Security with QueryString values in Asp.net MVC

前端 未结 7 1169
迷失自我
迷失自我 2020-12-10 08:30

How do you properly ensure that a user isnt tampering with querystring values or action url values? For example, you might have a Delete Comment action on your CommentContro

7条回答
  •  予麋鹿
    予麋鹿 (楼主)
    2020-12-10 09:01

    Enrypting and decrypting query params is a trivial process and there are some great examples of how to do so using an HttpModule here on StackOverflow.

    "You Don't", "You can't", or "It's not easy" are simply not acceptable responses in this day and age...

提交回复
热议问题