asp/html/javascript: lege invoer niet toegestaan

Pagina: 1
Acties:

  • fatbenny
  • Registratie: April 2001
  • Laatst online: 07-03-2023
Ik heb een tekstbalk waar gebruikers berichten kunnen toevoegen (url zie signature) en ik heb een script geschreven om html-code, volledige lege velden en dubbel invoer tegen te gaan.

Alleen als de gebruiker 1 of meer spaties invoert en het toevoegt dan wordt het dus wel toegevoegd. Hoe kan je dit tegengaan in ASP?

Huidige code om html tegen te gaan:

strHtml = Request.form("msg")

'Strips the HTML tags from strHTML using split and join

'Ensure that strHTML contains something
If len(strHTML) = 0 then
stripHTML = strHTML
End If

dim arysplit, i, j, strOutput

arysplit = split(strHTML, "<")

'Assuming strHTML is nonempty, we want to start iterating
'from the 2nd array postition
if len(arysplit(0)) > 0 then j = 1 else j = 0

'Loop through each instance of the array
for i=j to ubound(arysplit)
'Do we find a matching > sign?
if instr(arysplit(i), ">") then
'If so, snip out all the text between the start of the string
'and the > sign
arysplit(i) = mid(arysplit(i), instr(arysplit(i), ">") + 1)
else
'Ah, the < was was nonmatching
arysplit(i) = "<" & arysplit(i)
end if
next

'Rejoin the array into a single string
strOutput = join(arysplit, "")

'Snip out the first <
strOutput = mid(strOutput, 2-j)

stripHTML = strOutput

Verwijderd

trim() of id.

  • Janoz
  • Registratie: Oktober 2000
  • Laatst online: 12-09 21:31

Janoz

Moderator Devschuur®

!litemod

Je string ff trimmen.. Dit kan al met javascript (trim()).. Je moet trouwens de validatie NOOIT alleen aan de clientside doen. Dat is natuurlijk wel handig en gebruikersvriendelijk, maar je kunt nooit zeker weten of die validatie wel werkelijk uitgevoerd wordt.

Ken Thompson's famous line from V6 UNIX is equaly applicable to this post:
'You are not expected to understand this'


  • fatbenny
  • Registratie: April 2001
  • Laatst online: 07-03-2023
ik heb trim toegepast en dat werkt.

over de veiligheid van clientside validatie:
wanneer is die validatie dan te omzeilen?

  • brammetje
  • Registratie: Oktober 2000
  • Laatst online: 12-01-2025
Op dinsdag 12 maart 2002 22:42 schreef fatbenny het volgende:
ik heb trim toegepast en dat werkt.

over de veiligheid van clientside validatie:
wanneer is die validatie dan te omzeilen?
door gewoon zelf het formuliertje na te maken en te posten?

  • fatbenny
  • Registratie: April 2001
  • Laatst online: 07-03-2023
Moet ik dan checken waar de bezoeker vandaan komt of zijn er andere opties misbruik tegen te gaan?

Verwijderd

Op dinsdag 12 maart 2002 22:30 schreef fatbenny het volgende:
'Ensure that strHTML contains something
If len(strHTML) = 0 then
stripHTML = strHTML
End If
[mierenneukmodus]
Wat doet dit?? Kom dat hele stripHTML nergens tegen en je zegt daar dat stripHTML = '' ??
[/mierenneukmodus]

  • Crazy D
  • Registratie: Augustus 2000
  • Laatst online: 12:14

Crazy D

I think we should take a look.

Op dinsdag 12 maart 2002 23:10 schreef fatbenny het volgende:
Moet ik dan checken waar de bezoeker vandaan komt of zijn er andere opties misbruik tegen te gaan?
Nope. Naja er zijn wel manieren voor om dat redelijk te voorkomen, maar tis een stuk makkelijker om alle validatie serverside te doen, en wat javascript controles erin gooien zodat er clientside al wat gecontroleerd wordt als aardigheidje voor de gebruiker.

Exact expert nodig?


  • Basszje
  • Registratie: Augustus 2000
  • Laatst online: 11-09 08:17

Basszje

Reisvaap!]

Je dan de validatie idd zowiezo op twee punten doen. Clientside, scheelt ook serverload, is vriendelijk en snel
en voor de echte zekerheid nog een keer in je ASP code :)

Beware of listening to the imposter; you are undone if you once forget that the fruits of the earth belong to us all, and the earth itself to nobody.

Pagina: 1