【发布时间】:2017-03-14 19:42:12
【问题描述】:
如果您需要将有效的 JavaScript 或 URL 放入 .NET 按钮的 onclick 属性中,例如,安全扫描软件可能会标记任何不受信任的数据并要求您对值进行编码,但您最终会得到无效的 JS和/或 URL。
例如
这可行,但会被安全扫描标记:
someButton.Attributes["onclick"] = "document.location.href = '" + someUrl + "'; return false;";
这将是浏览器中的一堆转义字符:
someButton.Attributes["onclick"] = Microsoft.Security.Application.Encoder.HtmlAttributeEncode("document.location.href = '" + someUrl + "'; return false;");
这样也可以:
var encodedUrl = Microsoft.Security.Application.Encoder.UrlEncode(someUrl);
var encodedJs = Microsoft.Security.Application.Encoder.JavaScriptEncode(string.Format("document.location.href = '{0}'; return false;", endocdedUrl);
someButton.Attributes["onclick"] = encodedJs;
基于this thread,我也尝试使用Page.ClientScript.RegisterStartupScript,但同样,我发送到浏览器的任何已编码的内容都是无效的。
我想我可以在客户端上解码,但这肯定会否定整个编码练习?我一定在这里遗漏了一些明显的东西吗?
【问题讨论】:
标签: .net security encoding .net-4.0 attributes