账号密码登录
微信安全登录
微信扫描二维码登录

登录后绑定QQ、微信即可实现信息互通

手机验证码登录
找回密码返回
邮箱找回 手机找回
注册账号返回
其他登录方式
分享
  • 收藏
    X
    使用Mybatis的@SelectProvide会不会导致注入攻击?
    105
    0

    各位前辈,最近我在用mybatis注解开发,在使用动态sql的时候,是这样用的:

    @SelectProvider(type = SqlProvider.class, method = "countByDate")
    int countVoucherByDate(@Param("pre_date") String pre_date,
                           @Param("post_date") String post_date,
                           @Param("merchant_id") int merchant_id);

    在SqlProvider类中的方法是:

    public String countByDate(Map<String, Object> param){
        String pre_date = (String) param.get("pre_date");
        String post_date = (String) param.get("post_date");
        int merchant_id = (int) param.get("merchant_id");
    
        String sql = " select count(*) from voucher_t" +
                " where 1 = 1";
        if(!StringUtils.isEmpty(pre_date) && !StringUtils.isEmpty(post_date)){
            sql += " and create_date > " + "\"" + pre_date + "\"";
            sql += " and create_date < " + "\"" + post_date + " 23:59:59" + "\"";
        }
        sql +=  " and merchant_id = " + merchant_id;
        return sql;
    }

    如果用这种方法,会不会导致sql注入攻击?因为返回的是完整的sql执行语句,没有经过mybatis的preparedstatement处理。
    如何改进?

    0
    打赏
    收藏
    点击回答
        全部回答
    • 共 0 条
    • 柠檬花扣 普通会员 1楼
      502 Bad Gateway

      502 Bad Gateway


      nginx
    更多回答
    扫一扫访问手机版
    • 回到顶部
    • 回到顶部