package models import ( "errors" "fmt" "reflect" "strings" "github.com/beego/beego/v2/client/orm" ) type AiceUsers struct { Userid string `orm:"column(userid);pk"` Email string `orm:"column(email);size(255);null"` Token string `orm:"column(token);size(255);null"` Username string `orm:"column(username);size(255);null"` Address string `orm:"column(address);size(255);null"` Password string `orm:"column(password);size(255);null"` } func (t *AiceUsers) TableName() string { return "aice_users" } func init() { orm.RegisterModel(new(AiceUsers)) } // isValidFieldName 验证字段名是否有效,防止SQL注入 func isValidFieldName(fieldName string) bool { // AiceUsers结构体中的有效字段 validFields := map[string]bool{ "userid": true, "email": true, "token": true, "username": true, "address": true, "password": true, } // 处理带isnull的情况(如:email__isnull) baseField := strings.Replace(fieldName, "__isnull", "", -1) baseField = strings.Replace(baseField, ".", "__", -1) // 检查基础字段是否有效 for field := range validFields { if strings.HasPrefix(baseField, field) || baseField == field { return true } } return false } // AddAiceUsers insert a new AiceUsers into database and returns // last inserted Id on success. func AddAiceUsers(m *AiceUsers) (id int64, err error) { o := orm.NewOrm() id, err = o.Insert(m) return } // GetAiceUsersById retrieves AiceUsers by Id. Returns error if // Id doesn't exist func GetAiceUsersById(id string) (v *AiceUsers, err error) { o := orm.NewOrm() v = &AiceUsers{Userid: id} if err = o.Read(v); err == nil { return v, nil } return nil, err } // GetAllAiceUsers retrieves all AiceUsers matches certain condition. Returns empty list if // no records exist func GetAllAiceUsers(query map[string]string, fields []string, sortby []string, order []string, offset int64, limit int64) (ml []interface{}, err error) { o := orm.NewOrm() qs := o.QueryTable(new(AiceUsers)) // query k=v for k, v := range query { // 验证字段名有效性,防止SQL注入 if !isValidFieldName(k) { return nil, fmt.Errorf("invalid field name: %s", k) } // rewrite dot-notation to Object__Attribute k = strings.Replace(k, ".", "__", -1) if strings.Contains(k, "isnull") { qs = qs.Filter(k, (v == "true" || v == "1")) } else { qs = qs.Filter(k, v) } } // order by: var sortFields []string if len(sortby) != 0 { // 验证order参数的有效性 if len(order) != 0 && len(order) != 1 && len(order) != len(sortby) { return nil, errors.New("Error: 'sortby', 'order' sizes mismatch or 'order' size is not 1") } // 统一处理排序逻辑,消除重复代码 for i, field := range sortby { orderDir := "asc" if len(order) == 1 { orderDir = order[0] } else if len(order) > 1 { orderDir = order[i] } orderby := "" if orderDir == "desc" { orderby = "-" + field } else if orderDir == "asc" { orderby = field } else { return nil, errors.New("Error: Invalid order. Must be either [asc|desc]") } sortFields = append(sortFields, orderby) } qs = qs.OrderBy(sortFields...) } else { if len(order) != 0 { return nil, errors.New("Error: unused 'order' fields") } } var l []AiceUsers // 验证分页参数 if limit <= 0 || limit > 1000 { return nil, errors.New("Error: limit must be between 1 and 1000") } if offset < 0 { return nil, errors.New("Error: offset must be non-negative") } if _, err = qs.Limit(limit, offset).All(&l, fields...); err == nil { if len(fields) == 0 { for _, v := range l { ml = append(ml, v) } } else { // trim unused fields for _, v := range l { m := make(map[string]interface{}) val := reflect.ValueOf(v) for _, fname := range fields { field := val.FieldByName(fname) if !field.IsValid() { return nil, fmt.Errorf("invalid field name: %s", fname) } m[fname] = field.Interface() } ml = append(ml, m) } } return ml, nil } return nil, err } // UpdateAiceUsers updates AiceUsers by Id and returns error if // the record to be updated doesn't exist func UpdateAiceUsersById(m *AiceUsers) (err error) { o := orm.NewOrm() v := AiceUsers{Userid: m.Userid} // ascertain id exists in the database if err = o.Read(&v); err == nil { var num int64 if num, err = o.Update(m); err == nil { fmt.Println("Number of records updated in database:", num) } } return } // DeleteAiceUsers deletes AiceUsers by Id and returns error if // the record to be deleted doesn't exist func DeleteAiceUsers(id string) (err error) { o := orm.NewOrm() v := AiceUsers{Userid: id} // ascertain id exists in the database if err = o.Read(&v); err == nil { var num int64 if num, err = o.Delete(&AiceUsers{Userid: id}); err == nil { fmt.Println("Number of records deleted in database:", num) } } return }