From 743947afdee2bb9630fd305a10c20d504eed3a0f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zolt=C3=A1n=20Leh=C3=B3czky?= Date: Thu, 21 Mar 2024 18:50:57 +0100 Subject: [PATCH 1/2] Code styling --- .../Security/SecurityOrchardCoreBuilderExtensions.cs | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Lombiq.HelpfulLibraries.OrchardCore/Security/SecurityOrchardCoreBuilderExtensions.cs b/Lombiq.HelpfulLibraries.OrchardCore/Security/SecurityOrchardCoreBuilderExtensions.cs index c5f21109..7c4ed293 100644 --- a/Lombiq.HelpfulLibraries.OrchardCore/Security/SecurityOrchardCoreBuilderExtensions.cs +++ b/Lombiq.HelpfulLibraries.OrchardCore/Security/SecurityOrchardCoreBuilderExtensions.cs @@ -1,4 +1,4 @@ -using Lombiq.HelpfulLibraries.AspNetCore.Security; +using Lombiq.HelpfulLibraries.AspNetCore.Security; using Lombiq.HelpfulLibraries.OrchardCore.DependencyInjection; using Microsoft.AspNetCore.Antiforgery; using Microsoft.AspNetCore.Builder; @@ -34,8 +34,8 @@ public static OrchardCoreBuilder ConfigureAntiForgeryAlwaysSecure(this OrchardCo /// /// /// - /// Add to permit script evaluation when the - /// vuejs resource is included. + /// Add to permit script evaluation when the vuejs + /// resource is included. /// /// /// From f867626575cb98c749f2f5c6a308bc95b1769728 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A1ra=20El-Saig?= Date: Thu, 21 Mar 2024 19:29:28 +0100 Subject: [PATCH 2/2] Add domains from OrchardCore.Resources to CdnContentSecurityPolicyProvider. # Conflicts: # Lombiq.HelpfulLibraries.AspNetCore/Security/CdnContentSecurityPolicyProvider.cs --- .../Security/CdnContentSecurityPolicyProvider.cs | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/Lombiq.HelpfulLibraries.AspNetCore/Security/CdnContentSecurityPolicyProvider.cs b/Lombiq.HelpfulLibraries.AspNetCore/Security/CdnContentSecurityPolicyProvider.cs index f577dcd3..e382ec12 100644 --- a/Lombiq.HelpfulLibraries.AspNetCore/Security/CdnContentSecurityPolicyProvider.cs +++ b/Lombiq.HelpfulLibraries.AspNetCore/Security/CdnContentSecurityPolicyProvider.cs @@ -23,6 +23,8 @@ public class CdnContentSecurityPolicyProvider : IContentSecurityPolicyProvider new Uri("https://fonts.googleapis.com/css"), new Uri("https://fonts.gstatic.com/"), new Uri("https://cdn.jsdelivr.net/npm"), + new Uri("https://cdnjs.cloudflare.com/"), + new Uri("https://maxcdn.bootstrapcdn.com/"), }); /// @@ -31,7 +33,9 @@ public class CdnContentSecurityPolicyProvider : IContentSecurityPolicyProvider public static ConcurrentBag PermittedScriptSources { get; } = new(new[] { new Uri("https://cdn.jsdelivr.net/npm"), - new Uri("https://code.jquery.com/jquery-3.7.0.js"), + new Uri("https://code.jquery.com/"), + new Uri("https://cdnjs.cloudflare.com/"), + new Uri("https://maxcdn.bootstrapcdn.com/"), }); ///