dotnet / dotnet/aspnetcore

Empty body responses can violate content security policy

Open
#4,652 2 comments 0 reactions 0 assignees View on GitHub
area-auth enhancement help wanted
Dominant language
C#
Stars
38.4k
Forks
10.9k
Avg merge
2d 5h
Merged PRs (30d)
276

Description

# Overview

I have a basic MVC website utilizing OIDC with authorization code flow for authentication. After implementing a content security policy, remote sign out will no longer function.

On remote signout the OpenIdConnectHandler will respond with a response of code 200 but with no body. As a result, browsers will interpret the response by improvising the text/html content. This can result in a content security policy violation based on the browser's improvisation.

# Reproduction

[I have a repository with the most basic configuration.](https://github.com/null-d3v/OidcCsp)
Using Chrome, navigate directly to the `RemoteSignOutPath` (/signout-oidc)
Chrome will report a content security policy violation from the pre element's inline style:
```





```

Currently there is limited recourse. I understand I have several options: using 'unsafe-inline', overriding the remote sign out implementation via the `OnRemoteSignOut` event, or add middleware to change the content security policy for the `RemoteSignOutPath` specifically. These options are somewhat contrived and not what I would think ideal. However, if there is a better solution that I am overlooking I would appreciate any insight.

I would request consideration for the text/html status code 200 HTTP responses include a body to avoid this browser improvisation.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.