sql注入问题

PCqiandao
daiao 5 years ago
parent 71a77ac7b2
commit 2491b2d142

@ -33,10 +33,10 @@ class Weapps::SubjectQuery < ApplicationQuery
private private
def order_type def order_type
params[:order] || "updated_at" params[:order] == "updated_at" ? "updated_at" : "myshixuns_count"
end end
def sort_type def sort_type
params[:sort] || "desc" params[:sort] == "desc" ? "desc" : "asc"
end end
end end
Loading…
Cancel
Save