Add security headers, pin AllowedHosts and honor forwarded headers
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 50/100
Research direction
Start with LearnStack/appsettings.json:11 and LearnStack/Program.cs:76-95; review the current request pipeline and App Service deployment settings. Define the production host allowlist and CSP allowances, then verify the requested headers, forwarded scheme and client IP, unexpected-Host rejection, and securityheaders.com grade.
Written by the indexing model from the issue text.
Description
Tier 2 — security
Problem
- No security headers are emitted: no CSP,
X-Content-Type-Options,Referrer-PolicyorX-Frame-Options. AllowedHostsis"*", so the app answers to any Host header (host-header injection into generated links, cache poisoning).UseForwardedHeadersis not configured even though the app runs behind the App Service reverse proxy, so the scheme and client IP seen by the app are the proxy's — affecting redirects, logging and any future IP-based rate limiting.
Evidence
LearnStack/appsettings.json:11—"AllowedHosts": "*"LearnStack/Program.cs:76-95— no headers middleware, noUseForwardedHeaders
Proposed fix
- Add a middleware emitting the standard header set; start CSP in report-only mode since MudBlazor and Google Fonts need allowances, then enforce.
- Pin
AllowedHoststo the production domain(s). UseForwardedHeaderswithForwardedHeaders.XForwardedFor | XForwardedProtoearly in the pipeline.
Acceptance criteria
- securityheaders.com grade A or better
- Requests with an unexpected Host are rejected
- Logs show real client IPs and the correct scheme
- Dominant language
- HTML
- Stars
- 10
- Forks
- 0
- Avg merge
- 2h 35m
- Merged PRs (30d)
- 21
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from kasuken/LearnStack
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 91/100
kasuken/LearnStack#59 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
kasuken/LearnStack#72 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 30/100
kasuken/LearnStack#71 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
kasuken/LearnStack#70 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 45/100
kasuken/LearnStack#69 ·
Maintainers usually reply within 1 day
All issues in kasuken/LearnStack
Similar issues
-
bug needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
debpalash/VoiceStudio#2624 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
router-for-me/CLIProxyAPI#6399 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
ReactionMechanismGenerator/ARC#1067 ·
Maintainers usually reply within 1 day