razor-localization
GitHub提供Razor视图中参数化本地化字符串的最佳实践,指导根据是否含HTML选择StringLocalizer或ViewLocalizer,并强调动态参数的Html.Encode安全编码。
Trigger Scenarios
Install
npx skills add btcpayserver/btcpayserver --skill razor-localization -g -y
SKILL.md
Frontmatter
{
"name": "razor-localization",
"description": "Use when editing or reviewing Razor `.cshtml` files containing parameterized localized strings. Choose StringLocalizer for plain text and safely encode ViewLocalizer parameters when localized strings contain HTML."
}
Razor Localization
Apply these rules to parameterized localizable strings in Razor views.
Plain Text
Use StringLocalizer when the localized string does not contain HTML. Razor encodes the resulting localized string when rendering it.
@StringLocalizer["{0} has been invited as {1}.", Model.Email, Model.Role]
Do not use ViewLocalizer merely because a string has parameters.
HTML
Use ViewLocalizer only when the localized string intentionally contains HTML. Encode every dynamic parameter with Html.Encode before passing it to ViewLocalizer.
@ViewLocalizer["You have been invited to join <strong>{0}</strong> as {1}.",
Html.Encode(Model.StoreName), Html.Encode(Model.Role)]
Never pass user-controlled or otherwise dynamic strings directly to ViewLocalizer:
@* Unsafe *@
@ViewLocalizer["Welcome to <strong>{0}</strong>.", Model.StoreName]
Generated HTML values such as Html.ActionLink(...) are intentional HTML and should not be encoded.
Review Checklist
- Use
StringLocalizerfor parameterized strings without HTML. - Use
ViewLocalizeronly when the localized resource contains intentional HTML. - Wrap every dynamic
ViewLocalizerparameter inHtml.Encode(...). - Do not encode intentional HTML values returned by HTML helpers.
- Check every added or modified
ViewLocalizercall before completing a Razor change.
Version History
- a305e95 Current 2026-09-23 02:15


