Table of Contents

Security

Description

The framework adds a baseline of security behaviors out of the box — not a substitute for proper security testing, but a reasonable starting point.

Features

Request blocking: Requests to sensitive paths and file extensions are blocked automatically — see Static Files for the full list.

Security headers (production only):

  • X-Content-Type-Options: nosniff — all responses
  • Strict-Transport-Security: max-age=2592000; includeSubDomains — always sent, browsers respect it only over HTTPS
  • Referrer-Policy: strict-origin-when-cross-origin — on non-file requests
  • Content-Security-Policy — web responses only:
    • All sources allowed (default-src *)
    • Plugin embedding blocked (object-src 'none')
    • Base URI restricted to same origin (base-uri 'self')
    • Iframing restricted to your domain and subdomains (frame-ancestors)

Bot and crawler blocking: UserAgentFilter attribute blocks known bots and crawlers when applied to a controller or action.

Encryption: AES CBC, AES GCM and RSA available out of the box — see Encryption.

What the framework does NOT do

  • Penetration testing
  • Vulnerability scanning
  • OWASP compliance verification
  • Security auditing
  • Whitelist or validate scripts running on your site as CSP is set to default-src *

Caveats

  • Security headers are only added in production — other environments allow all content freely to simplify local development and testing
  • TODO: And should also be added to preproduction - so we have an environment equal to production