API/CodeSamples/ApplyAntiXssToReportOutput.md
... ...
@@ -0,0 +1,51 @@
1
+#ApplyAntiXssToReportOutput
2
+
3
+[[_TOC_]]
4
+
5
+##About
6
+
7
+When this option is enabled, report headers, footers, and other free-form input areas that accept HTML will be encoded when sent to the server and displayed to the user. When disabled, the HTML will be interpreted as executable markup an any script tags will be run. Users would be able to design headers and footers with dynamic parts and interactivity with this disabled.
8
+
9
+**Default Value:** false
10
+
11
+##Global.asax (C♯)
12
+
13
+```csharp
14
+//main class: inherits DatabaseAdHocConfig or FileSystemAdHocConfig
15
+public class CustomAdHocConfig : Izenda.AdHoc.DatabaseAdHocConfig
16
+{
17
+ // Configure settings
18
+ // Add custom settings after setting the license key and connection string by overriding the ConfigureSettings() method
19
+ public static void InitializeReporting() {
20
+ //Check to see if we've already initialized.
21
+ if (HttpContext.Current.Session == null || HttpContext.Current.Session["ReportingInitialized"] != null)
22
+ return;
23
+ AdHocSettings.LicenseKey = "INSERT_LICENSE_KEY_HERE";
24
+ AdHocSettings.SqlServerConnectionString = "INSERT_CONNECTION_STRING_HERE";
25
+ Izenda.AdHoc.AdHocSettings.AdHocConfig = new CustomAdHocConfig();
26
+ AdHocSettings.ApplyAntiXssToReportOutput = true; //The relevant setting
27
+ HttpContext.Current.Session["ReportingInitialized"] = true;
28
+ }
29
+}
30
+```
31
+
32
+##Global.asax (VB.NET)
33
+
34
+```visualbasic
35
+'main class: inherits DatabaseAdHocConfig or FileSystemAdHocConfig
36
+Public Class CustomAdHocConfig
37
+ Inherits Izenda.AdHoc.DatabaseAdHocConfig
38
+
39
+ Shared Sub InitializeReporting()
40
+ 'Check to see if we've already initialized
41
+ If HttpContext.Current.Session Is Nothing OrElse HttpContext.Current.Session("ReportingInitialized") IsNot Nothing Then
42
+ Return
43
+ 'Initialize System
44
+ AdHocSettings.LicenseKey = "INSERT_LICENSE_KEY_HERE"
45
+ AdHocSettings.SqlServerConnectionString = "INSERT_CONNECTION_STRING_HERE"
46
+ Izenda.AdHoc.AdHocSettings.AdHocConfig = New CustomAdHocConfig()
47
+ AdHocSettings.ApplyAntiXssToReportOutput = true; 'The relevant setting
48
+ HttpContext.Current.Session("ReportingInitialized") = True
49
+ End Sub
50
+End Class
51
+```
... ...
\ No newline at end of file