前端 对中文用函数escape()
function w_cx_bnt_qd() {
if (!check()) {
return;
}
s_jf = $("#w_cx_jf").val();
s_yf = $("#w_cx_yf").val();
s_htbh = $("#w_cx_htbh").val();
s_htje = $("#w_cx_htje").val();
s_bmdm = $("#w_cx_bmdm").find("option:selected").val();
s_nf = $("#w_cx_nf").find("option:selected").val();
s_jbr = $("#w_cx_jbr").val();
s = "cx_load1.aspx?s_jf=" + escape(s_jf);
s += "&s_yf=" + escape(s_yf);
s += "&s_htbh=" + s_htbh;
s += "&s_htje=" + s_htje;
s += "&s_bmdm=" + s_bmdm;
s += "&s_jbr=" + escape(s_jbr);
s += "&s_nf=" + s_nf;
$.get(s, function (data, status, xhr) {
var aa = $.parseJSON(data); //将JSON文本格式转成对象
var rec = new CRec(aa); //创建JSON类对象
var tb = "";
var s = "";
var ss = "";
var pdf = "";
var idh = "";
后端 用 Server.HtmlEncode();
string jf,yf,htbh,htje,s,s1;
string bmdm, jbr,nf;
jf = Request.Params["s_jf"].ToString();
yf = Request.Params["s_yf"].ToString();
htbh = Request.Params["s_htbh"].ToString();
htje = Request.Params["s_htje"].ToString();
bmdm = Request.Params["s_bmdm"].ToString();
jbr = Request.Params["s_jbr"].ToString();
nf = Request.Params["s_nf"].ToString();
jbr = Server.HtmlEncode(jbr);
jf = Server.HtmlEncode(jf);
yf = Server.HtmlEncode(yf);