Check Content for Dangerous Substrings landing.repo.checkContent
Choose a tool for developing with an AI agent:
- use Alaio Vibecode to build an app for Bitrix24 from a task description without knowing any programming language. The agent writes the code and deploys the app to a server, with no manual hosting setup
- use the MCP server to develop a REST API integration in your own project. The agent refers to the official REST documentation
Scope:
landingWho can execute the method: user with View access permission in the Sites and Stores section
The method landing.repo.checkContent checks content through a sanitizer.
Method Parameters
Required parameters are marked with *
|
Name |
Description |
|
content* |
Content to be checked |
|
splitter |
A delimiter that marks dangerous fragments in Default: |
Code Examples
How to Use Examples in Documentation
Example of content checking, where:
content— HTML to be checkedsplitter— marker string for dangerous fragments
curl -X POST \
-H "Content-Type: application/json" \
-d '{
"content": "<div style=\"color:red\" onclick=\"alert(1)\"><iframe src=\"//evil.com\"></iframe></div>",
"splitter": "#AAA#"
}' \
"https://**put.your-domain-here**/rest/**user_id**/**webhook_code**/landing.repo.checkContent.json"
curl -X POST \
-H "Content-Type: application/json" \
-d '{
"content": "<div style=\"color:red\" onclick=\"alert(1)\"><iframe src=\"//evil.com\"></iframe></div>",
"splitter": "#AAA#",
"auth": "**put_access_token_here**"
}' \
"https://**put.your-domain-here**/rest/landing.repo.checkContent.json"
// This snippet is an ES module: top-level await requires type="module" or a bundler.
// $b24 is an already-initialized SDK instance (see the SDK "Get started" guide).
import { Text } from '@bitrix24/b24jssdk'
import type { B24Frame } from '@bitrix24/b24jssdk'
declare const $b24: B24Frame
// Shape of the payload returned in result (match the "response handling" section of the page)
type CheckContentResult = {
is_bad: boolean
content: string
}
try {
const response = await $b24.actions.v2.call.make<CheckContentResult>({
method: 'landing.repo.checkContent',
params: {
content: '<div style="color:red" onclick="alert(1)"><iframe src="//evil.com"></iframe></div>',
splitter: '#AAA#',
},
requestId: Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
} else {
const result = response.getData()!.result
console.info('Is bad content:', result.is_bad, '| Sanitized content:', result.content)
}
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
<!-- Load the SDK (UMD build); it is exposed as the global B24Js -->
<script src="https://unpkg.com/@bitrix24/b24jssdk@1/dist/umd/index.min.js"></script>
<script>
async function checkContent() {
try {
// Initialize the SDK inside a Bitrix24 frame
const $b24 = await B24Js.initializeB24Frame()
const response = await $b24.actions.v2.call.make({
method: 'landing.repo.checkContent',
params: {
content: '<div style="color:red" onclick="alert(1)"><iframe src="//evil.com"></iframe></div>',
splitter: '#AAA#',
},
requestId: B24Js.Text.getUuidRfc4122()
})
// The payload is available only on a successful response
if (!response.isSuccess) {
console.error(response.getErrorMessages().join('; '))
return
}
const result = response.getData().result
console.info('Is bad content:', result.is_bad, '| Sanitized content:', result.content)
} catch (error) {
// Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
console.error(error)
}
}
document.addEventListener('DOMContentLoaded', checkContent)
</script>
from b24pysdk.errors import BitrixAPIError, BitrixSDKException
try:
bitrix_response = client.landing.repo.check_content(
content='<div style="color:red" onclick="alert(1)"><iframe src="//evil.com"></iframe></div>',
splitter="#AAA#",
).response
result = bitrix_response.result
print(result)
except BitrixAPIError as error:
print(
"Bitrix API error",
f"error: {error.error}",
f"error_description: {error.error_description}",
sep="\n",
)
except BitrixSDKException as error:
print(f"Bitrix SDK error: {error.message}")
except Exception as error:
print(f"Unexpected error: {error}")
try {
$response = $b24Service
->core
->call(
'landing.repo.checkContent',
[
'content' => '<div style="color:red" onclick="alert(1)"><iframe src="//evil.com"></iframe></div>',
'splitter' => '#AAA#',
]
);
$result = $response
->getResponseData()
->getResult();
echo 'Success: ' . print_r($result, true);
} catch (Throwable $e) {
error_log($e->getMessage());
echo 'Error checking content: ' . $e->getMessage();
}
BX24.callMethod(
'landing.repo.checkContent',
{
content: '<div style="color:red" onclick="alert(1)"><iframe src="//evil.com"></iframe></div>',
splitter: '#AAA#'
},
function(result)
{
if (result.error())
{
console.error(result.error());
}
else
{
console.info(result.data());
}
}
);
require_once('crest.php');
$result = CRest::call(
'landing.repo.checkContent',
[
'content' => '<div style="color:red" onclick="alert(1)"><iframe src="//evil.com"></iframe></div>',
'splitter' => '#AAA#',
]
);
if (isset($result['error']))
{
echo 'Error: ' . $result['error_description'];
}
else
{
echo '<pre>';
print_r($result['result']);
echo '</pre>';
}
// client and ctx are already created — see the Go SDK section
res, err := client.Core().Call(ctx, "landing.repo.checkContent", b24.Params{
"content": "<div style=\"color:red\" onclick=\"alert(1)\"><iframe src=\"//evil.com\"></iframe></div>",
"splitter": "#AAA#",
})
if err != nil {
return fmt.Errorf("landing.repo.checkContent: %w", err)
}
var item struct {
IsBad bool `json:"is_bad"`
Content string `json:"content"`
}
if err := json.Unmarshal(res.Result, &item); err != nil {
return fmt.Errorf("parse response: %w", err)
}
fmt.Println(item.IsBad, item.Content)
Response Handling
HTTP Status: 200
{
"result": {
"is_bad": true,
"content": "\u003Cdiv style=\u0022color:red\u0022 oncl#AAA#ick=\u0022alert(1)\u0022\u003E\u003Cifr#AAA#ame src=\u0022\/\/evil.com\u0022\u003E\u003C\/iframe\u003E\u003C\/div\u003E"
},
"time": {
"start": 1774952664,
"finish": 1774952665.017161,
"duration": 1.0171608924865723,
"processing": 0,
"date_start": "2026-03-31T13:24:24+02:00",
"date_finish": "2026-03-31T13:24:25+02:00",
"operating_reset_at": 1774953265,
"operating": 0
}
}
Returned Data
|
Name |
Description |
|
result |
Result of the check more details |
|
time |
Information about the request execution time |
Type result
|
Name |
Description |
|
is_bad |
Indicator of dangerous fragments in the content |
|
content |
Content after being processed by the sanitizer |
Error Handling
HTTP Status: 400
{
"error": "ERROR_ARGUMENT",
"error_description": "The value of an argument 'content' has an invalid type",
"argument": "content"
}
{
"error": "ACCESS_DENIED",
"error_description": "Insufficient permissions."
}
|
Name |
Description |
|
error |
String error code. It consists of digits, Latin letters, and underscores. It may arrive empty — in that case only |
|
error_description |
Error message for the developer. Do not show it to the end user without processing |
Possible Error Codes
|
Code |
Description |
Value |
|
|
Not enough parameters for the call, missing: content |
Method call without |
|
|
The value of an argument 'content' has an invalid type |
Parameter |
|
|
Insufficient permissions |
User did not pass general access checks |
|
|
Token lacks sufficient scope |
Token does not contain |
Statuses and System Error Codes
HTTP Status: 4xx, 5xx
The errors described below are returned by the REST API itself, not by the logic of a specific method. They can arrive in response to any method.
|
Status |
Code |
Description |
|
|
|
An internal server error has occurred. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support |
|
|
|
The server returned an unexpected response. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support |
|
|
|
The request intensity limit has been exceeded |
|
|
|
The method is blocked because the request resource intensity limit has been exceeded. The block is lifted automatically once the accumulated execution time of the method no longer exceeds the limit |
|
|
|
The request contains no authorization data: neither an access token nor a webhook code was passed |
|
|
|
Methods are called over the HTTPS protocol only |
|
|
|
The REST API is blocked due to overload. This is a manual individual block. To have it lifted, contact Bitrix24 technical support |
|
|
|
REST API access is not active for this account. In Bitrix24 Cloud, check the current plan or trial status: Vibe+ plans include REST API access, while Essentials plans do not. A webhook receives a different error message — |
|
|
|
No active webhook with the specified user identifier and secret code was found |
|
|
|
No method with this name was found. The name is misspelled, the method does not exist in the REST API, or it is unavailable without the required scope |
|
|
|
The request requires broader permissions than the token has: for a webhook these are the permissions granted to it, for an application it is the scope. For an application, the error message ends with |
|
|
|
The access token has expired |
|
|
|
The application is installed, but the Bitrix24 administrator has granted access to it only to specific users |
|
|
|
The public part of the site is closed. To open it on an on-premise installation, disable the "Temporary closure of the public part of the site" option. Path to the setting: Desktop > Settings > Product Settings > Module Settings > Main Module > Temporary closure of the public part of the site |