Secure Razor Pattern Engine

I am new to asp.net mvc 3, I am developing a website that allows the user to customize their layout and use the razor template mechanism. Tey could direct editing the template file.

How to cut a user only permits the use of some explicit helper in the template. I do not want the user to access other dangerous server functions and use only what I added.

thank

+3
source share
1 answer

There are two cases:

  • You trust your users: in this case you should not worry, as they will not violate your site.
  • ( ): . , , . . , , WYSIWYG, WMD, .
+3

Source: https://habr.com/ru/post/1776628/


All Articles