Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions src/Host/FSH.Starter.Api/appsettings.Production.json
Original file line number Diff line number Diff line change
Expand Up @@ -59,8 +59,8 @@
"CorsOptions": {
"AllowAll": false,
"AllowedOrigins": [],
"AllowedHeaders": [ "content-type", "authorization" ],
"AllowedMethods": [ "GET", "POST", "PUT", "DELETE" ]
"AllowedHeaders": [ "content-type", "authorization", "tenant", "x-fsh-app", "idempotency-key", "x-requested-with", "x-signalr-user-agent" ],
"AllowedMethods": [ "GET", "POST", "PUT", "PATCH", "DELETE" ]
},
"JwtOptions": {
"Issuer": "fsh.local",
Expand Down
4 changes: 2 additions & 2 deletions src/Host/FSH.Starter.Api/appsettings.json
Original file line number Diff line number Diff line change
Expand Up @@ -100,8 +100,8 @@
"http://localhost:5173",
"http://localhost:5174"
],
"AllowedHeaders": [ "content-type", "authorization" ],
"AllowedMethods": [ "GET", "POST", "PUT", "DELETE" ]
"AllowedHeaders": [ "content-type", "authorization", "tenant", "x-fsh-app", "idempotency-key", "x-requested-with", "x-signalr-user-agent" ],
"AllowedMethods": [ "GET", "POST", "PUT", "PATCH", "DELETE" ]
},
"JwtOptions": {
"Issuer": "fsh.local",
Expand Down
9 changes: 9 additions & 0 deletions src/Tests/Framework.Tests/Framework.Tests.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -32,4 +32,13 @@
<ProjectReference Include="..\..\BuildingBlocks\Web\Web.csproj" />
</ItemGroup>

<ItemGroup>
<None Include="..\..\Host\FSH.Starter.Api\appsettings.json"
Link="HostConfiguration\appsettings.json"
CopyToOutputDirectory="PreserveNewest" />
<None Include="..\..\Host\FSH.Starter.Api\appsettings.Production.json"
Link="HostConfiguration\appsettings.Production.json"
CopyToOutputDirectory="PreserveNewest" />
</ItemGroup>

</Project>
62 changes: 62 additions & 0 deletions src/Tests/Framework.Tests/Web/CorsConfigurationTests.cs
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
using System.Text.Json;

namespace Framework.Tests.Web;

public sealed class CorsConfigurationTests
{
[Theory]
[InlineData("appsettings.json")]
[InlineData("appsettings.Production.json")]
public void AllowedMethods_Should_IncludePatch_When_RestrictedCorsIsConfigured(string fileName)
{
// Arrange
string path = Path.Combine(AppContext.BaseDirectory, "HostConfiguration", fileName);

// Act
using JsonDocument document = JsonDocument.Parse(File.ReadAllText(path));
JsonElement corsOptions = document.RootElement.GetProperty("CorsOptions");
string[] allowedMethods = corsOptions
.GetProperty("AllowedMethods")
.EnumerateArray()
.Select(method => method.GetString())
.OfType<string>()
.ToArray();

// Assert
corsOptions.GetProperty("AllowAll").GetBoolean().ShouldBeFalse();
allowedMethods.ShouldContain("PATCH");
}

// Every non-safelisted header the React clients (and the SignalR client) send must be allowed,
// or the browser rejects the preflight: tenant on every call, X-FSH-App on login,
// Idempotency-Key on chat sends, X-Requested-With / X-SignalR-User-Agent on hub negotiate.
[Theory]
[InlineData("appsettings.json", "tenant")]
[InlineData("appsettings.json", "x-fsh-app")]
[InlineData("appsettings.json", "idempotency-key")]
[InlineData("appsettings.json", "x-requested-with")]
[InlineData("appsettings.json", "x-signalr-user-agent")]
[InlineData("appsettings.Production.json", "tenant")]
[InlineData("appsettings.Production.json", "x-fsh-app")]
[InlineData("appsettings.Production.json", "idempotency-key")]
[InlineData("appsettings.Production.json", "x-requested-with")]
[InlineData("appsettings.Production.json", "x-signalr-user-agent")]
public void AllowedHeaders_Should_IncludeClientHeader_When_RestrictedCorsIsConfigured(string fileName, string header)
{
// Arrange
string path = Path.Combine(AppContext.BaseDirectory, "HostConfiguration", fileName);

// Act
using JsonDocument document = JsonDocument.Parse(File.ReadAllText(path));
string[] allowedHeaders = document.RootElement
.GetProperty("CorsOptions")
.GetProperty("AllowedHeaders")
.EnumerateArray()
.Select(h => h.GetString())
.OfType<string>()
.ToArray();

// Assert
allowedHeaders.ShouldContain(h => string.Equals(h, header, StringComparison.OrdinalIgnoreCase));
}
}
Loading