Skip to content

online表单下拉选择,校验字段,字典Table 写上where条件后,在线测试没问题,生成代码后,出现sql注入问题 #1423

Closed
@xYang98

Description

@xYang98
版本号:2.2.0
问题描述:

online表单下拉选择,校验字段,
字典Table ->写上where条件后,例如:sys_user where sex = '1'
在线测试没问题,生成代码后,出现sql注入问题,换成#{sex},不知道在哪里传这个sex
(我图片中是另外一个sql)

截图&代码:

1
2
3

友情提示: 未按格式要求发帖,会直接删掉。

Activity

zhangdaiscott

zhangdaiscott commented on Jul 10, 2020

@zhangdaiscott
Member

待测试

1298191366

1298191366 commented on Jul 13, 2020

@1298191366
Contributor

@xYang98 新版本无查询条件

1298191366

1298191366 commented on Jul 16, 2020

@1298191366
Contributor

如果想代参查询,用这种格式
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

      Development

      No branches or pull requests

        Participants

        @zhangdaiscott@1298191366@xYang98

        Issue actions

          online表单下拉选择,校验字段,字典Table 写上where条件后,在线测试没问题,生成代码后,出现sql注入问题 · Issue #1423 · jeecgboot/JeecgBoot