Created
September 16, 2011 12:35
-
-
Save shawndumas/1222031 to your computer and use it in GitHub Desktop.
(Partial) XSS Fix For ASP.NET
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
' In the web.config | |
' | |
'<pages> | |
' <tagMapping> | |
' <clear /> | |
' <add tagType="System.Web.UI.WebControls.TextBox" | |
' mappedTagType="XSSTextBox"/> | |
' </tagMapping> | |
'</pages> | |
Imports Microsoft.Security.Application.Sanitizer | |
Public Class XSSTextBox | |
Inherits TextBox | |
Public Overrides Property Text() As String | |
Get | |
Return GetSafeHtmlFragment(MyBase.Text) | |
End Get | |
Set(ByVal value As String) | |
MyBase.Text = value | |
End Set | |
End Property | |
End Class |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment