You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Services中Angular的CSP Nonce配置问题求助

求助:Azure App Services(Windows)下为CSP头部实现动态Nonce的方案

我之前在ServerFault发过相同问题但关注度较低,故在此再次求助。

我的需求是为CSP头部策略实现nonce,从而移除script-src中的'unsafe-inline'——Angular现已支持为内联脚本绑定nonce,但在Windows环境下,我找不到在初始内容响应头中传递nonce的方法(也可能完全误解了流程)。

我们的架构是:Azure App Services托管应用,Azure Front-door作为防火墙/负载均衡器。我原本设想了两种可行方案,但尝试后均无法实现:

  • 方案1:在请求Angular应用的JS时,通过IIS配置添加nonce头部。但IIS无法配置生成随机值,虽然可以通过web.config添加CSP头部,但该文件仅支持静态字符串。
  • 方案2:在Front-door上设置返回nonce值的头部。但Front-door同样只能添加静态自定义头部,无法生成随机nonce。

以下是我的web.config文件内容:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <system.webServer>
    <rewrite>
      <rules>
        <rule name="Angular Routes" stopProcessing="true">
          <match url=".*" />
          <conditions logicalGrouping="MatchAll">
            <add input="{REQUEST_FILENAME}" matchType="IsFile" negate="true" />
            <add input="{REQUEST_FILENAME}" matchType="IsDirectory" negate="true" />
          </conditions>
          <action type="Rewrite" url="/" />
        </rule>
      </rules>
    </rewrite>
    <security>
            <requestFiltering removeServerHeader="true" />
        </security>
        <httpProtocol>
            <customHeaders>
                <remove name="X-Powered-By" />
        <add name="X-Frame-Options" value="SAMEORIGIN" />
        <add name="Strict-Transport-Security" value="max-age=31536000; includeSubDomains"/>
        <add name="X-XSS-Protection" value="1; mode=block" />
        <add name="X-Content-Type-Options" value="nosniff" />
        <add name="Content-Security-Policy" value="

connect-src 'self' *.my-domain.com my-domain.com; 

default-src 'self'; 

script-src 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ 'unsafe-inline'; 

style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; 

font-src 'self' https://fonts.gstatic.com 'unsafe-inline'; 

frame-src https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/;" 

/>
        <add name="Referrer-Policy" value="strict-origin" />
            </customHeaders>
        </httpProtocol>
  </system.webServer>
</configuration>

恳请各位提供可行的实现方案或相关见解。

内容的提问来源于stack exchange,提问作者hugmungus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 06:42:44