File Download Tips for asp.net
use http header
protected void Page_Load(object sender, EventArgs e)
{
string format = Convert.ToString(ViewData["format"]);
Response.AddHeader("Content-Disposition", "attachment; filename=" + HttpUtility.UrlEncode("·ÑÓñ¨Ïú±í", Encoding.UTF8) + string.Format(".{0}",format));
//²âÊÔÖз¢ÏÖ£ºÈç¹ûÒªÏëÔÚIEÖÐÖ±½Ó´ò¿ªPDF£¬ÉÏÐдúÂ룬²»ÄÜÓУ¡£¡·ñÔò¼´Ê¹¿Í»§¶ËÓÐÉèÖã¬Ò²»áʹÓà Adobe Reader/Acrobat ´ò¿ª
Response.ContentType = string.Format("application/{0}",format);
Response.Charset = "GB2312";
Response.ContentEncoding = System.Text.Encoding.UTF8;
Response.BinaryWrite(ViewData.Model);
Response.Flush();
//prevent render html to client(critical)
Response.End();
request to doc directly
Response.Redirect(“http://localhost:2222/Docs/abc.doc”, true);
Tips:
ÖÁÓÚ¿Í»§¶ËʹÓÃä¯ÀÀÆ÷´ò¿ª(µ±È»±ØÐëÒªÏàÓ¦µÄä¯ÀÀÆ÷²å¼þÖ§³Ö)£¬»¹ÊÇÏàÓ¦µÄapplication (MS-Word,Adobe Reader),´ò¿ªÇ°ÊÇ·ñÌáʾÏÂÔØ£¬Server¶ËÊÇÎÞ·¨¿ØÖƵģ¬Õâ¸öºÍÓû§ÉèÖÃÓйØϵ¡£¼ûͼ
Ïà¹ØÎĵµ£º
Iframe±ê¼Ç£¬Óֽи¡¶¯Ö¡±ê¼Ç£¬Äã¿ÉÒÔÓÃËü½«Ò»¸öHTMLÎĵµÇ¶ÈëÔÚÒ»¸öHTMLÖÐÏÔʾ¡£Ëü²»Í¬ÓÚFrame±ê¼Ç×î´óµÄÌØÕ÷¼´Õâ¸ö±ê¼ÇËùÒýÓõÄHTMLÎļþ²»ÊÇÓëÁíÍâµÄHTMLÎļþÏ໥¶ÀÁ¢ÏÔʾ£¬¶øÊÇ¿ÉÒÔÖ±½ÓǶÈëÔÚÒ»¸öHTMLÎļþÖУ¬ÓëÕâ¸öHTMLÎļþÄÚÈÝÏ໥Èںϣ¬³ÉΪһ¸öÕûÌ壬ÁíÍ⣬»¹¿ÉÒÔ¶à´ÎÔÚÒ»¸öÒ³ÃæÄÚÏÔʾͬһÄÚÈÝ£¬¶ø²»±ØÖظ´Ð´ÄÚÈ ......
¾¹ý¶Ôasp.netµÄѧ£¬ÎÒ¾õµÃÔ½À´Ô½Á¦²»´ÓÐÄ°¡£¡ËµÊµ»°ÎÒÏÖÔÚ¶¼²»¸Ò˵×Ô¼ºÒѾÈëÃÅÁË£¡ÓÐʱºòÕæÏ룬ÎÒµ½µ×Êʺϲ»ÊʺÏѧÕâ¸ö£¬ÎÒ²¢²»ÊÇÓöµ½À§ÄѾÍÏëÌӱܣ¬Ö»ÊÇÎÒÕÒ²»µ½ºÏÊʵķ½·¨À´½â¾ö×Ô¼ºÓöµ½µÄÎÊÌâ¡£¶¼ËµÇ§ÄêÄ¥Ò»½££¬ÏÖÔÚ²ÅÕæÕýÈÏʶµ½£¬ÏëÒªµÃµ½µã¶ù¶«Î÷£¬Ã»Óе㸶³öºÍÎþÉüÊÇ¿ÉÄܵÄÊ£¡
&n ......
×öÏîÄ¿Ò²ÓÐÒ»¶Îʱ¼äÁË£¬ÔÚ³ÌÐòÖÐÒ²Óöµ½ºÜ¶à°²È«·½ÃæµÄÎÊÌâ¡£Ò²¸Ã×ܽáÒ»ÏÂÁË¡£Õâ¸öÏîÄ¿ÊÇÒ»¸ö CMS ϵͳ¡£ÏµÍ³ÊÇÓà ASP.NET ×öµÄ¡£¿ª·¢µÄʱºò·¢ÏÖ΢Èí×öÁ˺ܶలȫ´ëÊ©£¬Ö»ÊÇÓÐЩÐÂÊÖ³ÌÐòÔ±²»ÖªµÀÔõô¿ªÆô¡£ÏÂÃæÎÒͨ¹ý¼¸¸ö·½Ãæ¼òµ¥½éÉÜ£º
¡¡¡¡1£ºSQL ×¢Èë
¡¡¡¡2£ºXSS
¡¡¡¡3£ºCSRF
¡¡¡¡4£ºÎļþÉÏ´«
SQL ×¢Èë
¡¡¡¡Ò ......
HiddenField ¿Ø¼þÌṩÁËÒ»ÖÖÔÚÒ³ÃæÖд洢ÐÅÏ¢µ«²»ÏÔʾÐÅÏ¢µÄ·½·¨¡£ÀýÈ磬¿ÉÒÔÔÚ HiddenField ¿Ø¼þÖд洢Óû§Ê×Ñ¡ÏîÉèÖã¬ÒÔ±ã¿ÉÒÔÔÚ¿Í»§¶Ë½Å±¾ÖжÁÈ¡´ËÉèÖá£ÈôÒª½«ÐÅÏ¢·ÅÈë HiddenField ¿Ø¼þÖУ¬ÇëÔÚÁ½´Î»Ø·¢Ö®¼ä½«Æä Value ÊôÐÔÉèÖÃΪҪ´æ´¢µÄÖµ¡£
Ò»¡¢¹¦ÄÜ
¿ÉÒÔʹÓà HiddenFi ......
webconfigα¾²Ì¬
<system.web>
<httpHandlers>
<add verb="*" path="*.aspx" type="URLRewriter.RewriterFactoryHandler, URLRewriter"/>
<add verb="*" path="*.html" type="URLRewriter.RewriterFactoryHandler, URLRewriter"/>
</httpHandlers>
</system.web>
......