How do I show content that includes an html tag?
I am using FckEditor on Create.aspx page in asp.net mvc application.
Since I need to display rich text on web pages, I used the validateInput (false) top of action attribute method in the controller class.
And I used Html.Encode (Model.Message) in Details.aspx to protect user attack.
But I had a result that I didn't want:
<p> Hello </p>
I need the following result not above:
Hello
How can I show the text which user is typing?
Thanks in advance
a source to share
The short answer is that HTMLEncode makes your markup look like this. If you are not using HTMLEncode, it will do what you want.
You need to consider if you need full control over the markup, who is introducing the markup, and if an alternative like BBCode is an option.
If your users using the editor are bound to be "safe" users, then XSS is unlikely to be as exciting. However, if you use this in the comment field, BBCode is more appropriate, or something like using SO directly.
You won't be able to use a WYSIWYG editor and do HTMLEncode though ... (no BBCode or some other token system)
a source to share
The user seems to have typed "<p> Hello </p>"
(because of pressing Enter?) Into an edit control and it displays correctly in HTML as you did Html.Encode. For instance. paragraphs are not rendered, they are rendered as "<p>..</p>"
as the HTML string is encoded into something like "<p> Hello <p>"
.
If you don't need tags, I would suggest looking for a text string for the tags (things with <...>
) and removing them from the entered text. Do this before HTML.Encode.
... or am I missing something?
a source to share