剑道 UI 上传器异步跨站点脚本与 ASP.NET 问题

本文关键字:脚本 ASP NET 问题 站点 UI 异步 剑道 | 更新日期: 2023-09-27 18:36:44

>我尝试在 ASP.NET 环境中以异步模式使用Kendo UI上传器,使用与该站点上的演示非常相似的代码,并且在IE8和Chrome 30.0.1599.101 m上都遇到了似乎是JQuery跨站点脚本错误



<!DOCTYPE html>
    <link href="css/kendostyles/kendo.common.min.css" rel="stylesheet" />
    <link href="css/kendostyles/kendo.default.min.css" rel="stylesheet" />
    <script src="scripts/kendojs/jquery.min.js"></script>
    <script src="scripts/kendojs/kendo.all.min.js"></script>

<div style="width:45%">
    <div style="width:45%">
        <div class="demo-section">
            <input name="files" id="files" type="file" />
        $(document).ready(function () {
                async: {
                    saveUrl: "save",
                    removeUrl: "remove",
                    autoUpload: true



public ActionResult Save(IEnumerable<HttpPostedFileBase> files)
    // The Name of the Upload component is "files"
    if (files != null)
        foreach (var file in files)
            // Some browsers send file names with full path.
            // We are only interested in the file name.
            var fileName = Path.GetFileName(file.FileName);
            var physicalPath = Path.Combine(Server.MapPath("~/Uploads"), fileName);
            // The files are not actually saved in this demo
            // file.SaveAs(physicalPath);
    // Return an empty string to signify success
    return View();


Error! Upload failed.Unexpected server response - see console.


Server response: Error trying to get server response: SecurityError: Blocked a frame with origin "http://localhost:21739" from accessing a frame with origin "null".  The frame requesting access has a protocol of "http", the frame being accessed has a protocol of "data". Protocols must match.

为了在搜索类似问题后解决问题,我尝试绕过更改 global.asax 文件的问题

protected void Application_BeginRequest(object sender, EventArgs e)
    HttpContext.Current.Response.AddHeader("Access-Control-Allow-Origin", "*");



剑道 UI 上传器异步跨站点脚本与 ASP.NET 问题


1)chrome对XSS问题很明确。除非 chrome 控制台显示跨站点脚本错误,否则我认为这不是您的问题。


            async: {
                saveUrl: "save",
                removeUrl: "remove",
                autoUpload: true
            error: onError
function onError(e){
alert("Failed to upload " + e.files.length + " files " + e.XMLHttpRequest.status + " " + e.XMLHttpRequest.responseText);


3)不确定您使用的是 Asp.net MVC还是Web Api控制器(看起来像 ASP.Net MVC),但是(也许我错了)您的保存属性似乎需要控制器或路由详细信息。

            async: {
                saveUrl: "MyControllerName/save", (or api/controller) ( or @Url.Action("Save", "ControllerName")
                removeUrl: "remove",
                autoUpload: true

4)返回KendoUI上传不会喜欢返回类型ActionResult它需要一个JsonResult返回类型。更正:不是100%确定这一点。请注意返回数据的结构。如果它是具有格式正确的 HTML 的字符串,则控件将吠叫