Empty body responses can violate content security policy
- Dominant language
- C#
- Stars
- 38.4k
- Forks
- 10.9k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 276
Description
# Overview
I have a basic MVC website utilizing OIDC with authorization code flow for authentication. After implementing a content security policy, remote sign out will no longer function.
On remote signout the OpenIdConnectHandler will respond with a response of code 200 but with no body. As a result, browsers will interpret the response by improvising the text/html content. This can result in a content security policy violation based on the browser's improvisation.
# Reproduction
[I have a repository with the most basic configuration.](https://github.com/null-d3v/OidcCsp)
Using Chrome, navigate directly to the `RemoteSignOutPath` (/signout-oidc)
Chrome will report a content security policy violation from the pre element's inline style:
```
```
Currently there is limited recourse. I understand I have several options: using 'unsafe-inline', overriding the remote sign out implementation via the `OnRemoteSignOut` event, or add middleware to change the content security policy for the `RemoteSignOutPath` specifically. These options are somewhat contrived and not what I would think ideal. However, if there is a better solution that I am overlooking I would appreciate any insight.
I would request consideration for the text/html status code 200 HTTP responses include a body to avoid this browser improvisation.
Contributor guide
Assessment
This issue has not been assessed yet.