Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6241939
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 24, 20262026-05-24T11:51:32+00:00 2026-05-24T11:51:32+00:00

i have a textarea and I am using ckeditor to allow users to enter

  • 0

i have a textarea and I am using ckeditor to allow users to enter data and click upload. This will save the html of this data to a mysql database table to display on a separate web page

What do i need to worry about in terms of what people are posting. Do i need to add any validation on the front end or back end to ensure that they are not posting dangerous scripts, etc . .

What is the easiest way to validate that what is being posted is fine to store and put back to the client to display later.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-24T11:51:34+00:00Added an answer on May 24, 2026 at 11:51 am

    Do i need to add any validation on the front end or back end to ensure
    that they are not posting dangerous scripts, etc

    No, you shouldn’t worry about this. As far as you use parametrized queries in order to store data to avoid SQL injection a relational database doesn’t care much about what kind of text you are throwing at it.

    Problems might arise when you try to display this data back on a web page. It is at this moment that you should ensure that it is properly HTML encoded.

    For razor:

    @...
    

    For WebForms (ASP.NET 4.0)

    <%: ...
    

    For WebForms (prior to ASP.NET 4.0)

    <%= Html.Encode(... 
    

    Or for all of the above:

    Html.DisplayFor(x => x.SomePropertyOftheViewModel)
    

    What is the easiest way to validate that what is being posted is fine
    to store and put back to the client to display later.

    Parametrized queries to store data (only if you are using a relational database) and HTML encode to display back.

    You might also find the following blog post useful about the Microsoft Anti-Xss library.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Let's say I have an html form. Each input/select/textarea will have a corresponding <label>
I have a form with a textarea. Users enter a block of text which
I'm using a HTML form's TEXTAREA field that will contain text and it may
I have saved input from a textarea element to a TEXT column in MySQL.
I am creating an editor in asp.net MVC application using ckeditor. In textarea i
I'm using CKEditor on a textarea and the jQuery validation plugin ( http://bassistance.de/jquery-plugins/jquery-plugin-validation/ )
I have traced the root of this exception to the sourcearea plugin of CKEditor
I'm using Javascript to create a textarea that I want to be a ckeditor.
I have a textarea in a form that will eventually be an email form.
i have a web application built with HTML(front-end),java(server-side) and i have a textarea when

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.