From 39cbf62517d3473803aeb9bfa4c08e5ec5ee8477 Mon Sep 17 00:00:00 2001 From: wangwei Date: Thu, 23 May 2019 15:17:27 +0800 Subject: [PATCH] =?UTF-8?q?=E5=AE=8C=E5=96=84=E5=AD=97=E5=85=B8=E8=A1=A8?= =?UTF-8?q?=E6=95=B0=E6=8D=AE=E6=8F=92=E5=85=A5sql=E8=AF=AD=E5=8F=A5?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../resources/sql/20190521/insert_dict.sql | 38 ++++++++----------- 1 file changed, 16 insertions(+), 22 deletions(-) diff --git a/src/main/resources/sql/20190521/insert_dict.sql b/src/main/resources/sql/20190521/insert_dict.sql index 8b6108b01..6eaad5184 100644 --- a/src/main/resources/sql/20190521/insert_dict.sql +++ b/src/main/resources/sql/20190521/insert_dict.sql @@ -1,36 +1,30 @@ -#劫持相关字典表 insert语句中的156即dictionary_id应替换为select筛选后中id字段的值 +#劫持相关字典表 INSERT INTO `sys_data_dictionary_name`(`module_name`, `mark`, `remark`, `revision`, `create_time`, `modify_time`, `status`) VALUES ('劫持文件内容格式', 'CONTENT_TYPE_HIJACK', 'hijack content-type', '', '2019-05-21 00:00:00', '2019-05-21 00:00:00', 1); -SELECT * FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK'; - INSERT into sys_data_dictionary_item(item_code,item_value,item_sort,`status`,type,dictionary_id) -VALUES('image/gif','image/gif',0,1,1,156), -('image/jpeg','image/jpeg',0,1,1,156), -('image/png','image/png',0,1,1,156), -('image/svg+xml','image/svg+xml',0,1,1,156), -('application/x-msdos-program','application/x-msdos-program',0,1,1,156), -('application/x-msdownload','application/x-msdownload',0,1,1,156), -('application/octet-stream','application/octet-stream',0,1,1,156), -('application/vnd.android.package-archive','application/vnd.android.package-archive',0,1,1,156), -('text/html','text/html',0,1,1,156); +VALUES('image/gif','image/gif',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('image/jpeg','image/jpeg',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('image/png','image/png',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('image/svg+xml','image/svg+xml',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('application/x-msdos-program','application/x-msdos-program',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('application/x-msdownload','application/x-msdownload',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('application/octet-stream','application/octet-stream',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('application/vnd.android.package-archive','application/vnd.android.package-archive',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')), +('text/html','text/html',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK')); -#文件策略相关字典表 insert语句中的157即dictionary_id应替换为select筛选后中id字段的值 +#文件策略相关字典表 INSERT INTO `sys_data_dictionary_name`(`module_name`, `mark`, `remark`, `revision`, `create_time`, `modify_time`, `status`) VALUES('文件策略内容格式', 'CONTENT_TYPE_FILESTRATEGY', 'fileStrategy content-type', '', '2019-05-21 00:00:00', '2019-05-21 00:00:00', 1); -SELECT * FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_FILESTRATEGY'; - INSERT into sys_data_dictionary_item(item_code,item_value,item_sort,`status`,type,dictionary_id) -VALUES('template','template',0,1,1,157), -('html','html',0,1,1,157); +VALUES('template','template',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_FILESTRATEGY')), +('html','html',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_FILESTRATEGY')); -#注入脚本相关字典表 insert语句中的158即dictionary_id应替换为select筛选后中id字段的值 +#注入脚本相关字典表 INSERT INTO `sys_data_dictionary_name`(`module_name`, `mark`, `remark`, `revision`, `create_time`, `modify_time`, `status`) VALUES('注入脚本文件内容格式', 'CONTENT_TYPE_INSERTSCRIPT', 'insertScript content-type', '', '2019-05-21 00:00:00', '2019-05-21 00:00:00', 1); -SELECT * FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_INSERTSCRIPT'; - INSERT into sys_data_dictionary_item(item_code,item_value,item_sort,`status`,type,dictionary_id) -VALUES('css','css',0,1,1,158), -('js','js',0,1,1,158); \ No newline at end of file +VALUES('css','css',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_INSERTSCRIPT')), +('js','js',0,1,1,(SELECT id FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_INSERTSCRIPT')); \ No newline at end of file