You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.Net中DropDownList(AutoPostBack)与RequiredFieldValidator异常问题

问题:DropDownList联动验证与颜色代码显示冲突处理

我有一个启用AutoPostBack的DropDownList和RequiredFieldValidator,期望用户选择颜色时,右侧dx:ASPxLabel控件显示对应HTML颜色代码;选择「Select」选项时,显示「Required」提示。

现有代码

前端代码

<dx:LayoutItem ColSpan="1" FieldName="Color">
   <LayoutItemNestedControlCollection>
      <dx:LayoutItemNestedControlContainer runat="server">
          <div style="display: flex; column-gap: 10px;">
               <dx:LayoutItemNestedControlContainer runat="server">
                   <asp:DropDownList ID="cboColor" runat="server" Width="90px" AutoPostBack="True">
                       <asp:ListItem>Select</asp:ListItem>
                       <asp:ListItem>Black</asp:ListItem>
                       <asp:ListItem>Yellow</asp:ListItem>
                       <asp:ListItem>Red</asp:ListItem>
                       <asp:ListItem>Blue</asp:ListItem>
                   </asp:DropDownList>
                </dx:LayoutItemNestedControlContainer>
                <asp:RequiredFieldValidator ID="RequiredFieldValidator2" ErrorMessage="Required" ControlToValidate="cboColor" InitialValue="Select" runat="server" ForeColor="Red" Font-Bold="true" Display="Dynamic"  />
                <dx:ASPxLabel ID="lblCompleteColor" runat="server" Text="" Font-Bold="true"></dx:ASPxLabel>
           </div>
        </dx:LayoutItemNestedControlContainer>
     </LayoutItemNestedControlCollection>
 </dx:LayoutItem>

后端代码

Protected Sub cboColor_SelectedIndexChanged(sender As Object, e As EventArgs) Handles cboColor.SelectedIndexChanged
    lblCompleteColor.Text = GetCodeColor(cboColor.SelectedValue)
End Sub

Private Function GetCodeColor(ByVal sCodeColor As String) As String
    Dim sResult As String = ""
    Dim conSQL As New System.Data.SqlClient.SqlConnection(ConfigurationManager.ConnectionStrings("ETConnectionString").ConnectionString)
    Dim cmdSQL As New System.Data.SqlClient.SqlCommand("SELECT CodiceColore FROM COLORI WHERE NomeColore='" & sCodeColor & "'", conSQL)

    Try
        conSQL.Open()
        sResult = cmdSQL.ExecuteScalar()
    Catch ex As Exception
        sResult = ""
    Finally
        conSQL.Close()
    End Try
    Return sResult
End Function

问题现象

  • 未给DropDownList设置CausesValidation属性时,选中「Select」后「Required」提示一闪即逝;
  • 设置CausesValidation="true"后,「Required」提示保留,但会显示之前选中的颜色代码。

解决方案

1. 调整前端DropDownList配置

给DropDownList添加CausesValidation="true",确保每次PostBack都触发验证:

<asp:DropDownList ID="cboColor" runat="server" Width="90px" AutoPostBack="True" CausesValidation="true">

2. 修改后端SelectedIndexChanged事件逻辑

在赋值颜色代码前,先重置标签文本,并结合选中项和页面验证状态控制显示:

Protected Sub cboColor_SelectedIndexChanged(sender As Object, e As EventArgs) Handles cboColor.SelectedIndexChanged
    ' 先重置标签内容,避免残留旧数据
    lblCompleteColor.Text = ""
    
    ' 仅当选中非Select选项且验证通过时,才获取并显示颜色代码
    If cboColor.SelectedValue <> "Select" AndAlso Page.IsValid Then
        lblCompleteColor.Text = GetCodeColor(cboColor.SelectedValue)
    End If
End Sub

3. 修复SQL注入漏洞(关键优化)

原GetCodeColor方法存在SQL注入风险,改用参数化查询:

Private Function GetCodeColor(ByVal sCodeColor As String) As String
    Dim sResult As String = ""
    Dim conSQL As New System.Data.SqlClient.SqlConnection(ConfigurationManager.ConnectionStrings("ETConnectionString").ConnectionString)
    
    ' 使用参数化查询避免SQL注入
    Dim cmdSQL As New System.Data.SqlClient.SqlCommand("SELECT CodiceColore FROM COLORI WHERE NomeColore=@NomeColore", conSQL)
    cmdSQL.Parameters.AddWithValue("@NomeColore", sCodeColor)
    
    Try
        conSQL.Open()
        Dim resultObj As Object = cmdSQL.ExecuteScalar()
        If resultObj IsNot Nothing Then
            sResult = resultObj.ToString()
        End If
    Catch ex As Exception
        sResult = ""
    Finally
        conSQL.Close()
    End Try
    
    Return sResult
End Function

逻辑说明

  • CausesValidation="true"确保选中「Select」时,RequiredFieldValidator触发验证并保留错误提示;
  • 事件中先重置标签文本,彻底避免残留之前的颜色代码;仅当选中有效颜色且验证通过时,才加载并显示对应代码;
  • 参数化查询彻底解决了原代码的SQL注入风险,提升应用安全性。

内容的提问来源于stack exchange,提问作者Ahmad Shatti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 07:37:34