scripts running on your site as CSP is set to
default-src *
Caveats
- Security headers are only added in production — other environments allow all content freely to simplify local development and testing
- TODO: And should also be added to preproduction - so we have an environment equal to production