mirror of
https://gitee.com/ShopeX/OMS
synced 2026-05-02 13:15:39 +08:00
fix: 禁止使用SQL语句--防止漏洞
This commit is contained in:
@@ -153,10 +153,14 @@ class vop_ctl_admin_sku_stock extends desktop_controller
|
|||||||
@ini_set('memory_limit','512M');
|
@ini_set('memory_limit','512M');
|
||||||
set_time_limit(0);
|
set_time_limit(0);
|
||||||
|
|
||||||
//shop
|
// 获取绑定的唯品会店铺列表
|
||||||
$shopObj = app::get('ome')->model('shop');
|
$shopObj = app::get('ome')->model('shop');
|
||||||
$sql = "SELECT shop_id,shop_bn,name AS shop_name,shop_type,node_id FROM sdb_ome_shop WHERE shop_type ='vop' AND node_id IS NOT NULL AND node_id != ''";
|
$filter = [
|
||||||
$shopList = $shopObj->db->select($sql);
|
'shop_type' => 'vop',
|
||||||
|
'filter_sql' => 'node_id IS NOT NULL AND node_id != ""',
|
||||||
|
];
|
||||||
|
$shopList = $shopObj->getList('shop_id,shop_bn,name AS shop_name,shop_type,node_id', $filter);
|
||||||
|
|
||||||
$this->pagedata['shopList'] = $shopList;
|
$this->pagedata['shopList'] = $shopList;
|
||||||
|
|
||||||
//开始时间(默认为昨天)
|
//开始时间(默认为昨天)
|
||||||
@@ -212,9 +216,13 @@ class vop_ctl_admin_sku_stock extends desktop_controller
|
|||||||
'err_msg' => array(),
|
'err_msg' => array(),
|
||||||
);
|
);
|
||||||
|
|
||||||
//shop
|
// 获取绑定的唯品会店铺
|
||||||
$sql = "SELECT shop_id,shop_bn,name,shop_type,node_id FROM sdb_ome_shop WHERE shop_type ='vop' AND shop_bn='". $_POST['shop_bn'] ."' AND node_id IS NOT NULL AND node_id != ''";
|
$filter = [
|
||||||
$shopInfo = $shopObj->db->selectrow($sql);
|
'shop_type' => 'vop',
|
||||||
|
'shop_bn' => $_POST['shop_bn'],
|
||||||
|
'filter_sql' => 'node_id IS NOT NULL AND node_id != ""',
|
||||||
|
];
|
||||||
|
$shopInfo = $shopObj->dump($filter, '*');
|
||||||
if(empty($shopInfo)){
|
if(empty($shopInfo)){
|
||||||
$retArr['err_msg'] = array('唯品会店铺不符合,无法拉取数据');
|
$retArr['err_msg'] = array('唯品会店铺不符合,无法拉取数据');
|
||||||
echo json_encode($retArr);
|
echo json_encode($retArr);
|
||||||
|
|||||||
Reference in New Issue
Block a user