Web API 2.0中如何为HttpGet传递DateTime参数?解决危险值报错
Hey Rajnesh, I’ve dealt with this exact error a handful of times when passing DateTime parameters via URL in GET APIs—let’s break down the most practical, secure fixes depending on your tech stack:
Common Root Cause
The error usually pops up because your framework (most often ASP.NET) flags certain characters in your date format (like slashes / in 2024/05/20) as potentially malicious. The good news is you don’t have to sacrifice security to fix it.
Solutions
1. Use ISO 8601 Date Format (Safest First Step)
Skip the risky character issues entirely by using the ISO 8601 standard format for your dates. This format is universally supported and won’t trigger request validation:
- Date only:
yyyy-MM-dd(e.g.,startdate=2024-05-20) - Date + time:
yyyy-MM-ddTHH:mm:ss(e.g.,startdate=2024-05-20T09:30:00)
Just update your client to send dates in this format, and your API should bind the parameters without any errors—no config changes needed.
2. Encode Special Characters in the URL
If you must stick with your existing date format (like MM/dd/yyyy), make sure the client encodes special characters like slashes. For example:
- Raw date:
2024/05/20→ Encoded:2024%2F05%2F20 - Your URL becomes:
https://yourapi.com/data?startdate=2024%2F05%2F20&enddate=2024%2F05%27
Most HTTP clients (like Postman, axios, or HttpClient) can auto-encode parameters if you pass them as key-value pairs instead of hardcoding the URL string.
3. Selectively Disable Request Validation (For ASP.NET Frameworks)
If the above fixes aren’t feasible, you can disable request validation only for your API endpoint (never globally—it’s a security risk):
For ASP.NET MVC/Web Forms
- Per Controller/Method: Add the
[ValidateInput(false)]attribute to your API method:[HttpGet] [ValidateInput(false)] public ActionResult FetchData(DateTime startdate, DateTime enddate) { // Your business logic here } - Per Endpoint in Web.config: If you need to target a specific path without touching code:
<configuration> <location path="api/your-endpoint"> <system.web> <pages validateRequest="false" /> <httpRuntime requestValidationMode="4.5" /> </system.web> </location> </configuration>
For ASP.NET Core
ASP.NET Core’s request validation is more lenient by default, but if you still hit the error, you can adjust validation settings for your controllers:
builder.Services.AddControllers(options => { // Disable automatic validation for non-nullable parameters if needed options.SuppressImplicitRequiredAttributeForNonNullableReferenceTypes = true; });
4. Explicitly Bind DateTime Parameters (Optional)
Sometimes the error is a side effect of failed parameter binding. To ensure your framework correctly parses the date, add a [Bind] attribute or specify the format in your model:
public ActionResult FetchData([Bind(Prefix = "startdate")] DateTime startDate, [Bind(Prefix = "enddate")] DateTime endDate) { // Logic here }
Or use a model with format annotations:
public class DateRangeModel { [DisplayFormat(DataFormatString = "{0:yyyy-MM-dd}", ApplyFormatInEditMode = true)] public DateTime startdate { get; set; } [DisplayFormat(DataFormatString = "{0:yyyy-MM-dd}", ApplyFormatInEditMode = true)] public DateTime enddate { get; set; } }
Final Notes
Always prioritize the ISO 8601 format or parameter encoding first—these fixes keep your API secure while resolving the error. Only disable validation selectively if you have no other option.
内容的提问来源于stack exchange,提问作者Rajnesh Giri

