fix 修复代码生成单图上传字段名,列表搜素orderBy参数校验,防止sql注入

This commit is contained in:
yxh 2025-06-25 21:52:22 +08:00
parent 677b47c708
commit bc8a3be3bc
3 changed files with 6 additions and 6 deletions

View File

@ -9,10 +9,10 @@ package model
// PageReq 公共请求参数
type PageReq struct {
DateRange []string `p:"dateRange"` //日期范围
PageNum int `p:"pageNum"` //当前页码
PageSize int `p:"pageSize"` //每页数
OrderBy string //排序方式
DateRange []string `p:"dateRange"` //日期范围
PageNum int `p:"pageNum"` //当前页码
PageSize int `p:"pageSize"` //每页数
OrderBy string `p:"orderBy" v:"regex:^[a-zA-Z0-9_]+(\\.[a-zA-Z0-9_]+)?\\s+(asc|desc|ASC|DESC)(?:\\s*,\\s*[a-zA-Z0-9_]+(\\.[a-zA-Z0-9_]+)?\\s+(asc|desc|ASC|DESC))*$#排序参数不合法"` // 排序方式
}
// ListRes 列表公共返回

View File

@ -9,5 +9,5 @@ package consts
const (
Logo = `CiAgIF9fX19fX19fX19fXyAgICAgICAgICAgX18gCiAgLyBfX19fLyBfX19fL19fXyBfX19fX18vIC9fCiAvIC8gX18vIC9fICAvIF9fIGAvIF9fXy8gX18vCi8gL18vIC8gX18vIC8gL18vIChfXyAgKSAvXyAgClxfX19fL18vICAgIFxfXyxfL19fX18vXF9fLyAg`
Version = "3.3.5"
Version = "3.3.6"
)

View File

@ -187,7 +187,7 @@
class="avatar-uploader"
name="file"
>
<div v-if="!proxy.isEmpty(imageUrlThumb)">
<div v-if="!proxy.isEmpty(imageUrl{{$column.GoField}})">
<el-link type="danger" style="position: absolute; right: 5px; top: 6px;font-size: 18px;" :underline="false" @click.stop="deleteImageUrl{{$column.GoField}}" title="删除">
<el-icon><ele-DeleteFilled /></el-icon>
</el-link>