AJAX调用ASMX WebService遇Error 500及XML格式错误求助
问题:ASMX WebService通过AJAX调用报500错误(根节点数据无效)
问题详情
在Visual Studio中开发了带参数的ASMX WebService,核心代码如下,单独测试可正常返回结果:
Public Function CheckPalletInLocation(location As String) As String Dim ScaleConnnection As New SqlClient.SqlConnection("MYCONNEXION") Dim ScaleCommand As New SqlClient.SqlCommand ScaleCommand.Connection = ScaleConnnection ScaleConnnection.Open() ScaleCommand.CommandText = "SELECT DISTINCT LOGISTICS_UNIT FROM LOCATION_INVENTORY WHERE LOCATION = '" & location & "'" Return ScaleCommand.ExecuteScalar() ScaleConnnection.Close() 'Return "True" End Function
但通过以下AJAX代码调用时,始终返回Error 500,响应提示:服务器无法处理请求,根节点数据无效,第1行第1位:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN"> <HTML> <HEAD> <title>TEST WEB SERVICE</title> <script type="text/javascript" src="jquery-3.4.1.js"></script> </HEAD> <BODY onload="Click_BB();">PAGE <script> function Click_BB() { $.ajax({ type: 'post', url: 'https://localhost:44341/WebService1.asmx?op=CheckPalletInLocation', contentType: "application/xml", data: { location: '110-01-03-10' }, success: function (d) { alert(d); }, failure: function (response) { debugger; alert(response.d); } }); } </script> </BODY> </HTML>
错误原因
- 请求格式不匹配:AJAX设置了
contentType: "application/xml",但发送的data是JSON对象格式,服务器无法解析XML格式的请求,导致根节点无效错误。 - 响应处理逻辑错误:ASMX WebService针对JSON请求返回的结果会包裹在
d属性中,原success函数直接alert(d)无法正确获取有效数据。 - WebService代码隐患:原代码存在SQL注入风险,且
ScaleConnnection.Close()在Return语句之后不会执行,可能导致数据库连接泄漏。
修复方案
方案1:改用JSON格式请求(推荐)
修改AJAX代码,适配ASMX的JSON处理规范:
function Click_BB() { $.ajax({ type: 'post', url: 'https://localhost:44341/WebService1.asmx/CheckPalletInLocation', // 直接使用方法名,无需op参数 contentType: "application/json; charset=utf-8", // 指定JSON格式 dataType: "json", // 预期返回JSON类型 data: JSON.stringify({ location: '110-01-03-10' }), // 序列化为JSON字符串 success: function (response) { alert(response.d); // 读取包裹在d属性中的返回值 }, error: function (xhr, status, error) // 使用jQuery标准error回调替代failure { debugger; alert("错误:" + error + ",状态:" + status); } }); }
同时确保WebService类添加[ScriptService]特性,启用JSON请求支持:
<System.Web.Script.Services.ScriptService()> _ Public Class WebService1 Inherits System.Web.Services.WebService ' 你的CheckPalletInLocation方法 End Class
方案2:使用SOAP XML格式请求
如果必须使用XML格式,需构造符合SOAP规范的请求数据:
function Click_BB() { var xmlData = '<?xml version="1.0" encoding="utf-8"?>' + '<soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/">' + ' <soap:Body>' + ' <CheckPalletInLocation xmlns="http://tempuri.org/">' + ' <location>110-01-03-10</location>' + ' </CheckPalletInLocation>' + ' </soap:Body>' + '</soap:Envelope>'; $.ajax({ type: 'post', url: 'https://localhost:44341/WebService1.asmx', contentType: "text/xml; charset=utf-8", dataType: "xml", data: xmlData, success: function (xml) { // 解析XML提取返回结果 var result = $(xml).find("CheckPalletInLocationResult").text(); alert(result); }, error: function (xhr, status, error) { debugger; alert("错误:" + error + ",状态:" + status); } }); }
修复WebService代码隐患
修改WebService代码,使用参数化查询避免SQL注入,并用Using语句确保数据库连接自动关闭:
Public Function CheckPalletInLocation(location As String) As String Using ScaleConnection As New SqlClient.SqlConnection("MYCONNEXION") Using ScaleCommand As New SqlClient.SqlCommand("SELECT DISTINCT LOGISTICS_UNIT FROM LOCATION_INVENTORY WHERE LOCATION = @Location", ScaleConnection) ScaleCommand.Parameters.AddWithValue("@Location", location) ScaleConnection.Open() Dim result = ScaleCommand.ExecuteScalar() Return If(result IsNot Nothing, result.ToString(), "") End Using End Using End Function
内容的提问来源于stack exchange,提问作者MANUEL
相关产品推荐
相关产品推荐

