|
|
@@ -75,6 +75,20 @@ public class FsCompanyCustomerController extends BaseController {
|
|
|
*/
|
|
|
@GetMapping("/list")
|
|
|
public TableDataInfo list(FsCompanyCustomer fsCompanyCustomer) {
|
|
|
+ // 防止 SQL 注入:只允许指定的排序字段和方向
|
|
|
+ String sortField = fsCompanyCustomer.getSortField();
|
|
|
+ if (sortField != null) {
|
|
|
+ if (!"create_time".equals(sortField) && !"filing_time".equals(sortField)) {
|
|
|
+ fsCompanyCustomer.setSortField(null);
|
|
|
+ fsCompanyCustomer.setSortOrder(null);
|
|
|
+ }
|
|
|
+ }
|
|
|
+ String sortOrder = fsCompanyCustomer.getSortOrder();
|
|
|
+ if (sortOrder != null) {
|
|
|
+ if (!"asc".equals(sortOrder) && !"desc".equals(sortOrder)) {
|
|
|
+ fsCompanyCustomer.setSortOrder(null);
|
|
|
+ }
|
|
|
+ }
|
|
|
// 获取当前登录用户id
|
|
|
Long currentUserId = SecurityUtils.getLoginUser().getUser().getUserId();
|
|
|
//管理员
|