From f6626b05f1275cc2f8ca77f773d4f6a6af1b0a89 Mon Sep 17 00:00:00 2001
From: king <18310653075@163.com>
Date: 星期一, 21 十一月 2022 16:11:55 +0800
Subject: [PATCH] 2022-11-21

---
 src/menu/datasource/verifycard/utils.jsx |   36 ++++++++++++++++++++++++++++--------
 1 files changed, 28 insertions(+), 8 deletions(-)

diff --git a/src/menu/datasource/verifycard/utils.jsx b/src/menu/datasource/verifycard/utils.jsx
index 23890a5..d4145df 100644
--- a/src/menu/datasource/verifycard/utils.jsx
+++ b/src/menu/datasource/verifycard/utils.jsx
@@ -40,8 +40,8 @@
     //   error = '绯荤粺鍑芥暟' + _customScript.match(/\$ex@.{1,50}@ex\$/g)[0].replace(/\$ex@|@ex\$/g, '') + '鏈畾涔�'
     // }
 
-    _dataresource = _dataresource.replace(/@(BID|ID|LoginUID|SessionUid|UserID|Appkey|time_id)@/ig, `'${timestamp}'`)
-    _customScript = _customScript.replace(/@(BID|ID|LoginUID|SessionUid|UserID|Appkey|time_id)@/ig, `'${timestamp}'`)
+    _dataresource = _dataresource.replace(/@(BID|ID|LoginUID|SessionUid|UserID|Appkey|time_id|datam|upid)@/ig, `'${timestamp}'`)
+    _customScript = _customScript.replace(/@(BID|ID|LoginUID|SessionUid|UserID|Appkey|time_id|datam|upid)@/ig, `'${timestamp}'`)
 
     _dataresource = _dataresource.replace(/@\$|\$@/ig, '')
     _customScript = _customScript.replace(/@\$|\$@/ig, '')
@@ -163,14 +163,14 @@
 
     if (arr_field && _dataresource && /\/\*\$sum@/ig.test(_dataresource)) {
       let _sql = _dataresource.replace(/\/\*\$sum@|@sum\$\*\//ig, '')
-      _sql = `${_sql} ${_search}`
+      _sql = `/*system_query*/${_sql} ${_search}`
       if (_customScript) {
         sumSql = `/* sql sum楠岃瘉 */
           ${_customScript}
           ${_sql}
           aaa:
           if @ErrorCode!=''
-            insert into tmp_err_retmsg (ID, ErrorCode, retmsg, CreateUserID) select @time_id@,@ErrorCode, @retmsg,@UserID@
+            insert into tmp_err_retmsg (ID, ErrorCode, retmsg, CreateUserID) select '${timestamp}',@ErrorCode, @retmsg,'${timestamp}'
         `
       } else {
         sumSql = `/* sql sum楠岃瘉 */
@@ -186,9 +186,9 @@
       }
 
       if (setting.order) {
-        _dataresource = `select${setting.laypage === 'true' ?  ' top 10' : ''} ${arr_field} from (select ${arr_field} ,ROW_NUMBER() over(order by ${setting.order}) as rows from ${_dataresource} ${_search}) tmptable ${setting.laypage === 'true' ?  'where rows > 0' : ''} order by tmptable.rows`
+        _dataresource = `/*system_query*/select${setting.laypage === 'true' ?  ' top 10' : ''} ${arr_field} from (select ${arr_field} ,ROW_NUMBER() over(order by ${setting.order}) as rows from ${_dataresource} ${_search}) tmptable ${setting.laypage === 'true' ?  'where rows > 0' : ''} order by tmptable.rows`
       } else {
-        _dataresource = `select${setting.laypage === 'true' ?  ' top 10' : ''} ${arr_field} from ${_dataresource} ${_search}`
+        _dataresource = `/*system_query*/select${setting.laypage === 'true' ?  ' top 10' : ''} ${arr_field} from ${_dataresource} ${_search}`
       }
     }
 
@@ -198,7 +198,7 @@
         ${_dataresource}
         aaa:
         if @ErrorCode!=''
-          insert into tmp_err_retmsg (ID, ErrorCode, retmsg, CreateUserID) select @time_id@,@ErrorCode, @retmsg,@UserID@
+          insert into tmp_err_retmsg (ID, ErrorCode, retmsg, CreateUserID) select '${timestamp}',@ErrorCode, @retmsg,'${timestamp}'
       `
     } else {
       sql = `/* sql 楠岃瘉 */
@@ -209,12 +209,32 @@
 
     console.info(sql)
 
+    let errors = []
+
+    if (/@[0-9a-zA-Z_]+@/ig.test(sql)) {
+      let arr = sql.match(/@[0-9a-zA-Z_]+@/ig)
+
+      arr.forEach(item => {
+        let reg = new RegExp(item, 'ig')
+        if (reg.test(_dataresource)) {
+          errors.push(`鏁版嵁婧愪腑瀛樺湪鏈浛鎹㈠��${item}`)
+        }
+        scripts && scripts.forEach(script => {
+          if (reg.test(script.sql)) {
+            errors.push(`鑷畾涔夎剼鏈�(${script.$index || ''})瀛樺湪鏈浛鎹㈠��${item}`)
+          }
+        })
+      })
+    }
+
     if (sumSql) {
       sumSql = sumSql.replace(/\n\s{10}/ig, '\n')
 
       console.info(sumSql)
+      sumSql = sumSql.replace(/\n/g, ' ')
     }
+    sql = sql.replace(/\n/g, ' ')
     
-    return { error, sql, sumSql }
+    return { error, sql, sumSql, errors: errors.join('锛�') }
   }
 }
\ No newline at end of file

--
Gitblit v1.8.0