|
@@ -16,6 +16,7 @@
|
|
package org.springblade.core.mp.support;
|
|
package org.springblade.core.mp.support;
|
|
|
|
|
|
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
|
|
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
|
|
|
|
+import org.springblade.core.tool.utils.DateUtil;
|
|
import org.springblade.core.tool.utils.Func;
|
|
import org.springblade.core.tool.utils.Func;
|
|
import org.springblade.core.tool.utils.StringPool;
|
|
import org.springblade.core.tool.utils.StringPool;
|
|
import org.springblade.core.tool.utils.StringUtil;
|
|
import org.springblade.core.tool.utils.StringUtil;
|
|
@@ -28,17 +29,23 @@ import java.util.Map;
|
|
* @author Chill
|
|
* @author Chill
|
|
*/
|
|
*/
|
|
public class SqlKeyword {
|
|
public class SqlKeyword {
|
|
- private final static String SQL_REGEX = "'|%|--|insert|delete|select|count|group|union|drop|truncate|alter|grant|execute|exec|xp_cmdshell|call|declare|sql";
|
|
|
|
|
|
+ private final static String SQL_REGEX = "'|%|--|insert|delete|select|sleep|count|group|union|drop|truncate|alter|grant|execute|exec|xp_cmdshell|call|declare|sql";
|
|
|
|
|
|
private static final String EQUAL = "_equal";
|
|
private static final String EQUAL = "_equal";
|
|
private static final String NOT_EQUAL = "_notequal";
|
|
private static final String NOT_EQUAL = "_notequal";
|
|
private static final String LIKE = "_like";
|
|
private static final String LIKE = "_like";
|
|
|
|
+ private static final String LIKE_LEFT = "_likeleft";
|
|
|
|
+ private static final String LIKE_RIGHT = "_likeright";
|
|
private static final String NOT_LIKE = "_notlike";
|
|
private static final String NOT_LIKE = "_notlike";
|
|
|
|
+ private static final String GE = "_ge";
|
|
|
|
+ private static final String LE = "_le";
|
|
private static final String GT = "_gt";
|
|
private static final String GT = "_gt";
|
|
private static final String LT = "_lt";
|
|
private static final String LT = "_lt";
|
|
|
|
+ private static final String DATE_GE = "_datege";
|
|
private static final String DATE_GT = "_dategt";
|
|
private static final String DATE_GT = "_dategt";
|
|
private static final String DATE_EQUAL = "_dateequal";
|
|
private static final String DATE_EQUAL = "_dateequal";
|
|
private static final String DATE_LT = "_datelt";
|
|
private static final String DATE_LT = "_datelt";
|
|
|
|
+ private static final String DATE_LE = "_datele";
|
|
private static final String IS_NULL = "_null";
|
|
private static final String IS_NULL = "_null";
|
|
private static final String NOT_NULL = "_notnull";
|
|
private static final String NOT_NULL = "_notnull";
|
|
private static final String IGNORE = "_ignore";
|
|
private static final String IGNORE = "_ignore";
|
|
@@ -57,22 +64,36 @@ public class SqlKeyword {
|
|
if (Func.hasEmpty(k, v) || k.endsWith(IGNORE)) {
|
|
if (Func.hasEmpty(k, v) || k.endsWith(IGNORE)) {
|
|
return;
|
|
return;
|
|
}
|
|
}
|
|
|
|
+ // 过滤sql注入关键词
|
|
|
|
+ k = filter(k);
|
|
if (k.endsWith(EQUAL)) {
|
|
if (k.endsWith(EQUAL)) {
|
|
qw.eq(getColumn(k, EQUAL), v);
|
|
qw.eq(getColumn(k, EQUAL), v);
|
|
} else if (k.endsWith(NOT_EQUAL)) {
|
|
} else if (k.endsWith(NOT_EQUAL)) {
|
|
qw.ne(getColumn(k, NOT_EQUAL), v);
|
|
qw.ne(getColumn(k, NOT_EQUAL), v);
|
|
|
|
+ } else if (k.endsWith(LIKE_LEFT)) {
|
|
|
|
+ qw.likeLeft(getColumn(k, LIKE_LEFT), v);
|
|
|
|
+ } else if (k.endsWith(LIKE_RIGHT)) {
|
|
|
|
+ qw.likeRight(getColumn(k, LIKE_RIGHT), v);
|
|
} else if (k.endsWith(NOT_LIKE)) {
|
|
} else if (k.endsWith(NOT_LIKE)) {
|
|
qw.notLike(getColumn(k, NOT_LIKE), v);
|
|
qw.notLike(getColumn(k, NOT_LIKE), v);
|
|
|
|
+ } else if (k.endsWith(GE)) {
|
|
|
|
+ qw.ge(getColumn(k, GE), v);
|
|
|
|
+ } else if (k.endsWith(LE)) {
|
|
|
|
+ qw.le(getColumn(k, LE), v);
|
|
} else if (k.endsWith(GT)) {
|
|
} else if (k.endsWith(GT)) {
|
|
qw.gt(getColumn(k, GT), v);
|
|
qw.gt(getColumn(k, GT), v);
|
|
} else if (k.endsWith(LT)) {
|
|
} else if (k.endsWith(LT)) {
|
|
qw.lt(getColumn(k, LT), v);
|
|
qw.lt(getColumn(k, LT), v);
|
|
|
|
+ } else if (k.endsWith(DATE_GE)) {
|
|
|
|
+ qw.ge(getColumn(k, DATE_GE), DateUtil.parse(String.valueOf(v), DateUtil.PATTERN_DATETIME));
|
|
} else if (k.endsWith(DATE_GT)) {
|
|
} else if (k.endsWith(DATE_GT)) {
|
|
- qw.gt(getColumn(k, DATE_GT), v);
|
|
|
|
|
|
+ qw.gt(getColumn(k, DATE_GT), DateUtil.parse(String.valueOf(v), DateUtil.PATTERN_DATETIME));
|
|
} else if (k.endsWith(DATE_EQUAL)) {
|
|
} else if (k.endsWith(DATE_EQUAL)) {
|
|
- qw.eq(getColumn(k, DATE_EQUAL), v);
|
|
|
|
|
|
+ qw.eq(getColumn(k, DATE_EQUAL), DateUtil.parse(String.valueOf(v), DateUtil.PATTERN_DATETIME));
|
|
|
|
+ } else if (k.endsWith(DATE_LE)) {
|
|
|
|
+ qw.le(getColumn(k, DATE_LE), DateUtil.parse(String.valueOf(v), DateUtil.PATTERN_DATETIME));
|
|
} else if (k.endsWith(DATE_LT)) {
|
|
} else if (k.endsWith(DATE_LT)) {
|
|
- qw.lt(getColumn(k, DATE_LT), v);
|
|
|
|
|
|
+ qw.lt(getColumn(k, DATE_LT), DateUtil.parse(String.valueOf(v), DateUtil.PATTERN_DATETIME));
|
|
} else if (k.endsWith(IS_NULL)) {
|
|
} else if (k.endsWith(IS_NULL)) {
|
|
qw.isNull(getColumn(k, IS_NULL));
|
|
qw.isNull(getColumn(k, IS_NULL));
|
|
} else if (k.endsWith(NOT_NULL)) {
|
|
} else if (k.endsWith(NOT_NULL)) {
|
|
@@ -106,5 +127,4 @@ public class SqlKeyword {
|
|
}
|
|
}
|
|
return param.replaceAll("(?i)" + SQL_REGEX, StringPool.EMPTY);
|
|
return param.replaceAll("(?i)" + SQL_REGEX, StringPool.EMPTY);
|
|
}
|
|
}
|
|
-
|
|
|
|
}
|
|
}
|