ravisilva
ravisilva

Reputation: 259

what does " <%: " do?

I have seen the following tag as an answer to a question:

<%: Model.FirstName %>

what does " <%: " do?

Upvotes: 7

Views: 1172

Answers (2)

Erwin
Erwin

Reputation: 4817

It html encodes the output of Firstname, this prevents encoding attacks like cross-side scripting (XSS).

Html encoded:

<%: Model.FirstName %>

Normal output:

<%= Model.FirstName %>

More info can by found at this blog post:

New <%: %> Syntax for HTML Encoding Output in ASP.NET 4 (and ASP.NET MVC 2)

Upvotes: 6

Related Questions