安全性測(cè)試 - nodejs中如何防m(xù)ySQL注入
問題描述
如題,如能有具體示例或demo鏈接感激不盡
問題解答
回答1:使用escape()對(duì)傳入?yún)?shù)進(jìn)行編碼var userId = 1, name = ’test’;var query = connection.query(’SELECT * FROM users WHERE id = ’ + connection.escape(userId) + ’, name = ’ + connection.escape(name), function(err, results) { // ...});console.log(query.sql); // SELECT * FROM users WHERE id = 1, name = ’test’使用connection.query()的查詢參數(shù)占位符
var userId = 1, name = ’test’;var query = connection.query(’SELECT * FROM users WHERE id = ?, name = ?’, [userId, name], function(err, results) { // ...});console.log(query.sql); // SELECT * FROM users WHERE id = 1, name = ’test’使用escapeId()編碼SQL查詢標(biāo)識(shí)符
var sorter = ’date’;var sql = ’SELECT * FROM posts ORDER BY ’ + connection.escapeId(sorter);connection.query(sql, function(err, results) { // ...});使用mysql.format()轉(zhuǎn)義參數(shù)
var userId = 1;var sql = 'SELECT * FROM ?? WHERE ?? = ?';var inserts = [’users’, ’id’, userId];sql = mysql.format(sql, inserts); // SELECT * FROM users WHERE id = 1
Ref: http://www.dengzhr.com/node-j...
PS: Google第一頁(yè)就是答案
相關(guān)文章:
1. node.js - nodejs+express+vue2. javascript - vue2.0中使用vue2-dropzone的demo,vue2-dropzone的github網(wǎng)址是什么??百度不到。3. elasticsearch - Elastisearch怎么求查詢結(jié)果的交集,如MYSQL的interset4. node.js - win7下,npm 無法下載依賴包,淘寶鏡像也裝不上,求幫忙???5. Python 子類能否覆蓋全局函數(shù)?6. javascript - JS如何取對(duì)稱范圍的隨機(jī)數(shù)?7. 前端 - @media query 使用出現(xiàn)的問題?8. java軟引用在android中有實(shí)際應(yīng)用場(chǎng)景嗎?9. mysql - sql 找出2個(gè)數(shù)據(jù)庫(kù)的差異表名10. vue計(jì)算屬性怎么樣與for結(jié)合使用
