ASP.NET MVC能否默认执行HtmlEncode?请求自动编码及[HtmlAllowed]属性问询
好问题!这两个需求在ASP.NET(不管是Framework还是Core)生态里都完全可以实现,我来给你拆解一下具体怎么做:
一、实现请求接收时自动执行HtmlEncode
你完全不需要手动调用HtmlEncode,可以通过Action过滤器或者自定义模型绑定器来统一处理,这样所有符合规则的请求参数都会自动完成编码,避免重复工作。
最推荐的是用Action过滤器的方式,灵活性很高,既可以全局生效,也可以针对单个Action/Controller启用。这里给你一个完整的实现示例:
public class AutoHtmlEncodeAttribute : ActionFilterAttribute { public override void OnActionExecuting(ActionExecutingContext context) { // 遍历所有Action参数 foreach (var key in context.ActionArguments.Keys.ToList()) { var value = context.ActionArguments[key]; // 处理字符串类型参数 if (value is string strValue && !IsHtmlAllowed(context, key)) { context.ActionArguments[key] = HttpUtility.HtmlEncode(strValue); } // 处理复杂模型对象(递归遍历属性) else if (value != null && value.GetType().IsClass && !value.GetType().IsPrimitive) { ProcessModelProperties(value); } } base.OnActionExecuting(context); } // 递归处理模型的所有字符串属性 private void ProcessModelProperties(object model) { foreach (var prop in model.GetType().GetProperties()) { if (prop.PropertyType == typeof(string) && !prop.IsDefined(typeof(HtmlAllowedAttribute), inherit: true)) { var currentValue = prop.GetValue(model) as string; if (!string.IsNullOrEmpty(currentValue)) { prop.SetValue(model, HttpUtility.HtmlEncode(currentValue)); } } // 处理嵌套的复杂对象 else if (prop.PropertyType.IsClass && !prop.PropertyType.IsPrimitive && prop.PropertyType != typeof(string)) { var nestedModel = prop.GetValue(model); if (nestedModel != null) { ProcessModelProperties(nestedModel); } } } } // 检查当前参数是否标记了允许HTML的属性 private bool IsHtmlAllowed(ActionExecutingContext context, string paramKey) { var parameter = context.ActionDescriptor.Parameters.FirstOrDefault(p => p.Name == paramKey); return parameter != null && parameter.IsDefined(typeof(HtmlAllowedAttribute), inherit: true); } }
二、自定义[HtmlAllowed]属性实现HTML允许
框架默认没有[HtmlAllowed]这个属性,但我们可以自己定义一个标记类,配合上面的过滤器使用,实现"例外字段不编码"的需求:
// 标记类,用来标识哪些参数/属性允许HTML内容 [AttributeUsage(AttributeTargets.Parameter | AttributeTargets.Property, AllowMultiple = false)] public class HtmlAllowedAttribute : Attribute { // 不需要额外逻辑,仅作为标记使用 }
使用示例
1. 直接在Action参数上标记
// 给当前Action启用自动编码 [AutoHtmlEncode] public IActionResult CreateQuestion([HtmlAllowed] string content, string title) { // title会被自动HtmlEncode,content则保持原始HTML内容 _questionRepo.Add(new Question { Title = title, Content = content }); return Ok(); }
2. 在模型类的属性上标记
public class QuestionModel { // 该属性会被自动编码 public string Title { get; set; } // 该属性允许HTML,跳过编码 [HtmlAllowed] public string Content { get; set; } } [AutoHtmlEncode] public IActionResult CreateQuestion(QuestionModel model) { // model.Title已完成编码,model.Content保留原始HTML _questionRepo.Add(new Question { Title = model.Title, Content = model.Content }); return Ok(); }
额外提醒
如果允许用户输入HTML,一定要注意XSS攻击防护!不要直接将用户输入的HTML渲染到页面上,建议配合AntiXSS类库过滤掉危险标签(比如<script>、<iframe>等),确保只有安全的HTML才能存入数据库和展示。
内容的提问来源于stack exchange,提问作者Alexander Grek
相关产品推荐
相关产品推荐

