You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e43b6ae
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: readme.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -147,7 +147,7 @@ is built on the one below and they compose in the same app.
147
147
|**Diagnostics**| Health checks with liveness/readiness tags, telemetry on the in-box primitives — one `Activity` per request continuing the caller's `traceparent`, and the OpenTelemetry HTTP metrics an ASP.NET dashboard already reads — and W3C access logs, rolled and pruned, written off the request path |
148
148
|**Formats**| Content negotiation in both directions — responses chosen from `Accept`, request bodies from `Content-Type`. JSON out of the box; XML, MessagePack and protobuf are one line each, and a format of your own is an `IOutputFormatter`/`IInputFormatter` pair. XML and MessagePack need no dependency and no attributes on your DTOs: they read the same `JsonTypeInfo` the JSON path reads, which is what keeps them AOT-clean where `XmlSerializer` cannot be |
149
149
|**Protocols**| HTTP/1.1, HTTP/2 (own HPACK), HTTP/3 (own QPACK), WebSockets, Server-Sent Events, trailing headers on all three versions, 103 Early Hints and other 1xx interim responses on all three. Never guessed — ALPN over TLS, connection preface over cleartext. WebSockets carry permessage-deflate, keepalive pings, and a registry for broadcasting to a group |
150
-
|**Content**| Static files from disk, embedded resources *or* a zip archive (on disk or embedded), a published Blazor WebAssembly app, streaming multipart uploads, downloads with byte ranges and conditional GETs, a file browser over a directory, and brotli/gzip/deflate compression in both directions, and RFC 9530 Content-Digest/Repr-Digest verified on uploads as they stream and sent on responses as a header or a trailer |
150
+
|**Content**| Static files from disk, embedded resources *or* a zip archive (on disk or embedded), a published Blazor WebAssembly app, streaming multipart uploads with a request body limit per endpoint (a large-upload route stays open while the rest of the server keeps a small default), downloads with byte ranges and conditional GETs, a file browser over a directory, and brotli/gzip/deflate compression in both directions, and RFC 9530 Content-Digest/Repr-Digest verified on uploads as they stream and sent on responses as a header or a trailer |
151
151
|**Security**| Authentication and authorization split ASP.NET-style, with Basic, API key, cookie and JWT schemes; policies, roles and claims; CORS, rate limiting and IP filtering, all with per-endpoint policies; host filtering against DNS rebinding; webhook receivers that verify GitHub, Stripe, Slack, Standard Webhooks and generic HMAC signatures over the raw body, with replay protection, duplicate suppression and key rotation, plus a signer for outgoing webhooks; signed double-submit antiforgery, the browser security headers, HSTS and an HTTPS redirect |
152
152
|**TLS**| Several endpoints with per-endpoint TLS, self-signed certificates generated in managed code (iOS and Android included), client certificates, and SPKI pinning for the app's own `HttpClient`; the PROXY protocol (v1 and v2) per endpoint, so the real client behind a TCP load balancer reaches the IP filter, rate limiter and logs; and publicly trusted certificates issued and renewed automatically over ACME (Let's Encrypt, ZeroSSL) and hot-swapped with no restart |
153
153
|**OpenAPI**| An OpenAPI 3.0.3 document built entirely from compile-time metadata and your `JsonSerializerContext` — no reflection, no document object model — one document per API version, and a Scalar API reference page that the browser loads from the CDN, so the app ships no UI |
0 commit comments