fix(risk_control,message_gateway): fix SQL LIKE escape syntax and use UserService contract

This commit is contained in:
ryan
2026-08-28 20:19:24 +08:00
parent df351cbd33
commit 0035e548a5
6 changed files with 125 additions and 36 deletions
@@ -93,7 +93,7 @@ func applyFilter(query *gorm.DB, filter AccessLogFilter) *gorm.DB {
query = query.Where("user_id IN ?", filter.UserIDs)
}
if filter.Path != "" {
query = query.Where("path LIKE ?", "%"+util.EscapeLike(filter.Path)+"%")
query = query.Where("path LIKE ? ESCAPE '\\'", "%"+util.EscapeLike(filter.Path)+"%")
}
if filter.StartTime != nil {
query = query.Where("created_at >= ?", *filter.StartTime)
@@ -5,6 +5,7 @@ package logstore
import (
"Wavelet/pkg/idgen"
"Wavelet/pkg/util"
"context"
"errors"
"fmt"
@@ -153,8 +154,8 @@ func buildUserAccessLogWhere(filter AccessLogFilter) (string, []any, bool) {
args = append(args, filter.UserIDs)
}
if trimmed := strings.TrimSpace(filter.Path); trimmed != "" {
parts = append(parts, "path LIKE ?")
args = append(args, "%"+trimmed+"%")
parts = append(parts, "path LIKE ? ESCAPE '\\'")
args = append(args, "%"+util.EscapeLike(trimmed)+"%")
}
if filter.StartTime != nil {
parts = append(parts, "created_at >= ?")