Detection method and device for preventing SQL leakage, electronic equipment and medium
By detecting the Mapper object when Spring program starts, the problem of missing SQL caused by developers forgetting to add fields on the online database is solved, avoiding the program's error and generating error log prompts.
Patent Information
- Application Number
- CN202510772134.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-11
AI Technical Summary
When developing an application, developers may forget to add fields to the online database, resulting in SQL missing and an error in the program.
When starting the Spring program, start the preset detection program, obtain the Mapper object and detect it based on the detection rules. If there is SQL missing, return the exception result and stop starting the Spring program.
Avoid program errors caused by missed SQL. By detecting and preventing the start of Spring programs at startup, an error log is generated to prompt the developer to missed SQL.
Smart Images

Figure CN120276965A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a detection method, device, electronic device and medium for preventing SQL leakage. Background Art
[0002] During the process of developing an application, developers often add fields during requirement development, and through a strict release system, write a release plan before release and verify after release according to the release plan. However, when the requirements are put online, developers may forget to add fields to the online database, which is commonly known as SQL leakage, and thus the program will report an error. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a detection method, device, electronic device and medium for preventing SQL leakage, which can avoid program errors caused by SQL leakage when requirements are put online.
[0004] In order to achieve the above purpose, the technical solution adopted by the present invention is as follows: In the first aspect, the present invention provides a detection method for preventing SQL leakage, including: when starting a Spring program, starting a preset detection program; obtaining a Mapper object in the Spring program, and performing detection based on the Mapper object according to the detection rules set in the detection program; if there is a situation of SQL leakage during the detection process, returning an abnormal result and stopping the startup of the Spring program.
[0005] Optionally, when starting a Spring program, starting a preset detection program includes: obtaining and starting a preset detection program by calling a preset CommandLineRunner interface in the Spring program.
[0006] Optionally, obtaining a Mapper object in the Spring program includes: obtaining a Mapper object in the Spring program through the Resource annotation of the Spring program.
[0007] Optionally, performing detection based on the Mapper object according to the detection rules set in the detection program includes: performing a database query based on the Mapper object, and judging whether there is a situation of SQL leakage based on the database query result.
[0008] Optionally, perform a database query based on the Mapper object, and determine whether there is a missing SQL statement based on the database query result, including: looping through and executing the selectList method of each Mapper object; if there is no missing SQL statement, obtain the first record of the actual table mapped by the Mapper object; if there is a missing SQL statement, the SelectList method of the Mapper object cannot be executed, and the database returns a detection exception result.
[0009] Optionally, it further includes: generating an error log during the execution of the detection program to prompt developers of the missing SQL statement.
[0010] In a second aspect, the present invention provides a detection device for preventing missing SQL statements, including: a detection program startup module for starting a preset detection program when starting a Spring program; a detection module for obtaining Mapper objects in the Spring program and performing detection based on the detection rules set in the detection program according to the Mapper objects; a result feedback module for returning an exception result and stopping the startup of the Spring program if there is a missing SQL statement during the detection process.
[0011] Optionally, the detection program startup module is specifically configured to: obtain and start a preset detection program by calling a preset CommandLineRunner interface in the Spring program.
[0012] In a third aspect, the present invention provides an electronic device, including a processor and a memory, where the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the steps of the method provided in any one of the first aspects above.
[0013] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the steps of the method provided in any one of the first aspects above.
[0014] The present invention brings the following beneficial effects: The above-mentioned SQL leakage prevention detection method, device, electronic device and medium provided by the present invention first start a preset detection program when starting the Spring program; then obtain the Mapper object in the Spring program, and perform detection based on the Mapper object according to the detection rules set in the detection program; if there is a situation of SQL leakage during the detection process, an abnormal result is returned, and the startup of the Spring program is stopped. The above method can execute the detection program when starting the Spring program, detect whether there is SQL leakage based on the Mapper object, and if so, stop the startup of the Spring program, thereby avoiding program errors caused by SQL leakage when the requirements are put on the line.
[0015] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention are realized and obtained by the structures specifically pointed out in the specification, claims and drawings.
[0016] To make the above objectives, features and advantages of the present invention more obvious and understandable, the following specifically gives preferred examples and, in conjunction with the accompanying drawings, makes a detailed description as follows. Description of the Drawings
[0017] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0018] Figure 1 It is a flowchart of a method for detecting SQL leakage prevention provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a device for detecting SQL leakage prevention provided by an embodiment of the present invention; Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments
[0019] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention in conjunction with the drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0020] Spring: A framework that supports the rapid development of Java EE applications.
[0021] MyBatis: An excellent persistence layer framework that supports custom SQL, stored procedures, and advanced mapping.
[0022] Mybatis-Plus: An enhanced tool for MyBatis, which only enhances without changing on the basis of MyBatis, and is born to simplify development and improve efficiency.
[0023] Currently, during the development of applications by developers, fields are often added during requirements development. However, when the requirements are put into production, developers may forget to add fields to the online database, which is commonly known as missing SQL. Therefore, it will cause the program to report an error.
[0024] Based on this, a detection method, device, electronic device, and medium for preventing missing SQL provided by the embodiments of the present invention can avoid program errors caused by missing SQL when requirements are put into production.
[0025] For the convenience of understanding this embodiment, first, a detection method for preventing missing SQL disclosed in the embodiments of the present invention will be introduced in detail. This method can be executed by an electronic device, such as a smart phone, a computer, a tablet computer, etc. Refer to Figure 1 The flowchart of a detection method for preventing missing SQL shown in the figure indicates that the method mainly includes the following steps S101 to step S103: Step S101: When starting the Spring program, start a preset detection program.
[0026] In one implementation, the Spring program has a startup process, and the program only provides services after startup. In this embodiment, a detection program is added to the Spring program to detect missing SQL when starting the Spring program.
[0027] In specific implementation, the preset detection program can be obtained and started by calling the preset CommandLineRunner interface in the Spring program. Specifically, Spring provides the CommandLineRunner interface, and developers can implement this interface to customize what to do when the Spring program starts. By implementing the CommandLineRunner interface and adding the detection program, the Spring program can execute the preset detection program when starting.
[0028] Step S102: Obtain the Mapper object in the Spring program and perform detection based on the detection rules set in the detection program according to the Mapper object.
[0029] Step S103: If there is a situation of missing SQL during the detection process, an abnormal result is returned, and the startup of the Spring program is stopped.
[0030] In one implementation, after starting the detection program, all Mapper objects can be collected. Since in a Mybatis-Plus-based project, the database is usually accessed through Mapper objects, and these Mapper objects all inherit from the baseMapper provided by Mybatis-Plus. All Mapper objects in the Mybatis-Plus project will be hosted in Spring. Based on the automatic injection function of Spring, that is, through the Resource annotation provided by Spring, Spring can collect all Mapper objects. Based on this, in the embodiments of the present invention, when obtaining Mapper objects in the Spring program, the Mapper objects in the Spring program can be obtained through the Resource annotation of the Spring program.
[0031] Further, according to the detection rules set in the detection program, each Mapper object is executed cyclically. If there is no situation of missing SQL, the execution process is normal; if there is a situation of missing SQL, an abnormal result will be returned, and the startup of the Spring program will be stopped.
[0032] The above-mentioned detection method for preventing missing SQL provided by the present invention can execute the detection program when starting the Spring program, and detect whether there is a situation of missing SQL based on Mapper objects. If so, the startup of the Spring program is stopped, so as to avoid program errors caused by missing SQL when the requirements are put on the line.
[0033] In one implementation, for the aforementioned step S102, that is, when detecting according to the detection rules set in the detection program based on Mapper objects, the following methods can be adopted including but not limited to: performing a database query based on the Mapper object, and judging whether there is a situation of missing SQL based on the database query result.
[0034] In specific implementation, the selectList method of each Mapper object is executed cyclically; if there is no situation of missing SQL, the first record of the actual table mapped by the Mapper object is obtained; if there is a situation of missing SQL, the SelectList method of the Mapper object cannot be executed, and the database returns a detection abnormal result.
[0035] Loop through the MapperList (i.e., the list of all Mapper objects), and execute the SelectList method of each Mapper object with the input parameter of limit 1. Under normal circumstances, if the code execution has no exceptions, it will return the first record of the actual table mapped by the Mapper object; if there is a missing SQL situation, since the database does not add fields, the database will return an error message without fields, and the code execution will throw an exception, which will continue to be thrown up to the upper layer until the Spring program catches the exception and stops starting.
[0036] The example code is as follows: for (BaseMapper baseMapper : mapperList) { try { baseMapper.selectList(new LambdaQueryWrapper<>().last("limit 1")); } catch (Exception e) { log.error("sql check fail", e); throw e; }。
[0037] In one implementation, the above method further includes: generating an error log during the execution of the detection program to prompt developers of missing SQL.
[0038] In specific implementation, the Spring program can execute the detection program at startup. When the detection fails, the Spring program will fail to start due to execution exceptions and generate an error log. Developers can learn about the situation of missing SQL by checking the error log.
[0039] The above method provided by the embodiments of the present invention adds a detection program to the Spring program. When it detects missing SQL, it can prevent the Spring program from starting and prompt developers of the situation of missing SQL in the error log, thereby avoiding program errors caused by missing SQL when the requirements are put online.
[0040] For the detection method for preventing missing SQL provided in the foregoing embodiments, the embodiments of the present invention also provide a detection device for preventing missing SQL. Refer to Figure 2 the structural schematic diagram of a detection device for preventing missing SQL shown in The detection program startup module 201 is used to start a preset detection program when starting the Spring program; The detection module 202 is used to obtain the Mapper objects in the Spring program and perform detection based on the detection rules set in the detection program according to the Mapper objects. The result feedback module 203 is used to return an abnormal result and stop starting the Spring program if there is a situation of missing SQL statements during the detection process.
[0041] The above detection device for preventing missing SQL statements provided by the present invention can execute the detection program when starting the Spring program, detect whether there is a situation of missing SQL statements based on the Mapper objects, and if so, stop starting the Spring program, thereby avoiding program errors caused by missing SQL statements when the requirements are put on the line.
[0042] In one implementation manner, the above detection program startup module 201 is specifically used to: obtain and start a preset detection program by calling the preset CommandLineRunner interface in the Spring program.
[0043] In one implementation manner, the above detection module 202 is specifically used to: obtain the Mapper objects in the Spring program through the Resource annotation of the Spring program.
[0044] In one implementation manner, the above detection module 202 is specifically used to: perform a database query based on the Mapper objects and determine whether there is a situation of missing SQL statements based on the database query results.
[0045] In one implementation manner, the above detection module 202 is specifically used to: loop and execute the selectList method of each Mapper object; if there is no situation of missing SQL statements, obtain the first record of the actual table mapped by the Mapper object; if there is a situation of missing SQL statements, the SelectList method of the Mapper object cannot be executed, and the database returns a detection abnormal result.
[0046] In one implementation manner, the above device further includes: a log module, which is used to generate error logs during the execution of the detection program to prompt developers of missing SQL statements.
[0047] It should be noted that for the device provided in the embodiments of the present invention, the implementation principle and the technical effects generated are the same as those in the foregoing method embodiments. For a brief description, for the parts not mentioned in the device embodiments, reference may be made to the corresponding content in the foregoing method embodiments.
[0048] An embodiment of the present invention further provides an electronic device. Specifically, the electronic device includes a processor and a storage device; a computer program is stored on the storage device, and when the computer program is run by the processor, it executes the method described in any one of the above embodiments.
[0049] Figure 3 FIG. 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. The electronic device 100 includes: a processor 30, a memory 31, a bus 32, and a communication interface 33. The processor 30, the communication interface 33, and the memory 31 are connected through the bus 32. The processor 30 is used to execute an executable module stored in the memory 31, such as a computer program.
[0050] Among them, the memory 31 may include a high-speed random access memory (RAM, Random Access Memory), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 33 (which can be wired or wireless), a communication connection is realized between the system network element and at least one other network element, and the Internet, wide area network, local area network, metropolitan area network, etc. can be used.
[0051] The bus 32 may be an ISA bus, a PCI bus, an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 3 only a bidirectional arrow is used in FIG. 4, but it does not mean that there is only one bus or one type of bus.
[0052] Among them, the memory 31 is used to store a program. After receiving an execution instruction, the processor 30 executes the program. The method executed by the device defined by the flow process disclosed in any one of the above embodiments of the present invention can be applied to the processor 30 or implemented by the processor 30.
[0053] The processor 30 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above method can be completed by the integrated logic circuit of the hardware in the processor 30 or the instructions in the form of software. The above-mentioned processor 30 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present invention can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 31, and the processor 30 reads the information in the memory 31 and combines its hardware to complete the steps of the above method.
[0054] The computer program product of the readable storage medium provided by the embodiments of the present invention includes a computer-readable storage medium storing program code, and the instructions included in the program code can be used to execute the method described in the foregoing method embodiments. For the specific implementation, reference can be made to the foregoing method embodiments, which will not be elaborated herein.
[0055] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0056] Finally, it should be noted that the above-mentioned embodiments are only specific implementation manners of the present invention, used to illustrate the technical solutions of the present invention, rather than limiting them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions recorded in the foregoing embodiments, or can easily conceive of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A detection method for preventing SQL leakage, characterized in that, Including: When starting the Spring program, start the preset detection program; Obtain the Mapper object in the Spring program, and perform detection based on the Mapper object according to the detection rules set in the detection program; If there is a situation of missing SQL during the detection process, return an abnormal result and stop starting the Spring program.
2. The method according to claim 1, wherein When starting the Spring program, start the preset detection program, including: By calling the preset CommandLineRunner interface in the Spring program, obtain and start the preset detection program.
3. The method according to claim 1, wherein Obtain the Mapper object in the Spring program, including: Obtain the Mapper object in the Spring program through the Resource annotation of the Spring program.
4. The method according to claim 1, wherein Perform detection based on the Mapper object according to the detection rules set in the detection program, including: Perform database query based on the Mapper object, and judge whether there is a situation of missing SQL based on the database query result.
5. The method according to claim 4, wherein Perform database query based on the Mapper object, and judge whether there is a situation of missing SQL based on the database query result, including: Loop to execute the selectList method of each Mapper object; If there is no situation of missing SQL, obtain the first record of the actual table mapped by the Mapper object; If there is a situation of missing SQL, the SelectList method of the Mapper object cannot be executed, and the database returns a detection abnormal result.
6. The method according to claim 1, characterized in that, Also including: During the execution of the detection program, generate an error log to prompt developers of missing SQL.
7. A detection device for preventing SQL leakage, characterized in that, Including: A detection program startup module, used to start the preset detection program when starting the Spring program; A detection module, used to obtain the Mapper object in the Spring program, and perform detection based on the Mapper object according to the detection rules set in the detection program; A result feedback module, used to return an abnormal result and stop starting the Spring program if there is a situation of missing SQL during the detection process.
8. The device according to claim 7, characterized in that, The detection program startup module is specifically used for: By calling the preset CommandLineRunner interface in the Spring program, obtain and start the preset detection program.
9. An electronic device, characterized in that, Including a processor and a memory, the memory stores computer executable instructions that can be executed by the processor, and the processor executes the computer executable instructions to implement the steps of the method according to any one of claims 1 to 6.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is run by the processor, it executes the steps of the method according to any one of claims 1 to 6 above.
Citation Information
Patent Citations
Mybatis framework SQL (Structured Query Language) statement anomaly detection method, server and system
CN114116765A
SQL (Structured Query Language) injection vulnerability positioning detection method and device, electronic equipment and storage medium
CN117056934A
Code scanning method for detecting field difference between Mybatis Mapper XML and database
CN118485057A