CSP, CORS & response headers
These settings belong to the host. A PDF request cannot change them. Configure them in appsettings.json, environment variables, or your deployment's configuration provider, then restart the API.
CORS: all origins by default
Cors:Mode defaults to All. Browser clients receive Access-Control-Allow-Origin: *. Requests may use GET or POST and the Content-Type and X-Api-Key headers. Browsers can read Content-Disposition, Retry-After, and Link. Preflight OPTIONS requests do not require an API key.
| Mode | Behaviour |
|---|---|
All · default | Allow any browser origin, including the opaque null origin. No cookies or credentialed CORS. |
AllowList | Allow only the exact HTTP(S) origins in AllowedOrigins. Disallowed origins on PDF POSTs receive 403. |
Disabled | No cross-origin response headers. PDF POSTs accept the API's own origin and server requests without an Origin header. |
{ "Cors": { "Mode": "All", "AllowedOrigins": [] } }{
"Cors": {
"Mode": "AllowList",
"AllowedOrigins": ["https://app.example.com", "https://admin.example.com"]
}
}$env:Cors__Mode = 'AllowList'
$env:Cors__AllowedOrigins__0 = 'https://app.example.com'
# To disable CORS instead: $env:Cors__Mode = 'Disabled'Origins have no trailing slash or path; wildcards are not accepted in an allowlist. Set the mode explicitly when migrating a previous AllowedOrigins configuration. Malformed or multiple Origin values are rejected on PDF POSTs. CORS controls browser access; API keys, HTTPS, validation, and traffic limits still apply. Server-to-server HTTP calls do not need CORS.
Use credentials: 'omit' for cross-origin browser fetches. The API does not authenticate with cookies and never sends Access-Control-Allow-Credentials. Keep a shared deployment key on your application's backend; a key sent by browser JavaScript is visible to that browser's user.
curl -i -X OPTIONS '__API_ORIGIN__/api/v1/pdfs/custom-template' \
-H 'Origin: https://app.example.com' \
-H 'Access-Control-Request-Method: POST' \
-H 'Access-Control-Request-Headers: Content-Type,X-Api-Key'Content Security Policy
The frontend enforces a strict policy by default. Scripts, styles, fonts, connections, and workers are served from this deployment. Inline scripts and evaluation are blocked. Images may also use data/blob URLs for PDF tools; framing, plugins, and base URL changes are prohibited.
default-src 'none'; script-src 'self'; style-src 'self'; img-src 'self' data: blob:; font-src 'self'; connect-src 'self'; worker-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'To customize the policy, set SecurityHeaders:ContentSecurityPolicy to the complete policy string. To inspect violations without blocking resources, set SecurityHeaders:ContentSecurityPolicyReportOnly to true. This switches to the report-only header and disables CSP enforcement; keep the default false for enforcement. Review violations in browser developer tools. No report collection endpoint is included; configure your own collector and policy reporting directives if needed.
$env:SecurityHeaders__ContentSecurityPolicyReportOnly = 'true'
# Return to enforcement after reviewing browser violations:
$env:SecurityHeaders__ContentSecurityPolicyReportOnly = 'false'Suppress server and framework headers
Kestrel's Server header is disabled. Application responses remove Server, X-Powered-By, X-AspNet-Version, and X-AspNetMvc-Version, including validation and authentication errors. The supplied web.config also suppresses IIS server and framework headers on supported IIS 10 installations.
A reverse proxy, gateway, or HTTP.sys error response may add its own headers after the application runs. Configure that layer too, and inspect the public URL, including error responses. Header suppression reduces HTTP fingerprinting; it does not replace runtime updates. The source download and OpenAPI remain public, and iText's required PDF producer metadata is preserved.
curl -I '__API_ORIGIN__/docs'| Additional header | Default |
|---|---|
| X-Content-Type-Options | nosniff |
| X-Frame-Options | DENY |
| Referrer-Policy | no-referrer |
| Permissions-Policy | Camera, microphone, location, payment, and USB disabled |
| Cross-Origin-Opener-Policy / Resource-Policy | same-origin; API calls use CORS |
| Cache-Control | no-store |
| Strict-Transport-Security | 180 days on applicable HTTPS responses when HTTPS is required |
References: Microsoft CORS guidance, OWASP CSP guidance, and IIS header filtering.