Get the App
SLTechnology News&Howtos  ›  Database  › 

Fuzzy query prevents sql injection

Shulou Source: shulou.com Published: 2022-06-01 09:38:31 09月14日 Update

Mysql mybatis environment:

1 >. Handle sql special characters {"*", "%", "_"}-- > with "/ *", "/%", "/ _"

2 >. Handle in sql, define'/'as escape character

Public abstract class BaseEntity extends PrimaryKeyObject {

Private static final long serialVersionUID = 1L

@ Transient / / is used to annotate the properties in the pojo object. The annotated properties will be transient and will not be persisted.

Does protected Boolean escapeChar; / / contain escape characters?

Protected String keyword; / / fuzzy query keyword

Public String getKeyword () {

Return keyword = = null? Null: keyword.trim ()

}

Public void setKeyword (String keyword) {

This.keyword = keyword = = null? Null: keyword.trim ()

}

Public Boolean getEscapeChar () {

This.getNewKeyword ()

Return escapeChar

}

Public void setEscapeChar (Boolean escapeChar) {

This.escapeChar = escapeChar

}

/ / replace sql special characters {"*", "%", "_"}-> with "/ *", "/%", "/ _"

Private void getNewKeyword () {

If (escapeChar = = null) {

EscapeChar = false

}

If (StringUtils.isNotEmpty (keyword) & &! escapeChar) {

Pattern p1 = Pattern.compile ("\ * |% | _")

Matcher M1 = p1.matcher (keyword)

StringBuffer buf = new StringBuffer ()

While (m1.find ()) {

M1.appendReplacement (buf, "/" + m1.group ())

}

M1.appendTail (buf)

String newkeyword = buf.toString ()

If (! keyword.equals (newkeyword)) {

This.setEscapeChar (true)

This.setKeyword (newkeyword)

}

}

}

}

And (

Name like CONCAT ("%", # {keyword}, "%") escape'/'

Or

Uname like CONCAT ("%", # {keyword}, "%") escape'/'

)

Tags: Character processing special attribute comment escape query key keyword object environment Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology MariaDB MySQL Shulou Tech Info vpn