Force JSF to process, validate and update readonly/disabled input components anyway
Solution 1:
That's the effect of JSF's safeguard against tampered/attacked requests wherein the hacker attempts to circumvent the readonly
(and disabled
) attribute by manipulating the HTML DOM and/or the HTTP request.
Instead of
<x:inputXxx ... readonly="true">
use
<x:inputXxx ... readonly="#{facesContext.currentPhaseId.ordinal eq 6}">
or
<x:inputXxx ... readonly="#{not facesContext.postback or facesContext.renderResponse}">
This makes sure that readonly
is only effective during render response phase and not during all other JSF phases. So, when JSF is about to decode the input component during the apply request values phase, it will consider readonly="false"
this way.
See also:
- other uses of
#{facesContext.currentPhaseId.ordinal}
Solution 2:
The key codes for the top row of numbers are 48-57 so you could write a function to disable keypress on those characters.
Something like this
function disableEnter(event) {
var charCode = (event.which) ? event.which : event.keyCode;
if (charCode > 31 && (charCode > 47 || charCode < 58)) {
return false;}
} else return true;
}
<h:inputText onkeypress="return disableEnter(event);" />