From 5a360c5a74438ac89db84b70ed3839f3ca19b39a Mon Sep 17 00:00:00 2001 From: sgjj <995959152@qq.com> Date: Tue, 22 Sep 2020 10:06:42 +0800 Subject: [PATCH] =?UTF-8?q?=E6=90=9C=E7=B4=A2=E5=88=86=E9=A1=B5=E5=88=87?= =?UTF-8?q?=E6=8D=A2=E4=B8=A4=E6=AC=A1=E9=97=AE=E9=A2=98=E3=80=81=E6=96=87?= =?UTF-8?q?=E7=AB=A0=E7=AE=A1=E7=90=86=E7=88=B6=E7=BA=A7=E6=A0=8F=E7=9B=AE?= =?UTF-8?q?=E4=B8=8D=E6=98=BE=E7=A4=BA=E5=AD=90=E6=A0=8F=E7=9B=AE=E6=96=87?= =?UTF-8?q?=E7=AB=A0=E9=97=AE=E9=A2=98?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/main/java/net/mingsoft/cms/action/web/MCmsAction.java | 6 +++--- src/main/java/net/mingsoft/cms/dao/IContentDao.xml | 3 ++- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/src/main/java/net/mingsoft/cms/action/web/MCmsAction.java b/src/main/java/net/mingsoft/cms/action/web/MCmsAction.java index 2fcbea2d..061e1594 100644 --- a/src/main/java/net/mingsoft/cms/action/web/MCmsAction.java +++ b/src/main/java/net/mingsoft/cms/action/web/MCmsAction.java @@ -385,7 +385,9 @@ public class MCmsAction extends net.mingsoft.cms.action.BaseAction { //sql注入过滤 searchMap.put(k,v.toString().replaceAll("('|\"|\\\\)","\\\\$1")); searchMap.put(k,clearXss(searchMap.get(k).toString())); - urlParams.append(k).append("=").append(searchMap.get(k)).append("&"); + if(!ParserUtil.SIZE.equals(k)&&!ParserUtil.PAGE_NO.equals(k)){ + urlParams.append(k).append("=").append(searchMap.get(k)).append("&"); + } }); //查询数量 @@ -429,8 +431,6 @@ public class MCmsAction extends net.mingsoft.cms.action.BaseAction { page.setPreUrl(preUrl); page.setLastUrl(lastUrl); - searchMap.put(ParserUtil.PAGE_NO, pageNo); - //解析后的内容 String content = ""; try { diff --git a/src/main/java/net/mingsoft/cms/dao/IContentDao.xml b/src/main/java/net/mingsoft/cms/dao/IContentDao.xml index 2726a0a2..4b153a9f 100644 --- a/src/main/java/net/mingsoft/cms/dao/IContentDao.xml +++ b/src/main/java/net/mingsoft/cms/dao/IContentDao.xml @@ -225,7 +225,8 @@ ct.del=0 and content_title like CONCAT('%',#{contentTitle},'%') - and content_category_id=#{contentCategoryId} + and (content_category_id=#{contentCategoryId} or content_category_id in + (select id FROM cms_category where )) and content_type LIKE CONCAT('%',#{contentType},'%') and content_display=#{contentDisplay} and content_author=#{contentAuthor}