sql注入问题

PCqiandao
daiao 5 years ago
parent 71a77ac7b2
commit 2491b2d142

@ -33,10 +33,10 @@ class Weapps::SubjectQuery < ApplicationQuery
private
def order_type
params[:order] || "updated_at"
params[:order] == "updated_at" ? "updated_at" : "myshixuns_count"
end
def sort_type
params[:sort] || "desc"
params[:sort] == "desc" ? "desc" : "asc"
end
end
Loading…
Cancel
Save