Browse Source

修复:SQL语法漏洞

dev_shibei_match
wxz 4 years ago
parent
commit
6019fd9122
  1. 2
      epmet-user/epmet-user-server/src/main/resources/mapper/GovStaffRoleDao.xml

2
epmet-user/epmet-user-server/src/main/resources/mapper/GovStaffRoleDao.xml

@ -132,11 +132,13 @@
gov_staff_role gov_staff_role
WHERE WHERE
DEL_FLAG = 0 DEL_FLAG = 0
<if test="roleIds != null and roleIds.size() > 0">
AND ( AND (
<foreach collection="roleIds" item="roleId" separator=" OR "> <foreach collection="roleIds" item="roleId" separator=" OR ">
ID = #{roleId} ID = #{roleId}
</foreach> </foreach>
) )
</if>
</select> </select>
<select id="getStaffRoles" resultType="com.epmet.entity.GovStaffRoleEntity"> <select id="getStaffRoles" resultType="com.epmet.entity.GovStaffRoleEntity">
SELECT SELECT

Loading…
Cancel
Save