Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6344621
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 24, 20262026-05-24T20:40:38+00:00 2026-05-24T20:40:38+00:00

Spoiled by Ruby on Rails (3), I expect all my HTML output to be

  • 0

Spoiled by Ruby on Rails (3), I expect all my HTML output to be automatically encoded.

I asked this question about script exploits a bit earlier and am now wondering, is there some setting, plugin or extension for ASP.NET that will automatically cause all HTML to be HtmlEncode‘ed or do I have to be really careful and ensure that on my own?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-24T20:40:38+00:00Added an answer on May 24, 2026 at 8:40 pm

    Various ASP.NET controls automatically encode HTML with HtmlEncode (and a few do URL encoding with UrlEncode), but it’s not universal. Here’s a list of controls and what encoding (if any) they do automatically. I don’t know if it’s updated for .NET 4.0 or not:

    Which ASP.NET Controls Automatically Encodes? (this link will ask you to save the document)

    This is the blog that the above document is from:

    http://blogs.msdn.com/b/sfaust/archive/2008/09/02/which-asp-net-controls-automatically-encodes.aspx

    It was originally posted in Sep 2008, so it’s probably current for 2.0, but not necessarily 4.0. Still a useful resource to have, though, IMO.

    You should also look at the Microsoft Anti-Cross Site Scripting Library 3.1.

    As pointed out by balexandre, it appears the Anit-XSS library is now part of the open source Web Protection Library:

    Microsoft Web Protection Library

    Also, OWASP is a good resource for security information, and they have an Enterprise Security API project (ESAPI) that is available (to varying degrees) in various programming languages. The .NET one is not complete yet, I believe.

    OWASP Enterprise Security API

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm coming from a Ruby on Rails environment and I'm really spoiled with Active
Having been spoiled by ruby for so long, I now find myself having to
Spoiler: It was an outdated version of the rspec-rails gem! I encountered this error
I've been spoiled by C# with the Foreach. Is there something like this for
Coming from an extremely spoiled family upbringing (turbo pascal, python, ruby) I'm a bit
I've been spoiled by .NET development and this is driving me NUTS . I
I have a simple ruby on rails project that I'm trying to use a
I know this has a really simple explanation, but I've been spoiled by not
I know GitHub has spoiled me, but shouldn't this be easy? I'm not able
Super-beginner easy points ruby question. I'm trying to learn some ruby by programming the

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.