Pervaxis.Genesis.Sanitization
3.4.4
dotnet add package Pervaxis.Genesis.Sanitization --version 3.4.4
NuGet\Install-Package Pervaxis.Genesis.Sanitization -Version 3.4.4
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Pervaxis.Genesis.Sanitization" Version="3.4.4" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Pervaxis.Genesis.Sanitization" Version="3.4.4" />
<PackageReference Include="Pervaxis.Genesis.Sanitization" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Pervaxis.Genesis.Sanitization --version 3.4.4
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Pervaxis.Genesis.Sanitization, 3.4.4"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Pervaxis.Genesis.Sanitization@3.4.4
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Pervaxis.Genesis.Sanitization&version=3.4.4
#tool nuget:?package=Pervaxis.Genesis.Sanitization&version=3.4.4
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Pervaxis.Genesis.Sanitization
Server-side input sanitization module for the Pervaxis Genesis platform. Prevents stored/reflected XSS at the service layer using whitelist-based HTML sanitization.
Features
- ISanitizer interface —
StripAll,SanitizeHtml, and profile-basedSanitizemethods - Three built-in profiles — PlainText, SafeHtml, Markdown
- Custom profiles — Define additional profiles via configuration
- [Sanitize] attribute — Declarative sanitization on DTO string properties at model binding time
- FluentValidation extensions —
.Sanitized()(transform) and.MustBeSanitized()(reject) - Global middleware — Optional auto-sanitization of POST/PUT/PATCH request bodies (off by default)
- Observability — Metrics (operations, threats detected, duration) and structured logging
Quick Start
// Program.cs
builder.Services.AddGenesisSanitization(builder.Configuration.GetSection("Genesis:Sanitization"));
app.UseGenesisSanitization();
// appsettings.json
{
"Genesis": {
"Sanitization": {
"DefaultProfile": "PlainText",
"AllowCustomProfiles": true,
"MaxInputLength": 1000000,
"EnableMiddleware": false
}
}
}
Usage
Explicit in service layer
public class CommentService
{
private readonly ISanitizer _sanitizer;
public async Task<Comment> CreateAsync(CreateCommentRequest request)
{
var safeContent = _sanitizer.SanitizeHtml(request.Body);
// ... store safeContent
}
}
Declarative on DTO
public record CreateCommentRequest
{
[Sanitize(Profile = "SafeHtml")]
public required string Body { get; init; }
}
FluentValidation
public class CreateCommentValidator : AbstractValidator<CreateCommentRequest>
{
public CreateCommentValidator(ISanitizer sanitizer)
{
RuleFor(x => x.Body)
.Sanitized(sanitizer, "SafeHtml")
.NotEmpty();
}
}
Implementation
Uses HtmlSanitizer (Ganss.Xss) — a mature, battle-tested .NET library with whitelist-based sanitization that handles edge cases including nested encoding, unicode tricks, and attribute injection.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- FluentValidation (>= 11.11.0)
- HtmlSanitizer (>= 8.1.870)
- Pervaxis.Genesis.Base (>= 3.4.4)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 3.4.4 | 132 | 6/8/2026 |