44 lines
1.4 KiB
C#
44 lines
1.4 KiB
C#
using Elternbeirat.Web.Components;
|
|
using Elternbeirat.Web.Services;
|
|
using Microsoft.AspNetCore.HttpOverrides;
|
|
|
|
var builder = WebApplication.CreateBuilder(args);
|
|
|
|
// Add services to the container.
|
|
builder.Services.AddRazorComponents();
|
|
|
|
// Content is read once at startup and cached -> singletons.
|
|
builder.Services.AddSingleton<PageService>();
|
|
builder.Services.AddSingleton<PostService>();
|
|
|
|
var app = builder.Build();
|
|
|
|
// NPM terminates TLS and is the only way to reach the container (no port
|
|
// mapping in production). Without UseForwardedHeaders the app sees every request
|
|
// as HTTP and with the proxy IP instead of the client IP.
|
|
// KnownNetworks/KnownProxies are deliberately empty because only NPM reaches
|
|
// the container.
|
|
app.UseForwardedHeaders(new ForwardedHeadersOptions
|
|
{
|
|
ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto,
|
|
KnownIPNetworks = { },
|
|
KnownProxies = { }
|
|
});
|
|
|
|
// Configure the HTTP request pipeline.
|
|
if (!app.Environment.IsDevelopment())
|
|
{
|
|
app.UseExceptionHandler("/Error", createScopeForErrors: true);
|
|
// No UseHsts() and no UseHttpsRedirection(): NPM sets HSTS and terminates
|
|
// TLS. Both here would create a redirect loop behind the proxy.
|
|
}
|
|
|
|
app.UseStatusCodePagesWithReExecute("/not-found", createScopeForStatusCodePages: true);
|
|
|
|
app.UseAntiforgery();
|
|
|
|
app.MapStaticAssets();
|
|
app.MapRazorComponents<App>();
|
|
|
|
app.Run();
|