ASP Calendar控件SelectedDate对未来日期失效问题求助
问题描述
我网站中的ASP Calendar控件(ID为UDExpiryCalendar)在页面加载赋值时出现异常:从用户记录读取DateTime类型数据后,给UDExpiryCalendar.VisibleDate和UDExpiryCalendar.SelectedDate赋值并执行DataBind(),结果如下:
- 日期为过去时:年月显示正确,目标日期选中正常
- 日期为当月时:年月显示正确,当前日期变灰,目标日期(哪怕是未来几天)选中正常
- 日期为未来月份时:年月显示正确,但目标日期未被选中
后台C#代码
var userID = Request.QueryString["ID"]; string getUserInfo = "select * from UserList where Id =" + userID; SqlCommand getUserInfocmd = new SqlCommand(getUserInfo, con); getUserInfocmd.ExecuteNonQuery(); DataTable dt = new DataTable(); SqlDataReader sqlDR = getUserInfocmd.ExecuteReader(); dt.Load(sqlDR); sqlDR.Close(); DateTime oldExpiryDate = Convert.ToDateTime(dt.Rows[0][6]); UDExpiryCalendar.VisibleDate = oldExpiryDate; UDExpiryCalendar.SelectedDate = oldExpiryDate; UDExpiryCalendar.DataBind();
前台ASP代码
<asp:Calendar ID="UDExpiryCalendar" runat="server" BackColor="White" BorderColor="#999999" CellPadding="4" DayNameFormat="Shortest" Font-Names="Verdana" Font-Size="8pt" ForeColor="Black" Height="180px" Width="200px"> <DayHeaderStyle BackColor="#CCCCCC" Font-Bold="True" Font-Size="7pt" /> <NextPrevStyle VerticalAlign="Bottom" /> <OtherMonthDayStyle ForeColor="#808080" /> <SelectedDayStyle BackColor="#666666" Font-Bold="True" ForeColor="White" /> <SelectorStyle BackColor="#CCCCCC" /> <TitleStyle BackColor="#999999" BorderColor="Black" Font-Bold="True" /> <TodayDayStyle BackColor="#CCCCCC" ForeColor="Black" /> <WeekendDayStyle BackColor="#FFFFCC" /> </asp:Calendar>
解决思路
移除多余的
DataBind()调用
ASP Calendar控件不需要手动执行DataBind(),它的选中状态由SelectedDate直接维护,手动调用DataBind()会重置控件状态,导致未来日期的选中状态被覆盖。直接删除UDExpiryCalendar.DataBind();这行代码即可。限制赋值逻辑仅在首次加载执行
把赋值代码放到!IsPostBack判断中,避免页面回发时重复赋值重置控件状态:
protected void Page_Load(object sender, EventArgs e) { if (!IsPostBack) { var userID = Request.QueryString["ID"]; // 改用参数化查询修复SQL注入漏洞 string getUserInfo = "select * from UserList where Id = @UserId"; SqlCommand getUserInfocmd = new SqlCommand(getUserInfo, con); getUserInfocmd.Parameters.AddWithValue("@UserId", userID); // 移除无用的ExecuteNonQuery()调用 DataTable dt = new DataTable(); SqlDataReader sqlDR = getUserInfocmd.ExecuteReader(); dt.Load(sqlDR); sqlDR.Close(); // 增加空数据判断,避免索引越界 if(dt.Rows.Count > 0) { // 仅取日期部分,排除时间干扰 DateTime oldExpiryDate = Convert.ToDateTime(dt.Rows[0][6]).Date; UDExpiryCalendar.VisibleDate = oldExpiryDate; UDExpiryCalendar.SelectedDate = oldExpiryDate; } } }
修复SQL注入漏洞
原代码直接拼接userID到SQL语句中,存在严重安全风险,必须改用参数化查询,如上代码所示。检查日期可选范围限制
确认控件未设置SelectionMode或SelectableDateRange属性限制未来日期的选中权限,若有相关设置,需调整为允许选择未来日期。
内容的提问来源于stack exchange,提问作者TimEdwards
相关产品推荐
相关产品推荐

