Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
467 views
in Technique[技术] by (71.8m points)

ASP.NET MVC Validation of Script Tags

I want to prevent a user from entering any <script> tags inside a textarea box I have called story using very similar code to this:

if (ArticleToCreate.story.Contains("<script>") == true)
                ModelState.AddModelError("Story", "No script tags allowed!");

Unfortunately this won't work because it's looking for <script> exactly as it is rather than looking for <script>some code</script> or some code`

Can anyone help? I want to use very similar code to as shown above and not any Service Layers or Model scripts. Thanks

See Question&Answers more detail:os

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Reply

0 votes
by (71.8m points)

By default, MVC won't allow this. If you explicitly allow it (e.g., with [ValidateInput(false)]), then you need to use a tool like the Microsoft Web Protection Library to sanitize the input.


与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
OGeek|极客中国-欢迎来到极客的世界,一个免费开放的程序员编程交流平台!开放,进步,分享!让技术改变生活,让极客改变未来! Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Click Here to Ask a Question

...