WRequest.cs 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Text;
  4. using System.Web;
  5. namespace CP.Common
  6. {
  7. public class WRequest
  8. {
  9. /// <summary>
  10. /// 过滤请求中可能存在的xxs漏洞..
  11. /// </summary>
  12. /// <param name="str"></param>
  13. /// <returns></returns>
  14. private static string GetXXString(string str)
  15. {
  16. if (string.IsNullOrEmpty(str))
  17. return "";
  18. string xxs = "--|javascript:|onkey|onchange|onfocus|onblur|onclick|select|update|delete|write|document|alert|script|.wma|.rm|.meta|param|iframe|.swf|.wmv|.asx|.mp3|.mp2|.avi|http-equiv|refresh|.css|position|absolute|z-index|window|cookie";
  19. string[] strs = xxs.Split('|');
  20. if (strs != null && strs.Length > 0)
  21. {
  22. for (int i = 0; i < strs.Length; i++)
  23. {
  24. if (str.IndexOf(strs[i], StringComparison.CurrentCultureIgnoreCase) != -1)
  25. str = str.Replace(strs[i], "");
  26. }
  27. }
  28. return str;
  29. }
  30. /// <summary>
  31. /// 根据request.url获取其中的某个参数
  32. /// </summary>
  33. /// <param name="key"></param>
  34. /// <returns></returns>
  35. private static string GetQueryUrlParam(string key)
  36. {
  37. if (System.Web.HttpContext.Current != null)
  38. {
  39. string query = HttpContext.Current.Request.Url.Query;
  40. if (!string.IsNullOrEmpty(query))
  41. {
  42. int index = 0;
  43. index = query.IndexOf(key + "=");
  44. if (index >= 0)
  45. {
  46. query = query.Substring(key.Length + 1 + index);
  47. index = query.IndexOf('&');
  48. if (index >= 0)
  49. query = query.Substring(0, index);
  50. return query;
  51. }
  52. }
  53. }
  54. return string.Empty;
  55. }
  56. /// <summary>
  57. /// 判断当前页面是否接收到了Post请求
  58. /// </summary>
  59. /// <returns>是否接收到了Post请求</returns>
  60. public static bool IsPost()
  61. {
  62. return HttpContext.Current.Request.HttpMethod.Equals("POST");
  63. }
  64. /// <summary>
  65. /// 判断当前页面是否接收到了Get请求
  66. /// </summary>
  67. /// <returns>是否接收到了Get请求</returns>
  68. public static bool IsGet()
  69. {
  70. return HttpContext.Current.Request.HttpMethod.Equals("GET");
  71. }
  72. /// <summary>
  73. /// 返回指定的服务器变量信息
  74. /// </summary>
  75. /// <param name="strName">服务器变量名</param>
  76. /// <returns>服务器变量信息</returns>
  77. public static string GetServerString(string strName)
  78. {
  79. if (HttpContext.Current.Request.ServerVariables[strName] == null)
  80. return "";
  81. return HttpContext.Current.Request.ServerVariables[strName].ToString();
  82. }
  83. /// <summary>
  84. /// 是否是站内请求.
  85. /// </summary>
  86. /// <returns></returns>
  87. public static bool IsLocationRequest()
  88. {
  89. string truehost = "8200.cn";
  90. Uri referrer = HttpContext.Current.Request.UrlReferrer;
  91. if (referrer != null && !string.IsNullOrEmpty(referrer.ToString()))
  92. {
  93. string rhost = referrer.Host;
  94. //string host = HttpContext.Current.Request.Url.Host;
  95. //验证主机头是否一样
  96. if (rhost.IndexOf(truehost, StringComparison.CurrentCultureIgnoreCase) == -1)
  97. return false;
  98. }
  99. else
  100. {
  101. return false;
  102. }
  103. return true;
  104. }
  105. /// <summary>
  106. /// 返回上一个页面的地址
  107. /// </summary>
  108. /// <returns>上一个页面的地址</returns>
  109. public static string GetUrlReferrer()
  110. {
  111. string retVal = string.Empty;
  112. try
  113. {
  114. retVal = HttpContext.Current.Request.UrlReferrer.ToString();
  115. }
  116. catch { }
  117. if (retVal == null)
  118. return "";
  119. return retVal;
  120. }
  121. /// <summary>
  122. /// 得到当前完整主机头
  123. /// </summary>
  124. /// <returns></returns>
  125. public static string GetCurrentFullHost()
  126. {
  127. HttpRequest request = System.Web.HttpContext.Current.Request;
  128. if (!request.Url.IsDefaultPort)
  129. return string.Format("{0}:{1}", request.Url.Host, request.Url.Port.ToString());
  130. return request.Url.Host;
  131. }
  132. /// <summary>
  133. /// 得到主机头
  134. /// </summary>
  135. /// <returns></returns>
  136. public static string GetHost()
  137. {
  138. return HttpContext.Current.Request.Url.Host;
  139. }
  140. /// <summary>
  141. /// 端口号
  142. /// </summary>
  143. /// <returns></returns>
  144. public static string GetPort()
  145. {
  146. return HttpContext.Current.Request.Url.Port.ToString();
  147. }
  148. /// <summary>
  149. /// 获取当前请求的原始 URL(URL 中域信息之后的部分,包括查询字符串(如果存在))
  150. /// </summary>
  151. /// <returns>原始 URL</returns>
  152. public static string GetRawUrl()
  153. {
  154. return HttpContext.Current.Request.RawUrl;
  155. }
  156. /// <summary>
  157. /// 判断当前访问是否来自浏览器软件
  158. /// </summary>
  159. /// <returns>当前访问是否来自浏览器软件</returns>
  160. public static bool IsBrowserGet()
  161. {
  162. string[] BrowserName = { "ie", "opera", "netscape", "mozilla", "konqueror", "firefox" };
  163. string curBrowser = HttpContext.Current.Request.Browser.Type.ToLower();
  164. for (int i = 0; i < BrowserName.Length; i++)
  165. {
  166. if (curBrowser.IndexOf(BrowserName[i]) >= 0)
  167. return true;
  168. }
  169. return false;
  170. }
  171. /// <summary>
  172. /// 判断是否来自搜索引擎链接
  173. /// </summary>
  174. /// <returns>是否来自搜索引擎链接</returns>
  175. public static bool IsSearchEnginesGet()
  176. {
  177. if (HttpContext.Current.Request.UrlReferrer == null)
  178. return false;
  179. string[] SearchEngine = { "google", "yahoo", "msn", "baidu", "sogou", "sohu", "sina", "163", "lycos", "tom", "yisou", "iask", "soso", "gougou", "zhongsou", "yodao", "youdao", "360" };
  180. string tmpReferrer = HttpContext.Current.Request.UrlReferrer.ToString().ToLower();
  181. for (int i = 0; i < SearchEngine.Length; i++)
  182. {
  183. if (tmpReferrer.IndexOf(SearchEngine[i], StringComparison.CurrentCultureIgnoreCase) >= 0)
  184. return true;
  185. }
  186. return false;
  187. }
  188. /// <summary>
  189. /// 获得当前完整Url地址
  190. /// </summary>
  191. /// <returns>当前完整Url地址</returns>
  192. public static string GetUrl()
  193. {
  194. return HttpContext.Current.Request.Url.ToString();
  195. }
  196. /// <summary>
  197. /// 获得指定Url参数的值
  198. /// </summary>
  199. /// <param name="strName">Url参数</param>
  200. /// <returns>Url参数的值</returns>
  201. public static string GetQueryString(string strName)
  202. {
  203. return GetQueryString(strName, false);
  204. }
  205. /// <summary>
  206. /// 获得指定Url参数的值
  207. /// </summary>
  208. /// <param name="strName">Url参数</param>
  209. /// <param name="sqlSafeCheck">是否进行sql安全测试</param>
  210. /// <returns>Url参数的值</returns>
  211. public static string GetQueryString(string strName, bool SafeCheck)
  212. {
  213. if (HttpContext.Current.Request.QueryString[strName] == null)
  214. return "";
  215. if (SafeCheck && !Utils.IsSafeSqlString(HttpContext.Current.Request.QueryString[strName]))
  216. return "unsafe string";
  217. return GetXXString(HttpContext.Current.Request.QueryString[strName]);
  218. }
  219. /// <summary>
  220. /// 获得当前页面的名称
  221. /// </summary>
  222. /// <returns>当前页面的名称</returns>
  223. public static string GetPageName()
  224. {
  225. string[] urlArr = HttpContext.Current.Request.Url.AbsolutePath.Split('/');
  226. return urlArr[urlArr.Length - 1].ToLower();
  227. }
  228. /// <summary>
  229. /// 返回表单或Url参数的总个数
  230. /// </summary>
  231. /// <returns></returns>
  232. public static int GetParamCount()
  233. {
  234. return HttpContext.Current.Request.Form.Count + HttpContext.Current.Request.QueryString.Count;
  235. }
  236. /// <summary>
  237. /// 获得指定表单参数的值
  238. /// </summary>
  239. /// <param name="strName">表单参数</param>
  240. /// <returns>表单参数的值</returns>
  241. public static string GetFormString(string strName)
  242. {
  243. return GetFormString(strName, false);
  244. }
  245. /// <summary>
  246. /// 获得指定表单参数的值
  247. /// </summary>
  248. /// <param name="strName">表单参数</param>4
  249. /// <param name="sqlSafeCheck">是否进行SQL安全检查</param>
  250. /// <returns>表单参数的值</returns>
  251. public static string GetFormString(string strName, bool sqlSafeCheck)
  252. {
  253. if (HttpContext.Current.Request.Form[strName] == null)
  254. return "";
  255. if (sqlSafeCheck && !Utils.IsSafeSqlString(HttpContext.Current.Request.Form[strName]))
  256. return "unsafe string";
  257. return GetXXString(HttpContext.Current.Request.Form[strName]);
  258. }
  259. /// <summary>
  260. /// 获得Url或表单参数的值, 先判断Url参数是否为空字符串, 如为True则返回表单参数的值
  261. /// </summary>
  262. /// <param name="strName">参数</param>
  263. /// <returns>Url或表单参数的值</returns>
  264. public static string GetString(string strName)
  265. {
  266. return GetString(strName, false);
  267. }
  268. /// <summary>
  269. /// 获得Url或表单参数的值, 先判断Url参数是否为空字符串, 如为True则返回表单参数的值
  270. /// </summary>
  271. /// <param name="strName">参数</param>
  272. /// <param name="sqlSafeCheck">是否进行SQL安全检查</param>
  273. /// <returns>Url或表单参数的值</returns>
  274. public static string GetString(string strName, bool sqlSafeCheck)
  275. {
  276. if ("".Equals(GetQueryString(strName)))
  277. return GetFormString(strName, sqlSafeCheck);
  278. else
  279. return GetQueryString(strName, sqlSafeCheck);
  280. }
  281. /// <summary>
  282. /// 获得指定Url参数的int类型值
  283. /// </summary>
  284. /// <param name="strName">Url参数</param>
  285. /// <returns>Url参数的int类型值</returns>
  286. public static int GetQueryInt(string strName)
  287. {
  288. return Utils.StrToInt(HttpContext.Current.Request.QueryString[strName], 0);
  289. }
  290. /// <summary>
  291. /// 获得指定Url参数的int类型值
  292. /// </summary>
  293. /// <param name="strName">Url参数</param>
  294. /// <param name="defValue">缺省值</param>
  295. /// <returns>Url参数的int类型值</returns>
  296. public static int GetQueryInt(string strName, int defValue)
  297. {
  298. return Utils.StrToInt(HttpContext.Current.Request.QueryString[strName], defValue);
  299. }
  300. /// <summary>
  301. /// 获得指定表单参数的int类型值
  302. /// </summary>
  303. /// <param name="strName">表单参数</param>
  304. /// <param name="defValue">缺省值</param>
  305. /// <returns>表单参数的int类型值</returns>
  306. public static int GetFormInt(string strName, int defValue)
  307. {
  308. return Utils.StrToInt(HttpContext.Current.Request.Form[strName], defValue);
  309. }
  310. /// <summary>
  311. /// 获得指定Url或表单参数的int类型值, 先判断Url参数是否为缺省值, 如为True则返回表单参数的值
  312. /// </summary>
  313. /// <param name="strName">Url或表单参数</param>
  314. /// <param name="defValue">缺省值</param>
  315. /// <returns>Url或表单参数的int类型值</returns>
  316. public static int GetInt(string strName, int defValue)
  317. {
  318. if (GetQueryInt(strName, defValue) == defValue)
  319. return GetFormInt(strName, defValue);
  320. else
  321. return GetQueryInt(strName, defValue);
  322. }
  323. /// <summary>
  324. /// 获得指定Url参数的float类型值
  325. /// </summary>
  326. /// <param name="strName">Url参数</param>
  327. /// <param name="defValue">缺省值</param>
  328. /// <returns>Url参数的int类型值</returns>
  329. public static float GetQueryFloat(string strName, float defValue)
  330. {
  331. return Utils.StrToFloat(HttpContext.Current.Request.QueryString[strName], defValue);
  332. }
  333. /// <summary>
  334. /// 获得指定表单参数的float类型值
  335. /// </summary>
  336. /// <param name="strName">表单参数</param>
  337. /// <param name="defValue">缺省值</param>
  338. /// <returns>表单参数的float类型值</returns>
  339. public static float GetFormFloat(string strName, float defValue)
  340. {
  341. return Utils.StrToFloat(HttpContext.Current.Request.Form[strName], defValue);
  342. }
  343. /// <summary>
  344. /// 获得指定Url或表单参数的float类型值, 先判断Url参数是否为缺省值, 如为True则返回表单参数的值
  345. /// </summary>
  346. /// <param name="strName">Url或表单参数</param>
  347. /// <param name="defValue">缺省值</param>
  348. /// <returns>Url或表单参数的int类型值</returns>
  349. public static float GetFloat(string strName, float defValue)
  350. {
  351. if (GetQueryFloat(strName, defValue) == defValue)
  352. return GetFormFloat(strName, defValue);
  353. else
  354. return GetQueryFloat(strName, defValue);
  355. }
  356. /// <summary>
  357. /// 获得当前页面客户端的IP
  358. /// </summary>
  359. /// <returns>当前页面客户端的IP</returns>
  360. public static string GetIP()
  361. {
  362. string result = HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];
  363. if (string.IsNullOrEmpty(result))
  364. result = HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];
  365. if (string.IsNullOrEmpty(result))
  366. result = HttpContext.Current.Request.UserHostAddress;
  367. if (string.IsNullOrEmpty(result) || !Utils.IsIP(result))
  368. return "127.0.0.1";
  369. return result;
  370. }
  371. /// <summary>
  372. /// 获取浏览器类型
  373. /// </summary>
  374. /// <returns></returns>
  375. public static string GetBrowse()
  376. {
  377. string b = string.Empty;
  378. string ua = HttpContext.Current.Request.UserAgent.ToString().ToLower();
  379. if (ua.Contains("firefox"))
  380. {
  381. b = "firefox";
  382. }
  383. else if (ua.Contains("msie"))
  384. {
  385. b = "ie";
  386. }
  387. else if (ua.Contains("gecko") && !ua.Contains("firefox")&&!ua.Contains("safari"))
  388. {
  389. b = "ie11";
  390. }
  391. else if (ua.Contains("safari"))
  392. {
  393. b = "safari";
  394. }
  395. else if (ua.Contains("chrome"))
  396. {
  397. b = "chrome";
  398. }
  399. else
  400. {
  401. b = "unknow";
  402. }
  403. return b;
  404. }
  405. /// <summary>
  406. /// 保存用户上传的文件
  407. /// </summary>
  408. /// <param name="path">保存路径</param>
  409. public static void SaveRequestFile(string path)
  410. {
  411. if (HttpContext.Current.Request.Files.Count > 0)
  412. {
  413. HttpContext.Current.Request.Files[0].SaveAs(path);
  414. }
  415. }
  416. }
  417. }