ASP Classic中父窗口传QueryString给弹窗填充输入框并区分打开方式
Solution
Let's fix both your pages to meet the requirement: populate textboxes only when Rate_Add.aspx is opened as a popup from update_status.asp, and keep them empty when accessed directly.
1. Corrected update_status.asp Code
First, we'll ensure query string parameters are properly encoded to avoid issues with special characters (like slashes in dates) and align the page name with your actual file (ASP.NET is case-sensitive on most servers):
var myWindow = window.open( "Rate_Add.aspx?loggedin=yes&indate=<%=Server.URLEncode(indate)%>&outdate=<%=Server.URLEncode(outdate)%>&curr=", "", "width=1200,height=600,toolbars=no,scrollbars,resizeable=no,left=50,top=50" );
Key Fixes:
- Changed
rateadd.aspxtoRate_Add.aspxto match your actual page filename - Used
Server.URLEncode()onindateandoutdateto safely pass special characters in the query string (prevents broken URLs if dates contain slashes or spaces)
2. Corrected Rate_Add.aspx Code
Next, we'll fix JavaScript syntax errors, safely escape values, and ensure textboxes are only populated when opened via a popup:
<script language="javascript" type="text/javascript"> // Check if the page was opened via a popup (window.opener exists and isn't the same window) if (window.opener && window.opener !== window) { // Safely retrieve and escape query string values to avoid JS syntax errors/XSS var indate = "<%=HttpUtility.JavaScriptStringEncode(Request.QueryString["indate"] ?? "")%>"; var outdate = "<%=HttpUtility.JavaScriptStringEncode(Request.QueryString["outdate"] ?? "")%>"; // Populate the textboxes document.getElementById("from_date1").value = indate; document.getElementById("to_date1").value = outdate; } else { // Clear textboxes explicitly when opened directly document.getElementById("from_date1").value = ""; document.getElementById("to_date1").value = ""; } </script>
Key Fixes:
- Fixed missing quotes: Added quotes around the
outdatevalue (original code omitted these, causing JavaScript errors for date strings) - Removed extra space: Eliminated the unnecessary space before the
indatevalue assignment - Safe value escaping: Used
HttpUtility.JavaScriptStringEncode()to properly escape values for JavaScript, preventing syntax issues (e.g., if dates contain quotes) and XSS vulnerabilities - Robust popup check: Added
window.opener !== windowto handle edge cases wherewindow.openermight point to the same window - Explicit clear logic: Added an
elseblock to ensure textboxes are empty when opened directly, even if query string parameters are present manually
Notes:
- Double-check that the textbox IDs (
from_date1andto_date1) match exactly with the IDs in yourRate_Add.aspxmarkup - For older ASP.NET versions that don’t support the null-coalescing operator (
??), replaceRequest.QueryString["indate"] ?? ""withstring.IsNullOrEmpty(Request.QueryString["indate"]) ? "" : Request.QueryString["indate"]
内容的提问来源于stack exchange,提问作者Ashutosh Singh
相关产品推荐
相关产品推荐

