Solved

Restrict ASP.net vb.net QueryString Text to Only Numbers or Commas

Posted on 2013-12-28
6
376 Views
Last Modified: 2014-01-04
Hello,

I am working on a page that can allow multiple product id's seperated by commas  and retrieve from the query string.  I have the code working but now I need to update it so that it will not take querystring parameters other than commas or numbers.

Can anyone tell me how I can update this one line of code so it only allows numbers and commas and nothing else?

strSelect = "SELECT Name, ShortName, ShortDescription, ImageSmallPath, uid, DateModified FROM dbo.Products WHERE uid IN (" + Request.QueryString("id") + ");"

If a regular expression is needed please let me know what imports or any other stuff is needed for the code to work.  I am hoping to do in as few lines as possible.

Thanks in advance,
Shawn
0
Comment
Question by:smower
  • 3
  • 2
6 Comments
 
LVL 19

Expert Comment

by:mrwad99
Comment Utility
I wouldn't try and update the SQL; what I would do personally is store the result of Request.QueryString("id") in a separate string object, then call IsNumeric() on that to see if it really is numeric; if is isn't, redirect to some error page.
0
 
LVL 74

Expert Comment

by:käµfm³d 👽
Comment Utility
Do you understand how dangerous what you have shown is? Are you familiar with SQL Injection?
0
 

Author Comment

by:smower
Comment Utility
Thank you. Won't the isnumeric block the commas. The commas are separators. I am planning on passing a list of comma separated values in as the query parameter so that multiple products can be looked up.  So the query string would be something like

234,347,123,568

The previous database I used had a filter values function where you could say (filtervalues; "0123456789,")

That way only those values would get through and other characters would be stripped out. Wouldn't the isnumeric come out false because of the comma seperators?

Does anyone have an example to simulate this filter and function on the one line of code?

Thank you
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 19

Expert Comment

by:mrwad99
Comment Utility
Ah yes; in that case you will want to iterate each character in the string, seeing if it is either a comma or if IsNumeric() evaluates to true; you can pass each character to IsNumeric().  Here is some pseudo code:

For Each c As Char in strID
    ' Compare 'c' to comma and pass it to IsNumeric(); if either return false you have an invalid ID
Next

Open in new window

0
 

Accepted Solution

by:
smower earned 0 total points
Comment Utility
Thanks,

I actually discovered this simple solution which seems to be working.
I had to add this namespace to use a regular expression.

<%@ Import Namespace="System.Text.RegularExpressions" %>
strSelect = "SELECT Name, ShortName, ShortDescription, ImageSmallPath, uid, DateModified FROM dbo.Products WHERE uid IN (" + Regex.Replace(Request.QueryString("id"), "[^0-9\,]", "") + ");"

That seems to be working.
0
 

Author Closing Comment

by:smower
Comment Utility
In my testing it seems to work and seems to strip out unwanted characters.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Whatever be the reason, if you are working on web development side,  you will need day-today validation codes like email validation, date validation , IP address validation, phone validation on any of the edit page or say at the time of registration…
User art_snob (http://www.experts-exchange.com/M_6114203.html) encountered strange behavior of Android Web browser on his Mobile Web site. It took a while to find the true cause. It happens so, that the Android Web browser (at least up to OS ver. 2.…
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now