Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
pig_冷冷
Pig
提交
d3c90987
Pig
项目概览
pig_冷冷
/
Pig
上一次同步 大约 1 年
通知
3
Star
1
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
Pig
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
体验新版 GitCode,发现更多精彩内容 >>
提交
d3c90987
编写于
7月 11, 2019
作者:
pig_冷冷
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
🔒
修复安全问题。 更新SQL过滤器,和新版mybatis plus orderitem 保持一致
上级
033f7603
变更
3
隐藏空白更改
内联
并排
Showing
3 changed file
with
42 addition
and
13 deletion
+42
-13
pig-common/pig-common-core/src/main/java/com/pig4cloud/pig/common/core/mybatis/SqlFilterArgumentResolver.java
...ud/pig/common/core/mybatis/SqlFilterArgumentResolver.java
+36
-12
pig-common/pig-common-core/src/main/java/com/pig4cloud/pig/common/core/mybatis/WebMvcConfig.java
...a/com/pig4cloud/pig/common/core/mybatis/WebMvcConfig.java
+4
-0
pig-common/pig-common-core/src/main/resources/META-INF/spring.factories
...-common-core/src/main/resources/META-INF/spring.factories
+2
-1
未找到文件。
pig-common/pig-common-core/src/main/java/com/pig4cloud/pig/common/core/mybatis/SqlFilterArgumentResolver.java
浏览文件 @
d3c90987
...
...
@@ -17,8 +17,9 @@
package
com.pig4cloud.pig.common.core.mybatis
;
import
cn.hutool.core.
util.Array
Util
;
import
cn.hutool.core.
collection.Coll
Util
;
import
cn.hutool.core.util.StrUtil
;
import
com.baomidou.mybatisplus.core.metadata.OrderItem
;
import
com.baomidou.mybatisplus.extension.plugins.pagination.Page
;
import
com.pig4cloud.pig.common.core.exception.CheckedException
;
import
lombok.extern.slf4j.Slf4j
;
...
...
@@ -29,6 +30,8 @@ import org.springframework.web.method.support.HandlerMethodArgumentResolver;
import
org.springframework.web.method.support.ModelAndViewContainer
;
import
javax.servlet.http.HttpServletRequest
;
import
java.util.ArrayList
;
import
java.util.List
;
/**
* @author lengleng
...
...
@@ -39,7 +42,7 @@ import javax.servlet.http.HttpServletRequest;
@Slf4j
public
class
SqlFilterArgumentResolver
implements
HandlerMethodArgumentResolver
{
private
final
static
String
[]
KEYWORDS
=
{
"master"
,
"truncate"
,
"insert"
,
"select"
,
"delete"
,
"update"
,
"declare"
,
"alter"
,
"drop"
,
"sleep"
};
,
"delete"
,
"update"
,
"declare"
,
"alter"
,
"drop"
,
"sleep"
};
/**
* 判断Controller是否包含page 参数
...
...
@@ -63,12 +66,12 @@ public class SqlFilterArgumentResolver implements HandlerMethodArgumentResolver
*/
@Override
public
Object
resolveArgument
(
MethodParameter
parameter
,
ModelAndViewContainer
mavContainer
,
NativeWebRequest
webRequest
,
WebDataBinderFactory
binderFactory
)
{
,
NativeWebRequest
webRequest
,
WebDataBinderFactory
binderFactory
)
{
HttpServletRequest
request
=
webRequest
.
getNativeRequest
(
HttpServletRequest
.
class
);
String
[]
ascs
=
request
.
getParameterValues
(
"ascs"
);
String
[]
descs
=
request
.
getParameterValues
(
"descs"
);
String
ascs
=
request
.
getParameter
(
"ascs"
);
String
descs
=
request
.
getParameter
(
"descs"
);
String
current
=
request
.
getParameter
(
"current"
);
String
size
=
request
.
getParameter
(
"size"
);
...
...
@@ -78,11 +81,23 @@ public class SqlFilterArgumentResolver implements HandlerMethodArgumentResolver
}
if
(
StrUtil
.
isNotBlank
(
size
))
{
page
.
set
Current
(
Long
.
parseLong
(
size
));
page
.
set
Size
(
Long
.
parseLong
(
size
));
}
page
.
setAsc
(
sqlInject
(
ascs
));
page
.
setDesc
(
sqlInject
(
descs
));
// 过滤 asc 条件
List
<
OrderItem
>
ascList
=
sqlInject
(
ascs
,
"asc"
);
// 过滤 desc条件
List
<
OrderItem
>
descList
=
sqlInject
(
descs
,
"desc"
);
List
<
OrderItem
>
orderItemList
=
new
ArrayList
<>();
if
(
CollUtil
.
isNotEmpty
(
ascList
))
{
orderItemList
.
addAll
(
ascList
);
}
if
(
CollUtil
.
isNotEmpty
(
descList
))
{
orderItemList
.
addAll
(
descList
);
}
page
.
setOrders
(
orderItemList
);
return
page
;
}
...
...
@@ -90,13 +105,14 @@ public class SqlFilterArgumentResolver implements HandlerMethodArgumentResolver
* SQL注入过滤
*
* @param str 待验证的字符串
* @return 返回标准的order 属性
*/
p
ublic
static
String
[]
sqlInject
(
String
[]
str
)
{
if
(
ArrayUtil
.
isEmpty
(
str
))
{
p
rivate
static
List
<
OrderItem
>
sqlInject
(
String
str
,
String
type
)
{
if
(
StrUtil
.
isBlank
(
str
))
{
return
null
;
}
//转换成小写
String
inStr
=
ArrayUtil
.
join
(
str
,
StrUtil
.
COMMA
)
.
toLowerCase
();
String
inStr
=
str
.
toLowerCase
();
//判断是否包含非法字符
for
(
String
keyword
:
KEYWORDS
)
{
...
...
@@ -106,6 +122,14 @@ public class SqlFilterArgumentResolver implements HandlerMethodArgumentResolver
}
}
return
str
;
List
<
OrderItem
>
orderItemList
=
new
ArrayList
<>();
for
(
String
in
:
str
.
split
(
StrUtil
.
COMMA
))
{
if
(
"asc"
.
equals
(
type
))
{
orderItemList
.
add
(
OrderItem
.
asc
(
in
));
}
else
{
orderItemList
.
add
(
OrderItem
.
desc
(
in
));
}
}
return
orderItemList
;
}
}
pig-common/pig-common-core/src/main/java/com/pig4cloud/pig/common/core/mybatis/WebMvcConfig.java
浏览文件 @
d3c90987
...
...
@@ -17,12 +17,15 @@
package
com.pig4cloud.pig.common.core.mybatis
;
import
org.springframework.boot.autoconfigure.condition.ConditionalOnWebApplication
;
import
org.springframework.context.annotation.Configuration
;
import
org.springframework.web.method.support.HandlerMethodArgumentResolver
;
import
org.springframework.web.servlet.config.annotation.WebMvcConfigurer
;
import
java.util.List
;
import
static
org
.
springframework
.
boot
.
autoconfigure
.
condition
.
ConditionalOnWebApplication
.
Type
.
SERVLET
;
/**
* @author lengleng
* @date 2019-06-24
...
...
@@ -30,6 +33,7 @@ import java.util.List;
* 注入自自定义SQL 过滤
*/
@Configuration
@ConditionalOnWebApplication
(
type
=
SERVLET
)
public
class
WebMvcConfig
implements
WebMvcConfigurer
{
@Override
public
void
addArgumentResolvers
(
List
<
HandlerMethodArgumentResolver
>
argumentResolvers
)
{
...
...
pig-common/pig-common-core/src/main/resources/META-INF/spring.factories
浏览文件 @
d3c90987
...
...
@@ -4,4 +4,5 @@ org.springframework.boot.autoconfigure.EnableAutoConfiguration=\
com.pig4cloud.pig.common.core.config.RestTemplateConfig,\
com.pig4cloud.pig.common.core.config.FilterIgnorePropertiesConfig,\
com.pig4cloud.pig.common.core.exception.GlobalExceptionHandler,\
com.pig4cloud.pig.common.core.util.SpringContextHolder
com.pig4cloud.pig.common.core.util.SpringContextHolder,\
com.pig4cloud.pig.common.core.mybatis.WebMvcConfig
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录