Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
T
task2.0
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
首航-临时账号
task2.0
Commits
c23874b3
Commit
c23874b3
authored
Sep 23, 2024
by
罗胜
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
sql注入漏洞修复
parent
8a85d9fa
Show whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
16 additions
and
9 deletions
+16
-9
SoundService.java
src/com/foc/sound/service/SoundService.java
+9
-5
SoundDbTaskMain.java
src/com/foc/task/SoundDbTaskMain.java
+1
-1
DBHelper.java
src/com/foc/util/DBHelper.java
+6
-3
No files found.
src/com/foc/sound/service/SoundService.java
View file @
c23874b3
...
@@ -550,13 +550,17 @@ public class SoundService {
...
@@ -550,13 +550,17 @@ public class SoundService {
if
(
GConstants
.
NO
.
equals
(
flag
))
{
if
(
GConstants
.
NO
.
equals
(
flag
))
{
tableName
=
Constants
.
FOC_SOUND_RECORDS
;
tableName
=
Constants
.
FOC_SOUND_RECORDS
;
}
}
stringBuilder
.
append
(
"FROM "
).
append
(
tableName
).
append
(
"\n"
)
stringBuilder
.
append
(
"FROM "
).
append
(
" ? "
).
append
(
"\n"
)
.
append
(
"WHERE end_status != 'INIT'\n"
)
.
append
(
"WHERE end_status != 'INIT'\n"
)
.
append
(
"AND create_name =
'"
).
append
(
callUser
.
getName
()).
append
(
"'
\n"
)
.
append
(
"AND create_name =
?
\n"
)
.
append
(
"AND start_time <=
'"
).
append
(
entity
.
getEndTime
()).
append
(
"
'\n"
)
.
append
(
"AND start_time <=
?
'\n"
)
.
append
(
"AND id !=
'"
).
append
(
recordId
).
append
(
"'
\n"
)
.
append
(
"AND id !=
?
\n"
)
.
append
(
"ORDER BY start_time DESC"
);
.
append
(
"ORDER BY start_time DESC"
);
List
<
Map
<
String
,
Object
>>
soundRecordsList
=
DBHelper
.
fetch
(
"foc"
,
stringBuilder
.
toString
());
List
<
Object
>
params
=
new
ArrayList
<>();
params
.
add
(
callUser
.
getName
());
params
.
add
(
DateUtil
.
dateToStr
(
entity
.
getEndTime
(),
"yyyy-MM-dd hh:mm:ss"
));
params
.
add
(
recordId
);
List
<
Map
<
String
,
Object
>>
soundRecordsList
=
DBHelper
.
fetch
(
"foc"
,
stringBuilder
.
toString
(),
params
);
// 过滤掉了id,所以查出的数据就是重复的
// 过滤掉了id,所以查出的数据就是重复的
if
(
soundRecordsList
!=
null
&&
soundRecordsList
.
size
()
>
0
)
{
if
(
soundRecordsList
!=
null
&&
soundRecordsList
.
size
()
>
0
)
{
for
(
Map
<
String
,
Object
>
map
:
soundRecordsList
)
{
for
(
Map
<
String
,
Object
>
map
:
soundRecordsList
)
{
...
...
src/com/foc/task/SoundDbTaskMain.java
View file @
c23874b3
...
@@ -206,7 +206,7 @@ public class SoundDbTaskMain {
...
@@ -206,7 +206,7 @@ public class SoundDbTaskMain {
Class
.
forName
(
driver
);
Class
.
forName
(
driver
);
conn
=
DriverManager
.
getConnection
(
url
,
username
,
password
);
conn
=
DriverManager
.
getConnection
(
url
,
username
,
password
);
pstmt
=
conn
pstmt
=
conn
.
prepareStatement
(
"select MAX(id) AS maxid from
"
+
tableName
);
.
prepareStatement
(
"select MAX(id) AS maxid from
dbo.cdr"
);
rs
=
pstmt
.
executeQuery
();
rs
=
pstmt
.
executeQuery
();
while
(
rs
.
next
())
{
while
(
rs
.
next
())
{
...
...
src/com/foc/util/DBHelper.java
View file @
c23874b3
...
@@ -500,9 +500,9 @@ public class DBHelper {
...
@@ -500,9 +500,9 @@ public class DBHelper {
* @param query
* @param query
* @return
* @return
*/
*/
public
static
List
<
Map
<
String
,
Object
>>
fetch
(
String
name
,
String
query
){
public
static
List
<
Map
<
String
,
Object
>>
fetch
(
String
name
,
String
query
,
List
<
Object
>
params
){
return
fetch
(
name
,
query
,
true
);
return
fetch
(
name
,
query
,
params
,
true
);
}
}
/**
/**
* 获取所有结果
* 获取所有结果
...
@@ -513,7 +513,7 @@ public class DBHelper {
...
@@ -513,7 +513,7 @@ public class DBHelper {
* @param byLabel
* @param byLabel
* @return
* @return
*/
*/
public
static
List
<
Map
<
String
,
Object
>>
fetch
(
String
name
,
String
query
,
boolean
byLabel
){
public
static
List
<
Map
<
String
,
Object
>>
fetch
(
String
name
,
String
query
,
List
<
Object
>
params
,
boolean
byLabel
){
synchronized
(
object
){
synchronized
(
object
){
PreparedStatement
ps
=
null
;
PreparedStatement
ps
=
null
;
Connection
conn
=
null
;
Connection
conn
=
null
;
...
@@ -523,6 +523,9 @@ public class DBHelper {
...
@@ -523,6 +523,9 @@ public class DBHelper {
try
{
try
{
conn
=
getConnection
(
name
);
conn
=
getConnection
(
name
);
ps
=
conn
.
prepareStatement
(
query
);
ps
=
conn
.
prepareStatement
(
query
);
for
(
int
i
=
0
;
i
<
params
.
size
();
i
++)
{
ps
.
setString
(
i
+
1
,
params
.
get
(
i
).
toString
());
}
rs
=
ps
.
executeQuery
();
rs
=
ps
.
executeQuery
();
rows
=
new
ArrayList
<
Map
<
String
,
Object
>>();
rows
=
new
ArrayList
<
Map
<
String
,
Object
>>();
String
coluName
=
null
;
String
coluName
=
null
;
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment