Azure App Services中Angular的CSP Nonce配置问题求助
求助:Azure App Services(Windows)下为CSP头部实现动态Nonce的方案
我之前在ServerFault发过相同问题但关注度较低,故在此再次求助。
我的需求是为CSP头部策略实现nonce,从而移除script-src中的'unsafe-inline'——Angular现已支持为内联脚本绑定nonce,但在Windows环境下,我找不到在初始内容响应头中传递nonce的方法(也可能完全误解了流程)。
我们的架构是:Azure App Services托管应用,Azure Front-door作为防火墙/负载均衡器。我原本设想了两种可行方案,但尝试后均无法实现:
- 方案1:在请求Angular应用的JS时,通过IIS配置添加nonce头部。但IIS无法配置生成随机值,虽然可以通过web.config添加CSP头部,但该文件仅支持静态字符串。
- 方案2:在Front-door上设置返回nonce值的头部。但Front-door同样只能添加静态自定义头部,无法生成随机nonce。
以下是我的web.config文件内容:
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules> <rule name="Angular Routes" stopProcessing="true"> <match url=".*" /> <conditions logicalGrouping="MatchAll"> <add input="{REQUEST_FILENAME}" matchType="IsFile" negate="true" /> <add input="{REQUEST_FILENAME}" matchType="IsDirectory" negate="true" /> </conditions> <action type="Rewrite" url="/" /> </rule> </rules> </rewrite> <security> <requestFiltering removeServerHeader="true" /> </security> <httpProtocol> <customHeaders> <remove name="X-Powered-By" /> <add name="X-Frame-Options" value="SAMEORIGIN" /> <add name="Strict-Transport-Security" value="max-age=31536000; includeSubDomains"/> <add name="X-XSS-Protection" value="1; mode=block" /> <add name="X-Content-Type-Options" value="nosniff" /> <add name="Content-Security-Policy" value=" connect-src 'self' *.my-domain.com my-domain.com; default-src 'self'; script-src 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ 'unsafe-inline'; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com 'unsafe-inline'; frame-src https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/;" /> <add name="Referrer-Policy" value="strict-origin" /> </customHeaders> </httpProtocol> </system.webServer> </configuration>
恳请各位提供可行的实现方案或相关见解。
内容的提问来源于stack exchange,提问作者hugmungus
相关产品推荐
相关产品推荐

