Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
G
gs1-office-web-sit
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
吴迪
gs1-office-web-sit
Commits
4bdc9d85
Commit
4bdc9d85
authored
Nov 06, 2022
by
吴迪
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
【修改】bug修改
parent
0c31b453
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
2 additions
and
2 deletions
+2
-2
SQLFilter.java
src/main/java/io/office/common/xss/SQLFilter.java
+1
-1
MedicalController.java
...o/office/modules/manage/controller/MedicalController.java
+1
-1
No files found.
src/main/java/io/office/common/xss/SQLFilter.java
View file @
4bdc9d85
...
@@ -36,7 +36,7 @@ public class SQLFilter {
...
@@ -36,7 +36,7 @@ public class SQLFilter {
str
=
str
.
toLowerCase
();
str
=
str
.
toLowerCase
();
//非法字符
//非法字符
String
[]
keywords
=
{
"master"
,
"truncate"
,
"insert"
,
"select"
,
"delete"
,
"
update"
,
"
declare"
,
"alter"
,
"drop"
};
String
[]
keywords
=
{
"master"
,
"truncate"
,
"insert"
,
"select"
,
"delete"
,
"declare"
,
"alter"
,
"drop"
};
//判断是否包含非法字符
//判断是否包含非法字符
for
(
String
keyword
:
keywords
){
for
(
String
keyword
:
keywords
){
...
...
src/main/java/io/office/modules/manage/controller/MedicalController.java
View file @
4bdc9d85
...
@@ -137,7 +137,7 @@ public class MedicalController extends AbstractController {
...
@@ -137,7 +137,7 @@ public class MedicalController extends AbstractController {
@PostMapping
(
"/api/getList10ByType"
)
@PostMapping
(
"/api/getList10ByType"
)
public
R
getList10ByType
(
@RequestBody
MedicalEntity
medical
)
{
public
R
getList10ByType
(
@RequestBody
MedicalEntity
medical
)
{
QueryWrapper
<
MedicalEntity
>
queryWrapper
=
new
QueryWrapper
<>();
QueryWrapper
<
MedicalEntity
>
queryWrapper
=
new
QueryWrapper
<>();
queryWrapper
.
select
(
"top
10
id,title "
);
queryWrapper
.
select
(
"top
7
id,title "
);
queryWrapper
.
gt
(
"level"
,
"0"
);
queryWrapper
.
gt
(
"level"
,
"0"
);
queryWrapper
.
eq
(
"status"
,
"1"
);
queryWrapper
.
eq
(
"status"
,
"1"
);
queryWrapper
.
orderByDesc
(
"level"
);
queryWrapper
.
orderByDesc
(
"level"
);
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment