Table of Contents

StaticFiles

Description

Serves static files from well-known asset folders with sensible defaults — cache headers, compression and unknown file type support out of the box.

Features

  • Auto-discovery: serves files from wwwroot, public, static, dist, frontend, assets, files automatically
  • Client-side caching: Cache-Control: public, max-age=604800, immutable applied to all static files by default (7 days)
  • Unknown file types: served without restriction — no file extension whitelist
  • Compression: HTTPS compression enabled by default

Behavior

Static files are served from two sources:

WebRootPath (wwwroot) — standard ASP.NET web root, served at /

Asset folders — served at their folder name as path segment:

~/public/   → /public/
~/static/   → /static/
~/dist/     → /dist/
~/frontend/ → /frontend/
~/assets/   → /assets/
~/files/    → /files/

Only GET and HEAD requests are handled — all other methods pass through to the next middleware.

Cache header is only added if not already present — consumers can override per file or route.

Security

Certain paths and file extensions are blocked automatically — returns 403 Forbidden:

Blocked paths:

/app_data/
/properties/
/configs/
/configurations/
/bin/
/obj/
appsettings.*

Blocked extensions:

.exe .dll .iso .msi .ps1 .cmd .sh .bash .vbs .dmg
.config .env .ini .key .pem .cshtml .cs .sql .mdf
.bat .jar .php .py .pl .rb .go .vb .hta .bak .db .pfx .crt

This runs before static file serving — blocked requests never reach the file system.

Caveats

  • UseStaticFilePolicy must be true in FrameworkOptions — enabled by default
  • If WebRootPath is set but folder does not exist — logs a warning and continues
  • Cache duration is controlled by StaticFilesClientCacheSeconds in FrameworkOptions — default 604800 (7 days)
Tip

Place your CSS, JS and images in ~/wwwroot or any of the auto-discovered asset folders — no configuration needed. Files are immediately available at their path.