Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
F
finance-manage
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
finance-oa
finance-manage
Commits
52d48fa6
Commit
52d48fa6
authored
Jul 23, 2020
by
RuoYi
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
检查字符支持小数点&降级改成异常提醒
parent
df3ef54b
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
4 additions
and
3 deletions
+4
-3
ruoyi-common/src/main/java/com/ruoyi/common/utils/sql/SqlUtil.java
...mon/src/main/java/com/ruoyi/common/utils/sql/SqlUtil.java
+4
-3
No files found.
ruoyi-common/src/main/java/com/ruoyi/common/utils/sql/SqlUtil.java
View file @
52d48fa6
package
com.ruoyi.common.utils.sql
;
package
com.ruoyi.common.utils.sql
;
import
com.ruoyi.common.exception.BaseException
;
import
com.ruoyi.common.utils.StringUtils
;
import
com.ruoyi.common.utils.StringUtils
;
/**
/**
...
@@ -10,9 +11,9 @@ import com.ruoyi.common.utils.StringUtils;
...
@@ -10,9 +11,9 @@ import com.ruoyi.common.utils.StringUtils;
public
class
SqlUtil
public
class
SqlUtil
{
{
/**
/**
* 仅支持字母、数字、下划线、空格、逗号(支持多个字段排序)
* 仅支持字母、数字、下划线、空格、逗号
、小数点
(支持多个字段排序)
*/
*/
public
static
String
SQL_PATTERN
=
"[a-zA-Z0-9_\\ \\,]+"
;
public
static
String
SQL_PATTERN
=
"[a-zA-Z0-9_\\ \\,
\\.
]+"
;
/**
/**
* 检查字符,防止注入绕过
* 检查字符,防止注入绕过
...
@@ -21,7 +22,7 @@ public class SqlUtil
...
@@ -21,7 +22,7 @@ public class SqlUtil
{
{
if
(
StringUtils
.
isNotEmpty
(
value
)
&&
!
isValidOrderBySql
(
value
))
if
(
StringUtils
.
isNotEmpty
(
value
)
&&
!
isValidOrderBySql
(
value
))
{
{
return
StringUtils
.
EMPTY
;
throw
new
BaseException
(
"参数不符合规范,不能进行查询"
)
;
}
}
return
value
;
return
value
;
}
}
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment