forked from OrchardCMS/OrchardCore
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add Security Module (Lombiq Technologies: OCORE-91) (OrchardCMS#11538)
- Loading branch information
Showing
45 changed files
with
1,572 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,34 @@ | ||
using System; | ||
using System.Threading.Tasks; | ||
using Microsoft.Extensions.Localization; | ||
using OrchardCore.Navigation; | ||
using OrchardCore.Security.Drivers; | ||
|
||
namespace OrchardCore.Security | ||
{ | ||
public class AdminMenu : INavigationProvider | ||
{ | ||
private readonly IStringLocalizer S; | ||
|
||
public AdminMenu(IStringLocalizer<AdminMenu> localizer) | ||
{ | ||
S = localizer; | ||
} | ||
|
||
public Task BuildNavigationAsync(string name, NavigationBuilder builder) | ||
{ | ||
if (String.Equals(name, "admin", StringComparison.OrdinalIgnoreCase)) | ||
{ | ||
builder.Add(S["Security"], NavigationConstants.AdminMenuSecurityPosition, security => security | ||
.AddClass("security").Id("security") | ||
.Add(S["Settings"], settings => settings | ||
.Add(S["Security Headers"], S["Security Headers"].PrefixPosition(), headers => headers | ||
.Permission(SecurityPermissions.ManageSecurityHeadersSettings) | ||
.Action("Index", "Admin", new { area = "OrchardCore.Settings", groupId = SecuritySettingsDisplayDriver.SettingsGroupId }) | ||
.LocalNav()))); | ||
} | ||
|
||
return Task.CompletedTask; | ||
} | ||
} | ||
} |
123 changes: 123 additions & 0 deletions
123
src/OrchardCore.Modules/OrchardCore.Security/Drivers/SecuritySettingsDisplayDriver.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,123 @@ | ||
using System.Threading.Tasks; | ||
using Microsoft.AspNetCore.Authorization; | ||
using Microsoft.AspNetCore.Http; | ||
using Microsoft.Extensions.Options; | ||
using OrchardCore.DisplayManagement.Entities; | ||
using OrchardCore.DisplayManagement.Handlers; | ||
using OrchardCore.DisplayManagement.Views; | ||
using OrchardCore.Environment.Shell; | ||
using OrchardCore.Security.Options; | ||
using OrchardCore.Security.Settings; | ||
using OrchardCore.Security.ViewModels; | ||
using OrchardCore.Settings; | ||
|
||
namespace OrchardCore.Security.Drivers | ||
{ | ||
public class SecuritySettingsDisplayDriver : SectionDisplayDriver<ISite, SecuritySettings> | ||
{ | ||
internal const string SettingsGroupId = "SecurityHeaders"; | ||
|
||
private readonly IShellHost _shellHost; | ||
private readonly ShellSettings _shellSettings; | ||
private readonly IHttpContextAccessor _httpContextAccessor; | ||
private readonly IAuthorizationService _authorizationService; | ||
private readonly SecuritySettings _securitySettings; | ||
|
||
public SecuritySettingsDisplayDriver( | ||
IShellHost shellHost, | ||
ShellSettings shellSettings, | ||
IHttpContextAccessor httpContextAccessor, | ||
IAuthorizationService authorizationService, | ||
IOptionsSnapshot<SecuritySettings> securitySettings) | ||
{ | ||
_shellHost = shellHost; | ||
_shellSettings = shellSettings; | ||
_httpContextAccessor = httpContextAccessor; | ||
_authorizationService = authorizationService; | ||
_securitySettings = securitySettings.Value; | ||
} | ||
|
||
public override async Task<IDisplayResult> EditAsync(SecuritySettings settings, BuildEditorContext context) | ||
{ | ||
var user = _httpContextAccessor.HttpContext?.User; | ||
|
||
if (!await _authorizationService.AuthorizeAsync(user, SecurityPermissions.ManageSecurityHeadersSettings)) | ||
{ | ||
return null; | ||
} | ||
|
||
return Initialize<SecuritySettingsViewModel>("SecurityHeadersSettings_Edit", model => | ||
{ | ||
// Set the settings from configuration when AdminSettings are overriden via ConfigureSecuritySettings() | ||
var currentSettings = settings; | ||
if (_securitySettings.FromConfiguration) | ||
{ | ||
currentSettings = _securitySettings; | ||
} | ||
|
||
model.FromConfiguration = currentSettings.FromConfiguration; | ||
model.ContentSecurityPolicy = currentSettings.ContentSecurityPolicy; | ||
model.PermissionsPolicy = currentSettings.PermissionsPolicy; | ||
model.ReferrerPolicy = currentSettings.ReferrerPolicy; | ||
|
||
model.EnableSandbox = currentSettings.ContentSecurityPolicy != null && | ||
currentSettings.ContentSecurityPolicy.ContainsKey(ContentSecurityPolicyValue.Sandbox); | ||
|
||
model.UpgradeInsecureRequests = currentSettings.ContentSecurityPolicy != null && | ||
currentSettings.ContentSecurityPolicy.ContainsKey(ContentSecurityPolicyValue.UpgradeInsecureRequests); | ||
}).Location("Content:2").OnGroup(SettingsGroupId); | ||
} | ||
|
||
public override async Task<IDisplayResult> UpdateAsync(SecuritySettings section, BuildEditorContext context) | ||
{ | ||
var user = _httpContextAccessor.HttpContext?.User; | ||
|
||
if (!await _authorizationService.AuthorizeAsync(user, SecurityPermissions.ManageSecurityHeadersSettings)) | ||
{ | ||
return null; | ||
} | ||
|
||
if (context.GroupId == SettingsGroupId) | ||
{ | ||
var model = new SecuritySettingsViewModel(); | ||
|
||
await context.Updater.TryUpdateModelAsync(model, Prefix); | ||
|
||
PrepareContentSecurityPolicyValues(model); | ||
|
||
section.ContentTypeOptions = SecurityHeaderDefaults.ContentTypeOptions; | ||
section.ContentSecurityPolicy = model.ContentSecurityPolicy; | ||
section.PermissionsPolicy = model.PermissionsPolicy; | ||
section.ReferrerPolicy = model.ReferrerPolicy; | ||
|
||
if (context.Updater.ModelState.IsValid) | ||
{ | ||
await _shellHost.ReleaseShellContextAsync(_shellSettings); | ||
} | ||
} | ||
|
||
return await EditAsync(section, context); | ||
} | ||
|
||
private static void PrepareContentSecurityPolicyValues(SecuritySettingsViewModel model) | ||
{ | ||
if (!model.EnableSandbox) | ||
{ | ||
model.ContentSecurityPolicy.Remove(ContentSecurityPolicyValue.Sandbox); | ||
} | ||
else if (!model.ContentSecurityPolicy.TryGetValue(ContentSecurityPolicyValue.Sandbox, out _)) | ||
{ | ||
model.ContentSecurityPolicy[ContentSecurityPolicyValue.Sandbox] = null; | ||
} | ||
|
||
if (!model.UpgradeInsecureRequests) | ||
{ | ||
model.ContentSecurityPolicy.Remove(ContentSecurityPolicyValue.UpgradeInsecureRequests); | ||
} | ||
else | ||
{ | ||
model.ContentSecurityPolicy[ContentSecurityPolicyValue.UpgradeInsecureRequests] = null; | ||
} | ||
} | ||
} | ||
} |
29 changes: 29 additions & 0 deletions
29
src/OrchardCore.Modules/OrchardCore.Security/Extensions/OrchardCoreBuilderExtensions.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,29 @@ | ||
using Microsoft.Extensions.Configuration; | ||
using OrchardCore.Environment.Shell.Configuration; | ||
using OrchardCore.Security.Settings; | ||
|
||
namespace Microsoft.Extensions.DependencyInjection | ||
{ | ||
public static class OrchardCoreBuilderExtensions | ||
{ | ||
public static OrchardCoreBuilder ConfigureSecuritySettings(this OrchardCoreBuilder builder) | ||
{ | ||
builder.ConfigureServices((tenantServices, serviceProvider) => | ||
{ | ||
var configurationSection = serviceProvider.GetRequiredService<IShellConfiguration>().GetSection("OrchardCore_Security"); | ||
|
||
tenantServices.PostConfigure<SecuritySettings>(settings => | ||
{ | ||
settings.ContentSecurityPolicy.Clear(); | ||
settings.PermissionsPolicy.Clear(); | ||
|
||
configurationSection.Bind(settings); | ||
|
||
settings.FromConfiguration = true; | ||
}); | ||
}); | ||
|
||
return builder; | ||
} | ||
} | ||
} |
38 changes: 38 additions & 0 deletions
38
...re.Modules/OrchardCore.Security/Extensions/SecurityHeadersApplicationBuilderExtensions.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,38 @@ | ||
using System; | ||
using OrchardCore.Security.Services; | ||
using OrchardCore.Security.Options; | ||
|
||
namespace Microsoft.AspNetCore.Builder | ||
{ | ||
public static class SecurityHeadersApplicationBuilderExtensions | ||
{ | ||
public static IApplicationBuilder UseSecurityHeaders(this IApplicationBuilder app) | ||
{ | ||
ArgumentNullException.ThrowIfNull(app, nameof(app)); | ||
|
||
return app.UseSecurityHeaders(new SecurityHeadersOptions()); | ||
} | ||
|
||
public static IApplicationBuilder UseSecurityHeaders(this IApplicationBuilder app, SecurityHeadersOptions options) | ||
{ | ||
ArgumentNullException.ThrowIfNull(app, nameof(app)); | ||
ArgumentNullException.ThrowIfNull(options, nameof(options)); | ||
|
||
app.UseMiddleware<SecurityHeadersMiddleware>(options); | ||
|
||
return app; | ||
} | ||
|
||
public static IApplicationBuilder UseSecurityHeaders(this IApplicationBuilder app, Action<SecurityHeadersOptions> optionsAction) | ||
{ | ||
ArgumentNullException.ThrowIfNull(app, nameof(app)); | ||
ArgumentNullException.ThrowIfNull(optionsAction, nameof(optionsAction)); | ||
|
||
var options = new SecurityHeadersOptions(); | ||
|
||
optionsAction.Invoke(options); | ||
|
||
return app.UseSecurityHeaders(options); | ||
} | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,10 @@ | ||
using OrchardCore.Modules.Manifest; | ||
|
||
[assembly: Module( | ||
Name = "Security", | ||
Author = ManifestConstants.OrchardCoreTeam, | ||
Website = ManifestConstants.OrchardCoreWebsite, | ||
Version = ManifestConstants.OrchardCoreVersion, | ||
Description = "The Security module adds HTTP headers to follow security best practices.", | ||
Category = "Security" | ||
)] |
11 changes: 11 additions & 0 deletions
11
src/OrchardCore.Modules/OrchardCore.Security/Options/ContentSecurityPolicyOriginValue.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,11 @@ | ||
namespace OrchardCore.Security.Options | ||
{ | ||
public class ContentSecurityPolicyOriginValue | ||
{ | ||
public const string Any = "*"; | ||
|
||
public const string None = "'none'"; | ||
|
||
public const string Self = "'self'"; | ||
} | ||
} |
39 changes: 39 additions & 0 deletions
39
src/OrchardCore.Modules/OrchardCore.Security/Options/ContentSecurityPolicyValue.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,39 @@ | ||
namespace OrchardCore.Security.Options | ||
{ | ||
public class ContentSecurityPolicyValue | ||
{ | ||
public const string BaseUri = "base-uri"; | ||
|
||
public const string ChildSource = "child-src"; | ||
|
||
public const string ConnectSource = "connect-src"; | ||
|
||
public const string DefaultSource = "default-src"; | ||
|
||
public const string FontSource = "font-src"; | ||
|
||
public const string FormAction = "form-action"; | ||
|
||
public const string FrameAncestors = "frame-ancestors"; | ||
|
||
public const string FrameSource = "frame-src"; | ||
|
||
public const string ImageSource = "img-src"; | ||
|
||
public const string ManifestSource = "manifest-src"; | ||
|
||
public const string MediaSource = "media-src"; | ||
|
||
public const string ObjectSource = "object-src"; | ||
|
||
public const string ReportUri = "report-uri"; | ||
|
||
public const string Sandbox = "sandbox"; | ||
|
||
public const string ScriptSource = "script-src"; | ||
|
||
public const string StyleSource = "style-src"; | ||
|
||
public const string UpgradeInsecureRequests = "upgrade-insecure-requests"; | ||
} | ||
} |
7 changes: 7 additions & 0 deletions
7
src/OrchardCore.Modules/OrchardCore.Security/Options/ContentTypeOptionsValue.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
namespace OrchardCore.Security.Options | ||
{ | ||
public class ContentTypeOptionsValue | ||
{ | ||
public const string NoSniff = "nosniff"; | ||
} | ||
} |
11 changes: 11 additions & 0 deletions
11
src/OrchardCore.Modules/OrchardCore.Security/Options/PermissionsPolicyOriginValue.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,11 @@ | ||
namespace OrchardCore.Security.Options | ||
{ | ||
public class PermissionsPolicyOriginValue | ||
{ | ||
public const string Any = "*"; | ||
|
||
public const string None = "()"; | ||
|
||
public const string Self = "self"; | ||
} | ||
} |
Oops, something went wrong.