Orbyss.Foundation.WebDefaults 0.2.3

There is a newer version of this package available.
See the version list below for details.
dotnet add package Orbyss.Foundation.WebDefaults --version 0.2.3
                    
NuGet\Install-Package Orbyss.Foundation.WebDefaults -Version 0.2.3
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Orbyss.Foundation.WebDefaults" Version="0.2.3" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Orbyss.Foundation.WebDefaults" Version="0.2.3" />
                    
Directory.Packages.props
<PackageReference Include="Orbyss.Foundation.WebDefaults" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Orbyss.Foundation.WebDefaults --version 0.2.3
                    
#r "nuget: Orbyss.Foundation.WebDefaults, 0.2.3"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Orbyss.Foundation.WebDefaults@0.2.3
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Orbyss.Foundation.WebDefaults&version=0.2.3
                    
Install as a Cake Addin
#tool nuget:?package=Orbyss.Foundation.WebDefaults&version=0.2.3
                    
Install as a Cake Tool

Orbyss.Foundation.WebDefaults

Foundation:Web:SupportedLocales replaces the fallback locale list when explicitly configured. Omission retains ["en"]; an explicit selection must be a non-empty indexed array of distinct, non-empty culture names and contain DefaultLocale (which itself defaults to en). Set both DefaultLocale: "nl" and SupportedLocales: ["nl", "de"] to enable only Dutch and German. Empty, null and malformed selections fail validation. Configuration-provider precedence applies before binding; recreate the shell to apply changes.

An optional CShells middleware feature providing Orbyss Foundation's default correlation identifier, browser-security response headers, localization, and production HSTS behavior. Consumers can deactivate this feature and activate their own equivalent middleware feature.

Named response policies

Select the feature and configure the shell's Configuration:Foundation:Web:ResponsePolicies:

{
  "DefaultPolicy": "default",
  "Policies": {
    "default": {
      "ContentSecurityPolicy": "default-src 'self'; frame-ancestors 'none'; object-src 'none'; base-uri 'self'",
      "ReferrerPolicy": "same-origin",
      "PermissionsPolicy": "camera=(), microphone=(), geolocation=()",
      "AllowIndexing": false
    }
  },
  "FeaturePolicies": { "My.PublicPage": "default" }
}

The built-in default, private, and public-asset policies preserve framing and object restrictions. Configuration is compiled once per shell activation. Restart/recreate the shell to apply changes. Invalid settings fail activation under the Host's existing activation-failure policy; no permissive fallback is used. Application settings are inherited through CShells configuration, then shell settings override them.

Features attach WebResponseMetadata(Feature: "My.PublicPage") to their route group. An endpoint may select a complete policy with WebResponseMetadata(Policy: "public-asset", ImmutablePublicAsset: true). Precedence is endpoint selection, feature selection, shell default, Foundation default. Conflicting endpoint selections or feature owners are rejected. This is explicit endpoint ownership, not reflection over handler types. Mark private responses with Private: true regardless of authentication metadata. Mapped selectors are checked when endpoint sources are available during pipeline construction. A selector introduced later that cannot resolve fails closed with web_policy_invalid, default security headers and no-store; its handler never runs.

One response-start writer owns CSP, framing, nosniff, referrer, Permissions-Policy and cache headers. Private responses, errors, unclassified/static middleware responses and responses with cookies are no-store. Only explicitly admitted immutable public GET/HEAD resources with status 200/206/304 get public caching. Resource NoIndex and policy denial override indexing permission. Discovery retains its standalone protection when this feature is not selected. Request authorization and same-origin admission remain independent. Shell policies cover requests inside that shell pipeline, not proxy or pre-shell failures. Embedding, unsafe-inline and unsafe-eval policies are not supported.

Run python tests/validate_web_policies.py after the Release solution build. Its real CShells probe exercises two isolated policy catalogs, error response clearing, endpoint overrides, private responses, public caching and header conflicts.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.

NuGet packages (4)

Showing the top 4 NuGet packages that depend on Orbyss.Foundation.WebDefaults:

Package Downloads
Orbyss.Foundation.Authentication.BffCookie

Confidential OIDC BFF-cookie authentication as a CShells web and middleware feature.

Orbyss.Foundation.Authentication.SpaPkce

Direct SPA-PKCE bearer authentication as a CShells middleware feature.

Orbyss.Foundation.Web.Discovery

Optional shell-owned public HTML, sitemap, robots and Markdown discovery endpoints.

Orbyss.Foundation.Web.HostedPages

Fixed semantic hosted pages and admitted public branding/runtime assets.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.3.1 76 10/7/2026
0.3.0 83 10/7/2026
0.2.4 324 10/4/2026
0.2.3 122 10/3/2026
0.2.2 336 9/16/2026
0.2.1 136 9/16/2026
0.2.0 157 9/12/2026
0.1.0 134 9/8/2026