Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP General > why use htmlencode

Reply
Thread Tools

why use htmlencode

 
 
diablo
Guest
Posts: n/a
 
      07-07-2005
Hi

I have a website where people can enter comments into a textarea - some of
these may have a bit of html - like links - or <blockquote>

the comments are stored in a Access2000 mdb file - A friend told me that i
have to use htmlencode on the textarea string before storing it in the
database. but it seems to work fine without doing this - is there any reason
as to why i should put it thru htmlencode?

when the comments are displayed they are written straight into a <div>

<div><%=recset.fields("comments")%></div>

thanks in advance

Diablo



 
Reply With Quote
 
 
 
 
Aaron Bertrand [SQL Server MVP]
Guest
Posts: n/a
 
      07-07-2005
No, IMHO you should use HTMLEncode when placing it INTO the textarea (e.g.
for edit) and when displaying if you don't want any of the HTML to actually
render as intended. Again, IMHO, it should be stored as entered, and only
converted when displaying. I'd be curious about your friend's reason(s)
about having to store it in HTMLEncoded format.




"diablo" <(E-Mail Removed)> wrote in message
news:cGeze.2080$(E-Mail Removed)...
> Hi
>
> I have a website where people can enter comments into a textarea - some of
> these may have a bit of html - like links - or <blockquote>
>
> the comments are stored in a Access2000 mdb file - A friend told me that i
> have to use htmlencode on the textarea string before storing it in the
> database. but it seems to work fine without doing this - is there any
> reason
> as to why i should put it thru htmlencode?
>
> when the comments are displayed they are written straight into a <div>
>
> <div><%=recset.fields("comments")%></div>
>
> thanks in advance
>
> Diablo
>
>
>



 
Reply With Quote
 
 
 
 
diablo
Guest
Posts: n/a
 
      07-07-2005

> when displaying if you don't want any of the HTML to actually
> render as intended. Again, IMHO, it should be stored as entered,


I am a simple soul and may have misinterpreted my friends advice - but what
you are saying is that, ignoring the case of editing, I do not need to use
htmlencode?

I found this tip

http://www.devx.com/tips/Tip/13459

but i guess i can ignore it since if i store raw html in the db then i wont
have

&amp;

type characters in my DB.

Is my thinking correct?


> and only
> converted when displaying.


Here you mean displaying for editing not for rendering dont you?

TIA

D



 
Reply With Quote
 
Aaron Bertrand [SQL Server MVP]
Guest
Posts: n/a
 
      07-07-2005
> if i store raw html in the db then i wont have
>
> &amp;
>
> type characters in my DB.


Correct. It will just be &

> > and only
> > converted when displaying.

>
> Here you mean displaying for editing not for rendering dont you?


No, I meant what I said. You trimmed some of it, but it *needs* to be
converted before being inserted into a textarea for editing. How you want
to handle rendering is up to you.

Do you want <a href=foo>link</a> to look exactly as it does in this message?
Then HTMLEncode it.

Do you want <a href=foo>link</a> to work as an active link when rendered?
Then do not HTMLEncode it.


 
Reply With Quote
 
diablo
Guest
Posts: n/a
 
      07-08-2005

> No, I meant what I said. You trimmed some of it, but it *needs* to be
> converted before being inserted into a textarea for editing. How you want
> to handle rendering is up to you.
>
> Do you want <a href=foo>link</a> to look exactly as it does in this

message?
> Then HTMLEncode it.
>
> Do you want <a href=foo>link</a> to work as an active link when rendered?
> Then do not HTMLEncode it.
>

Ah... penny has dropped.

Thanks for your help

D


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
findcontrol("PlaceHolderPrice") why why why why why why why why why why why Mr. SweatyFinger ASP .Net 2 12-02-2006 03:46 PM
use of htmlencode with access database diablo HTML 0 06-26-2005 12:35 PM
Why HtmlEncode NavigateUrl, ImageUrl: missing some point?? Versteijn ASP .Net 0 10-23-2004 10:26 AM
Always use Server.HTMLEncode? Hraklhs ASP General 0 01-07-2004 10:08 AM
How to use Server.HtmlEncode in DataGrid Bind Makarand ASP .Net 0 11-06-2003 09:22 AM



Advertisments