6523df63f37ae09d1714978ef3fc35ed8d1babf8
API/CodeSamples/ApplyAntiXssToReportOutput.md
| ... | ... | @@ -0,0 +1,51 @@ |
| 1 | +#ApplyAntiXssToReportOutput |
|
| 2 | + |
|
| 3 | +[[_TOC_]] |
|
| 4 | + |
|
| 5 | +##About |
|
| 6 | + |
|
| 7 | +When this option is enabled, report headers, footers, and other free-form input areas that accept HTML will be encoded when sent to the server and displayed to the user. When disabled, the HTML will be interpreted as executable markup an any script tags will be run. Users would be able to design headers and footers with dynamic parts and interactivity with this disabled. |
|
| 8 | + |
|
| 9 | +**Default Value:** false |
|
| 10 | + |
|
| 11 | +##Global.asax (C♯) |
|
| 12 | + |
|
| 13 | +```csharp |
|
| 14 | +//main class: inherits DatabaseAdHocConfig or FileSystemAdHocConfig |
|
| 15 | +public class CustomAdHocConfig : Izenda.AdHoc.DatabaseAdHocConfig |
|
| 16 | +{ |
|
| 17 | + // Configure settings |
|
| 18 | + // Add custom settings after setting the license key and connection string by overriding the ConfigureSettings() method |
|
| 19 | + public static void InitializeReporting() { |
|
| 20 | + //Check to see if we've already initialized. |
|
| 21 | + if (HttpContext.Current.Session == null || HttpContext.Current.Session["ReportingInitialized"] != null) |
|
| 22 | + return; |
|
| 23 | + AdHocSettings.LicenseKey = "INSERT_LICENSE_KEY_HERE"; |
|
| 24 | + AdHocSettings.SqlServerConnectionString = "INSERT_CONNECTION_STRING_HERE"; |
|
| 25 | + Izenda.AdHoc.AdHocSettings.AdHocConfig = new CustomAdHocConfig(); |
|
| 26 | + AdHocSettings.ApplyAntiXssToReportOutput = true; //The relevant setting |
|
| 27 | + HttpContext.Current.Session["ReportingInitialized"] = true; |
|
| 28 | + } |
|
| 29 | +} |
|
| 30 | +``` |
|
| 31 | + |
|
| 32 | +##Global.asax (VB.NET) |
|
| 33 | + |
|
| 34 | +```visualbasic |
|
| 35 | +'main class: inherits DatabaseAdHocConfig or FileSystemAdHocConfig |
|
| 36 | +Public Class CustomAdHocConfig |
|
| 37 | + Inherits Izenda.AdHoc.DatabaseAdHocConfig |
|
| 38 | + |
|
| 39 | + Shared Sub InitializeReporting() |
|
| 40 | + 'Check to see if we've already initialized |
|
| 41 | + If HttpContext.Current.Session Is Nothing OrElse HttpContext.Current.Session("ReportingInitialized") IsNot Nothing Then |
|
| 42 | + Return |
|
| 43 | + 'Initialize System |
|
| 44 | + AdHocSettings.LicenseKey = "INSERT_LICENSE_KEY_HERE" |
|
| 45 | + AdHocSettings.SqlServerConnectionString = "INSERT_CONNECTION_STRING_HERE" |
|
| 46 | + Izenda.AdHoc.AdHocSettings.AdHocConfig = New CustomAdHocConfig() |
|
| 47 | + AdHocSettings.ApplyAntiXssToReportOutput = true; 'The relevant setting |
|
| 48 | + HttpContext.Current.Session("ReportingInitialized") = True |
|
| 49 | + End Sub |
|
| 50 | +End Class |
|
| 51 | +``` |
|
| ... | ... | \ No newline at end of file |