Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
古剑诛仙
soar
提交
6ae5c3f5
S
soar
项目概览
古剑诛仙
/
soar
与 Fork 源项目一致
Fork自
Xiaomi / soar
通知
1
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
S
soar
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
体验新版 GitCode,发现更多精彩内容 >>
提交
6ae5c3f5
编写于
6月 04, 2021
作者:
martianzhang
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
LIT.002 by pass insert values contain date time
上级
d096d6f5
变更
2
隐藏空白更改
内联
并排
Showing
2 changed file
with
41 addition
and
6 deletion
+41
-6
advisor/heuristic.go
advisor/heuristic.go
+14
-0
advisor/heuristic_test.go
advisor/heuristic_test.go
+27
-6
未找到文件。
advisor/heuristic.go
浏览文件 @
6ae5c3f5
...
...
@@ -962,6 +962,20 @@ func (q *Query4Audit) RuleIPString() Rule {
// RuleDataNotQuote LIT.002
func
(
q
*
Query4Audit
)
RuleDataNotQuote
()
Rule
{
var
rule
=
q
.
RuleOK
()
// by pass insert except, insert select
switch
n
:=
q
.
Stmt
.
(
type
)
{
case
*
sqlparser
.
Insert
:
var
insertSelect
bool
switch
n
.
Rows
.
(
type
)
{
case
*
sqlparser
.
Select
:
insertSelect
=
true
}
if
!
insertSelect
{
return
rule
}
}
// 2010-01-01
re
:=
regexp
.
MustCompile
(
`.\d{4}\s*-\s*\d{1,2}\s*-\s*\d{1,2}\b`
)
sqls
:=
re
.
FindAllString
(
q
.
Query
,
-
1
)
...
...
advisor/heuristic_test.go
浏览文件 @
6ae5c3f5
...
...
@@ -484,11 +484,16 @@ func TestRuleSelectStar(t *testing.T) {
// COL.002
func
TestRuleInsertColDef
(
t
*
testing
.
T
)
{
common
.
Log
.
Debug
(
"Entering function: %s"
,
common
.
GetFunctionName
())
sqls
:=
[]
string
{
"insert into tbl values(1,'name')"
,
"replace into tbl values(1,'name')"
,
sqls
:=
[][]
string
{
{
"insert into tbl values(1,'name')"
,
"replace into tbl values(1,'name')"
,
},
{
"insert into tb (col) values ('hello world')"
,
},
}
for
_
,
sql
:=
range
sqls
{
for
_
,
sql
:=
range
sqls
[
0
]
{
q
,
err
:=
NewQuery4Audit
(
sql
)
if
err
==
nil
{
rule
:=
q
.
RuleInsertColDef
()
...
...
@@ -499,6 +504,18 @@ func TestRuleInsertColDef(t *testing.T) {
t
.
Error
(
"sqlparser.Parse Error:"
,
err
)
}
}
for
_
,
sql
:=
range
sqls
[
1
]
{
q
,
err
:=
NewQuery4Audit
(
sql
)
if
err
==
nil
{
rule
:=
q
.
RuleInsertColDef
()
if
rule
.
Item
!=
"OK"
{
t
.
Error
(
"Rule not match:"
,
rule
.
Item
,
"Expect : OK"
)
}
}
else
{
t
.
Error
(
"sqlparser.Parse Error:"
,
err
)
}
}
common
.
Log
.
Debug
(
"Exiting function: %s"
,
common
.
GetFunctionName
())
}
...
...
@@ -634,10 +651,14 @@ func TestRuleDataNotQuote(t *testing.T) {
{
"select col1,col2 from tbl where time < 2018-01-10"
,
"select col1,col2 from tbl where time < 18-01-10"
,
"INSERT INTO tb1 SELECT * FROM tb2 WHERE time < 2020-01-10"
,
},
{
// TODO:
// "INSERT INTO `pay_order` (`app_pay_obj`) VALUES('timestamp=2019-12-16');",
"select col1,col2 from tbl where time < '2018-01-10'"
,
"INSERT INTO `tb` (`col`) VALUES ('timestamp=2019-12-16')"
,
"insert into tb (col) values (' 2020-09-15 ')"
,
"replace into tb (col) values (' 2020-09-15 ')"
,
"INSERT INTO tb1 SELECT * FROM tb2 WHERE time < '2020-01-10'"
,
},
}
for
_
,
sql
:=
range
sqls
[
0
]
{
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录