Welcome to OStack Knowledge Sharing Community for programmer and developer-Open, Learning and Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
508 views
in Technique[技术] by (71.8m points)

ASP.NET MVC Validation of Script Tags

I want to prevent a user from entering any <script> tags inside a textarea box I have called story using very similar code to this:

if (ArticleToCreate.story.Contains("<script>") == true)
                ModelState.AddModelError("Story", "No script tags allowed!");

Unfortunately this won't work because it's looking for <script> exactly as it is rather than looking for <script>some code</script> or some code`

Can anyone help? I want to use very similar code to as shown above and not any Service Layers or Model scripts. Thanks

See Question&Answers more detail:os

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Answer

0 votes
by (71.8m points)

By default, MVC won't allow this. If you explicitly allow it (e.g., with [ValidateInput(false)]), then you need to use a tool like the Microsoft Web Protection Library to sanitize the input.


与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome to OStack Knowledge Sharing Community for programmer and developer-Open, Learning and Share
Click Here to Ask a Question

...