mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-07 08:06:37 +08:00
fix(risk_control,message_gateway): fix SQL LIKE escape syntax and use UserService contract
This commit is contained in:
@@ -93,7 +93,7 @@ func applyFilter(query *gorm.DB, filter AccessLogFilter) *gorm.DB {
|
||||
query = query.Where("user_id IN ?", filter.UserIDs)
|
||||
}
|
||||
if filter.Path != "" {
|
||||
query = query.Where("path LIKE ?", "%"+util.EscapeLike(filter.Path)+"%")
|
||||
query = query.Where("path LIKE ? ESCAPE '\\'", "%"+util.EscapeLike(filter.Path)+"%")
|
||||
}
|
||||
if filter.StartTime != nil {
|
||||
query = query.Where("created_at >= ?", *filter.StartTime)
|
||||
|
||||
@@ -5,6 +5,7 @@ package logstore
|
||||
|
||||
import (
|
||||
"Wavelet/pkg/idgen"
|
||||
"Wavelet/pkg/util"
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
@@ -153,8 +154,8 @@ func buildUserAccessLogWhere(filter AccessLogFilter) (string, []any, bool) {
|
||||
args = append(args, filter.UserIDs)
|
||||
}
|
||||
if trimmed := strings.TrimSpace(filter.Path); trimmed != "" {
|
||||
parts = append(parts, "path LIKE ?")
|
||||
args = append(args, "%"+trimmed+"%")
|
||||
parts = append(parts, "path LIKE ? ESCAPE '\\'")
|
||||
args = append(args, "%"+util.EscapeLike(trimmed)+"%")
|
||||
}
|
||||
if filter.StartTime != nil {
|
||||
parts = append(parts, "created_at >= ?")
|
||||
|
||||
Reference in New Issue
Block a user