I have a web app based on MVC3 (no beta or release candidate, RTM/RTW version) that has an action that accepts XML files for processing.

Of course, this seems evil to MVC because of possible attacks, so it doesn't allow it. Well, I try to put either AllowHtml on the model object as such:

   public class XMLModel
    {
        [AllowHtml]
        public string msg { get; set; }
    }

Or I set ValidateInput to false on my action method such as this:

    [ValidateInput(false)]
    public ActionResult AddCDR(XMLModel model)
    {
    }

The reason for having a "strongly" typed model in the first place was that I originally tried to have a string value named "msg" as the action method parameter, but that always came back empty.

Now, when someone posts to this form, either on the same machine or from a networked computer, the msg field is always blank.

I have verified with WireShark that the data is actually in the request.

Now, one interesting thing. This should not be necessary with MVC 3. Yet it makes a slight difference.

If I add this to my web config:

<httpRuntime requestValidationMode="2.0" />

It works for requests originating from the local computer, but it does NOT work from another system.

I think the AllowHtml version seems elegant - if only it worked.

I have also found out about a bug in RC2 - again, this should not affect me, but I tried to add the following in Application_Start() anyway:

ModelMetadataProviders.Current = new DataAnnotationsModelMetadataProvider();

As expected, it makes no real difference.

Everything works as expected on my development computer (Win7x64, VS2010), but on the target system (Win2008R2x64, IIS7.5) the above problems are giving me a hard time.

Very important point to note: If I post t

Edit
Report