如何在Edge/Chrome中无扩展或IE模式下用Classic ASP安全上传文件
Classic ASP 兼容现代浏览器的文件上传解决方案
问题根源
你之前使用的上传代码依赖IE旧特性,现代浏览器(Edge/Chrome)的安全策略禁止了这类非标准处理逻辑。改用ADODB Stream直接解析请求体的二进制数据,能适配现代浏览器严格遵循的multipart/form-data格式标准,解决兼容性问题。
前端表单修正
先确保上传表单符合标准格式,现代浏览器仅认可这种规范写法:
<form method="POST" enctype="multipart/form-data" action="upload.asp"> <input type="file" name="fileUpload"> <button type="submit">上传文件</button> </form>
后端ASP代码实现(基于ADODB Stream)
以下是完整的上传处理代码,直接替换原有逻辑即可:
<%@ Language=VBScript %> <% ' 禁用缓存 Response.Expires = 0 Response.Buffer = True Response.Clear ' 校验请求类型 If Request.ServerVariables("REQUEST_METHOD") <> "POST" Then Response.Write("请通过表单上传文件") Response.End End If Dim contentType, boundary, stream, content, startPos, endPos Dim fileNameStart, fileNameEnd, fileName, fileContentStart contentType = Request.ServerVariables("CONTENT_TYPE") ' 提取multipart分隔符 If InStr(contentType, "boundary=") > 0 Then boundary = Mid(contentType, InStr(contentType, "boundary=") + 9) If Left(boundary, 2) = "--" Then boundary = Mid(boundary, 3) boundary = "--" & boundary Else Response.Write("不支持的请求格式") Response.End End If ' 读取整个请求体 Set stream = Server.CreateObject("ADODB.Stream") stream.Type = 1 ' 二进制模式 stream.Open stream.Write Request.BinaryRead(Request.TotalBytes) stream.Position = 0 content = stream.ReadText stream.Close ' 定位文件片段起始位置 startPos = InStr(content, boundary & vbCrLf & "Content-Disposition: form-data; name=""fileUpload""; filename=""") If startPos = 0 Then Response.Write("未找到上传文件") Response.End End If ' 提取文件名 fileNameStart = startPos + Len(boundary & vbCrLf & "Content-Disposition: form-data; name=""fileUpload""; filename=""") fileNameEnd = InStr(fileNameStart, content, """") fileName = Mid(content, fileNameStart, fileNameEnd - fileNameStart) ' 过滤文件名中的非法字符 fileName = Replace(fileName, "/", "_") fileName = Replace(fileName, "\", "_") ' 定位文件内容起始位置 fileContentStart = InStr(fileNameEnd, content, vbCrLf & vbCrLf) + 4 endPos = InStr(fileContentStart, content, vbCrLf & boundary) ' 提取并保存文件二进制内容 Set stream = Server.CreateObject("ADODB.Stream") stream.Type = 1 stream.Open stream.Write Request.BinaryRead(Request.TotalBytes) stream.Position = fileContentStart stream.CopyTo stream, endPos - fileContentStart ' 替换为你的实际网络存储路径,确保IIS应用池有权限写入 Dim savePath savePath = "\\your-network-storage\" & fileName stream.SaveToFile savePath, 2 ' 2表示覆盖已存在的同名文件 stream.Close Set stream = Nothing Response.Write("文件上传成功:" & fileName) %>
关键注意事项
- 权限配置:确保IIS应用池的运行身份(默认是ApplicationPoolIdentity)对目标网络路径拥有读写权限,否则会出现保存失败。
- 文件名编码:如果上传文件名包含非ASCII字符,可调整
stream.ReadText的编码参数适配(比如指定stream.Charset = "UTF-8")。 - 文件大小限制:可通过修改IIS站点的
maxRequestEntityAllowed参数,调整允许上传的最大文件大小。
内容的提问来源于stack exchange,提问作者JNickVA1
相关产品推荐
相关产品推荐

