aice_users.go 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191
  1. package models
  2. import (
  3. "errors"
  4. "fmt"
  5. "reflect"
  6. "strings"
  7. "github.com/beego/beego/v2/client/orm"
  8. )
  9. type AiceUsers struct {
  10. Userid string `orm:"column(userid);pk"`
  11. Email string `orm:"column(email);size(255);null"`
  12. Token string `orm:"column(token);size(255);null"`
  13. Username string `orm:"column(username);size(255);null"`
  14. Address string `orm:"column(address);size(255);null"`
  15. Password string `orm:"column(password);size(255);null"`
  16. }
  17. func (t *AiceUsers) TableName() string {
  18. return "aice_users"
  19. }
  20. func init() {
  21. orm.RegisterModel(new(AiceUsers))
  22. }
  23. // isValidFieldName 验证字段名是否有效,防止SQL注入
  24. func isValidFieldName(fieldName string) bool {
  25. // AiceUsers结构体中的有效字段
  26. validFields := map[string]bool{
  27. "userid": true,
  28. "email": true,
  29. "token": true,
  30. "username": true,
  31. "address": true,
  32. "password": true,
  33. }
  34. // 处理带isnull的情况(如:email__isnull)
  35. baseField := strings.Replace(fieldName, "__isnull", "", -1)
  36. baseField = strings.Replace(baseField, ".", "__", -1)
  37. // 检查基础字段是否有效
  38. for field := range validFields {
  39. if strings.HasPrefix(baseField, field) || baseField == field {
  40. return true
  41. }
  42. }
  43. return false
  44. }
  45. // AddAiceUsers insert a new AiceUsers into database and returns
  46. // last inserted Id on success.
  47. func AddAiceUsers(m *AiceUsers) (id int64, err error) {
  48. o := orm.NewOrm()
  49. id, err = o.Insert(m)
  50. return
  51. }
  52. // GetAiceUsersById retrieves AiceUsers by Id. Returns error if
  53. // Id doesn't exist
  54. func GetAiceUsersById(id string) (v *AiceUsers, err error) {
  55. o := orm.NewOrm()
  56. v = &AiceUsers{Userid: id}
  57. if err = o.Read(v); err == nil {
  58. return v, nil
  59. }
  60. return nil, err
  61. }
  62. // GetAllAiceUsers retrieves all AiceUsers matches certain condition. Returns empty list if
  63. // no records exist
  64. func GetAllAiceUsers(query map[string]string, fields []string, sortby []string, order []string,
  65. offset int64, limit int64) (ml []interface{}, err error) {
  66. o := orm.NewOrm()
  67. qs := o.QueryTable(new(AiceUsers))
  68. // query k=v
  69. for k, v := range query {
  70. // 验证字段名有效性,防止SQL注入
  71. if !isValidFieldName(k) {
  72. return nil, fmt.Errorf("invalid field name: %s", k)
  73. }
  74. // rewrite dot-notation to Object__Attribute
  75. k = strings.Replace(k, ".", "__", -1)
  76. if strings.Contains(k, "isnull") {
  77. qs = qs.Filter(k, (v == "true" || v == "1"))
  78. } else {
  79. qs = qs.Filter(k, v)
  80. }
  81. }
  82. // order by:
  83. var sortFields []string
  84. if len(sortby) != 0 {
  85. // 验证order参数的有效性
  86. if len(order) != 0 && len(order) != 1 && len(order) != len(sortby) {
  87. return nil, errors.New("Error: 'sortby', 'order' sizes mismatch or 'order' size is not 1")
  88. }
  89. // 统一处理排序逻辑,消除重复代码
  90. for i, field := range sortby {
  91. orderDir := "asc"
  92. if len(order) == 1 {
  93. orderDir = order[0]
  94. } else if len(order) > 1 {
  95. orderDir = order[i]
  96. }
  97. orderby := ""
  98. if orderDir == "desc" {
  99. orderby = "-" + field
  100. } else if orderDir == "asc" {
  101. orderby = field
  102. } else {
  103. return nil, errors.New("Error: Invalid order. Must be either [asc|desc]")
  104. }
  105. sortFields = append(sortFields, orderby)
  106. }
  107. qs = qs.OrderBy(sortFields...)
  108. } else {
  109. if len(order) != 0 {
  110. return nil, errors.New("Error: unused 'order' fields")
  111. }
  112. }
  113. var l []AiceUsers
  114. // 验证分页参数
  115. if limit <= 0 || limit > 1000 {
  116. return nil, errors.New("Error: limit must be between 1 and 1000")
  117. }
  118. if offset < 0 {
  119. return nil, errors.New("Error: offset must be non-negative")
  120. }
  121. if _, err = qs.Limit(limit, offset).All(&l, fields...); err == nil {
  122. if len(fields) == 0 {
  123. for _, v := range l {
  124. ml = append(ml, v)
  125. }
  126. } else {
  127. // trim unused fields
  128. for _, v := range l {
  129. m := make(map[string]interface{})
  130. val := reflect.ValueOf(v)
  131. for _, fname := range fields {
  132. field := val.FieldByName(fname)
  133. if !field.IsValid() {
  134. return nil, fmt.Errorf("invalid field name: %s", fname)
  135. }
  136. m[fname] = field.Interface()
  137. }
  138. ml = append(ml, m)
  139. }
  140. }
  141. return ml, nil
  142. }
  143. return nil, err
  144. }
  145. // UpdateAiceUsers updates AiceUsers by Id and returns error if
  146. // the record to be updated doesn't exist
  147. func UpdateAiceUsersById(m *AiceUsers) (err error) {
  148. o := orm.NewOrm()
  149. v := AiceUsers{Userid: m.Userid}
  150. // ascertain id exists in the database
  151. if err = o.Read(&v); err == nil {
  152. var num int64
  153. if num, err = o.Update(m); err == nil {
  154. fmt.Println("Number of records updated in database:", num)
  155. }
  156. }
  157. return
  158. }
  159. // DeleteAiceUsers deletes AiceUsers by Id and returns error if
  160. // the record to be deleted doesn't exist
  161. func DeleteAiceUsers(id string) (err error) {
  162. o := orm.NewOrm()
  163. v := AiceUsers{Userid: id}
  164. // ascertain id exists in the database
  165. if err = o.Read(&v); err == nil {
  166. var num int64
  167. if num, err = o.Delete(&AiceUsers{Userid: id}); err == nil {
  168. fmt.Println("Number of records deleted in database:", num)
  169. }
  170. }
  171. return
  172. }