Monday 24 January 2011

Escaping and Unescaping XML Literals

XML encoding is necessary if you have to save XML text in an XML document. If you don't escape special chars the XML to insert will become a part of the original XML DOM and not a value of a node.


Escaping the XML means basically replacing 5 chars with new values.


These replacements are:

<

->

& lt;

>

->

& gt;

"

->

& quot;

'

->

& apos;

&

->

& amp;

Here are 4 ways you can encode XML in C#:


1. String.Replace() 5 times

This is ugly but it works. Note that Replace("&", "&") has to be the first replace so we don't replace other already escaped &.

string xml = "it's my \"node\" & i like it";

encodedXml = xml.Replace("&", "&").Replace("<", "<").Replace(">", ">").Replace("\"", """).Replace("'", "'");


2. System.Web.HttpUtility.HtmlEncode()

Used for encoding HTML, but HTML is a form of XML so we can use that too. Mostly used in ASP.NET apps. Note that HtmlEncode does NOT encode apostrophes ( ' ).

string xml = "it's my \"node\" & i like it";

string encodedXml = HttpUtility.HtmlEncode(xml);

// RESULT: <node>it's my "node" & i like it<node>


3. System.Security.SecurityElement.Escape()

In Windows Forms or Console apps I use this method. If nothing else it saves me including the System.Web reference in my projects and it encodes all 5 chars.


string xml = "it's my \"node\" & i like it";

string encodedXml = System.Security.SecurityElement.Escape(xml);


4. System.Xml.XmlTextWriter

Using XmlTextWriter you don't have to worry about escaping anything since it escapes the chars where needed. For example in the attributes it doesn't escape apostrophes, while in node values it doesn't escape apostrophes and qoutes.

string xml = "it's my \"node\" & i like it";

using (XmlTextWriter xtw = new XmlTextWriter(@"c:\xmlTest.xml", Encoding.Unicode))

{

xtw.WriteStartElement("xmlEncodeTest");

xtw.WriteAttributeString("testAttribute", xml);

xtw.WriteString(xml);

xtw.WriteEndElement();

}

5. Using Switch Case

public string XmlEncode(string nonXmlText)

{

StringBuilder builder = new StringBuilder();

Char[] originalChars = nonXmlText.ToCharArray();

for (int i = 0; i <>

{

switch ((byte)originalChars[i])

{

case 34:

case 38:

case 39:

case 60:

case 61:

case 62:

builder.Append("&#");

builder.Append(originalChars[i]);

builder.Append(";");

break;

default:

builder.Append(originalChars[i]);

break;

}

}

return builder.ToString();

}


Unescaping XML characters:

public static string UnescapeXml(string xmlString)

{

if (xmlString.Length > 0)

{

xmlString = xmlString.Replace("<", "<");

xmlString = xmlString.Replace(">", ">");

xmlString = xmlString.Replace("&", "&");

xmlString = xmlString.Replace(""", "\"");

xmlString = xmlString.Replace("'", "’");

xmlString = xmlString.Replace("'", "’");

}

return xmlString;

}