Easily adding Security Headers to your ASP.NET Core web app and getting an A grade

added by DotNetKicks
3/24/2020 12:59:17 AM


Well that sucks. That's my podcast website with an F rating from SecurityHeaders.com. What's the deal? I took care of this months ago! Turns out, recently I moved from Windows to Linux on Azure. If I am using IIS on Windows, I can (and did) make a section in my web.config that looks something like this.