最近在改一个比较久的项目,是使用nodejs写的,但是对于长期写java的后端开发来说,还是有点难维护,不过不改bug的话,就需要重新开发,所以只能慢慢看nodejs代码,测试人员提了一个需要支持模糊查询的bug,如果是java写的,可以马上改好,因为不熟悉nodejs代码,还是改了一两个小时,边找资料,边改,记录下来,方便回顾
实验环境
- VS Code
- Mysql 8.0.26
修改过程
最开始直接这样改
exports.queryWordsList = function (req, res, next) {var Words = DB.get('Words')var params = req.bodyvar page = new Page({pageNum: params.pageNum || 1,pageSize: params.pageSize || 10,})delete params.pageNumdelete params.pageSizevar sql = `select t.id,t.name,t.words, t.type,t.tip_msg,t.replace_str,t.desc,UNIX_TIMESTAMP(t.create_time)*1000 as create_time,UNIX_TIMESTAMP(t.modify_time)*1000 as modify_timefrom t_words t`if (params.word) {sql = `${sql} WHERE name like '%?%' order by t.modify_time desc`} else {sql = `${sql} order by t.modify_time desc`}Words.queryPageBySql(sql,page,[params.word],function (err, result) {if (err) {res.json({ rescode: '10001', err: err })return}var list = page.listres.json({ rescode: '10000', data: result })})
}
运行后,发现报错
{"rescode": "10001","err": {"code": "ER_PARSE_ERROR","errno": 1064,"sqlMessage": "You have an error in your SQL syntax; check the manual that corresponds to your OceanBase version for the right syntax to use near '其'%' order by t.modify_time desc ) T' at line 4","sqlState": "42000","index": 0,"sql": "select count(*) as count from ( select t.id,t.name,t.type,t.tip_msg,t.replace_str,t.desc,\n UNIX_TIMESTAMP(t.create_time)*1000 as create_time,\n UNIX_TIMESTAMP(t.modify_time)*1000 as modify_time\n from t_words t WHERE name like '%'其'%' order by t.modify_time desc ) T"},"status": false,"req_id": "1713148803682.74"
}
所以,修改一下,传一个参数进去
exports.queryWordsList = function (req, res, next) {var Words = DB.get('Words')var params = req.bodyvar page = new Page({pageNum: params.pageNum || 1,pageSize: params.pageSize || 10,})delete params.pageNumdelete params.pageSizevar sql = `select t.id,t.name,t.type,t.tip_msg,t.replace_str,t.desc,UNIX_TIMESTAMP(t.create_time)*1000 as create_time,UNIX_TIMESTAMP(t.modify_time)*1000 as modify_timefrom t_words t`if (params.word) {sql = `${sql} WHERE name like ? order by t.modify_time desc`} else {sql = `${sql} order by t.modify_time desc`}var queryWord = "%" + params.word + "%";Words.queryPageBySql(sql,page,[queryWord],function (err, result) {if (err) {res.json({ rescode: '10001', err: err })return}var list = page.listres.json({ rescode: '10000', data: result })})
}
ok,经过测试,可以查询,不过测试,对于传入"其%"这样的查询字符,sql是直接当成关键字“其”进行模糊查询的,直接忽略了特殊符号“%”,所以要支持这种特殊符号查询,可以加上转义字符,暂时这样处理
sql = `${sql} WHERE name LIKE ? ESCAPE '\\' ORDER BY t.modify_time DESC`;
var queryWord = "%" + params.word.replace(/\\/g, "\\\\").replace(/%/g, "\\%") + "%";