.NET Core数据注解与Remote验证的前后端有效性及安全性问询
Let’s break down each of your questions clearly—since server-side validation is non-negotiable when users disable JavaScript or bypass client-side checks:
1. Do .NET Core Data Annotations support both client-side and server-side validation? Do I need extra server-side logic?
Absolutely! Most built-in data annotations like [Required], [StringLength], [EmailAddress], etc., work for both client-side and server-side validation:
- Client-side: The
jquery.validate.unobtrusivelibrary automatically generates validation rules from these annotations, giving users instant feedback before submitting. - Server-side: When you check
ModelState.IsValidin your action method, ASP.NET Core automatically validates the model against all data annotations.
You don’t need to write extra server-side validation logic for these basic rules—just make sure you always check ModelState.IsValid before processing the request.
2. Does the [Remote] attribute support both front-end and back-end validation?
Yes, it does! Here’s how it works:
- Client-side: When the user enters data in the field, jQuery Unobtrusive Validation sends an AJAX request to your specified action method (your
VerifyCargomethod) to check validity. If it returns an error message, the client displays it immediately. - Server-side: When you check
ModelState.IsValidin your post action, ASP.NET Core will automatically invoke the[Remote]action method again to re-validate the field. This ensures validation runs even if the user bypasses client-side checks (e.g., disabling JS).
3. Do I still need to perform additional validation in actions like Create?
Yes, absolutely—even with data annotations and [Remote] validation.
While [Remote] checks uniqueness during client input, there’s a small window between that check and the actual database save where another user could insert the same value (a concurrency issue). Plus, malicious users could directly send a POST request without going through the client-side form.
For your cargo description uniqueness check, add a final validation step right before saving to the database—it’s your last line of defense.
4. Is ModelState.IsValid() compatible with [Remote] validation?
Yes! When you call ModelState.IsValid, ASP.NET Core triggers all validation rules—including the server-side invocation of your [Remote] action. If the [Remote] check fails (returns an error message instead of true), ModelState.IsValid will return false, and the error message will be added to ModelState for you to display in the view.
Example: Securing Your Create Action
Here’s how to update your Create action to ensure full security, building on your existing ValidateName method:
[HttpPost] [ValidateAntiForgeryToken] public IActionResult Create(RH_Cargos cargo) { // First, check ModelState (includes [Remote] validation results) if (!ModelState.IsValid) { return View(cargo); } // Perform a final uniqueness check to prevent concurrency issues var existingCargo = ValidateName(cargo.Descricao); if (existingCargo != null) { ModelState.AddModelError(nameof(cargo.Descricao), $"Description {cargo.Descricao} is already in use."); return View(cargo); } // Save to database only if all checks pass _context.RH_Cargos.Add(cargo); _context.SaveChanges(); return RedirectToAction(nameof(Index)); }
Key Takeaway for [Remote] Security
Your [Remote] setup covers both client-side and server-side validation, but it’s not enough on its own. Always:
- Check
ModelState.IsValidin your post action. - Add a final database check before saving to handle concurrency and direct POST requests.
内容的提问来源于stack exchange,提问作者Ricardo Figueiredo

