Fuzzy query prevents sql injection
Mysql mybatis environment:
1 >. Handle sql special characters {"*", "%", "_"}-- > with "/ *", "/%", "/ _"
2 >. Handle in sql, define'/'as escape character
Public abstract class BaseEntity extends PrimaryKeyObject {
Private static final long serialVersionUID = 1L
@ Transient / / is used to annotate the properties in the pojo object. The annotated properties will be transient and will not be persisted.
Does protected Boolean escapeChar; / / contain escape characters?
Protected String keyword; / / fuzzy query keyword
Public String getKeyword () {
Return keyword = = null? Null: keyword.trim ()
}
Public void setKeyword (String keyword) {
This.keyword = keyword = = null? Null: keyword.trim ()
}
Public Boolean getEscapeChar () {
This.getNewKeyword ()
Return escapeChar
}
Public void setEscapeChar (Boolean escapeChar) {
This.escapeChar = escapeChar
}
/ / replace sql special characters {"*", "%", "_"}-> with "/ *", "/%", "/ _"
Private void getNewKeyword () {
If (escapeChar = = null) {
EscapeChar = false
}
If (StringUtils.isNotEmpty (keyword) & &! escapeChar) {
Pattern p1 = Pattern.compile ("\ * |% | _")
Matcher M1 = p1.matcher (keyword)
StringBuffer buf = new StringBuffer ()
While (m1.find ()) {
M1.appendReplacement (buf, "/" + m1.group ())
}
M1.appendTail (buf)
String newkeyword = buf.toString ()
If (! keyword.equals (newkeyword)) {
This.setEscapeChar (true)
This.setKeyword (newkeyword)
}
}
}
}
And (
Name like CONCAT ("%", # {keyword}, "%") escape'/'
Or
Uname like CONCAT ("%", # {keyword}, "%") escape'/'
)