Skip to content

Commit 1e7724c

Browse files
committed
fix: 引入sqlglot修复sql语句解析异常的问题
1 parent 4e8a84a commit 1e7724c

File tree

4 files changed

+47
-16
lines changed

4 files changed

+47
-16
lines changed

ruoyi-fastapi-backend/config/env.py

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
import sys
44
from dotenv import load_dotenv
55
from functools import lru_cache
6+
from pydantic import computed_field
67
from pydantic_settings import BaseSettings
78
from typing import Literal
89

@@ -51,6 +52,13 @@ class DataBaseSettings(BaseSettings):
5152
db_pool_recycle: int = 3600
5253
db_pool_timeout: int = 30
5354

55+
@computed_field
56+
@property
57+
def sqlglot_parse_dialect(self) -> str:
58+
if self.db_type == 'postgresql':
59+
return 'postgres'
60+
return self.db_type
61+
5462

5563
class RedisSettings(BaseSettings):
5664
"""

ruoyi-fastapi-backend/module_generator/dao/gen_dao.py

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
from sqlalchemy import delete, func, select, text, update
33
from sqlalchemy.ext.asyncio import AsyncSession
44
from sqlalchemy.orm import selectinload
5+
from sqlglot.expressions import Expression
56
from typing import List
67
from config.env import DataBaseConfig
78
from module_generator.entity.do.gen_do import GenTable, GenTableColumn
@@ -75,15 +76,17 @@ async def get_gen_table_all(cls, db: AsyncSession):
7576
return gen_table_all
7677

7778
@classmethod
78-
async def create_table_by_sql_dao(cls, db: AsyncSession, sql: str):
79+
async def create_table_by_sql_dao(cls, db: AsyncSession, sql_statements: List[Expression]):
7980
"""
8081
根据sql语句创建表结构
8182
8283
:param db: orm对象
83-
:param sql: sql语句
84+
:param sql_statements: sql语句的ast列表
8485
:return:
8586
"""
86-
await db.execute(text(sql))
87+
for sql_statement in sql_statements:
88+
sql = sql_statement.sql(dialect=DataBaseConfig.sqlglot_parse_dialect)
89+
await db.execute(text(sql))
8790

8891
@classmethod
8992
async def get_gen_table_list(cls, db: AsyncSession, query_object: GenTablePageQueryModel, is_page: bool = False):

ruoyi-fastapi-backend/module_generator/service/gen_service.py

Lines changed: 32 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,14 @@
11
import io
22
import json
33
import os
4-
import re
54
import zipfile
65
from datetime import datetime
76
from sqlalchemy.ext.asyncio import AsyncSession
7+
from sqlglot import parse as sqlglot_parse
8+
from sqlglot.expressions import Add, Alter, Create, Delete, Drop, Expression, Insert, Table, TruncateTable, Update
89
from typing import List
910
from config.constant import GenConstant
10-
from config.env import GenConfig
11+
from config.env import DataBaseConfig, GenConfig
1112
from exceptions.exception import ServiceException
1213
from module_admin.entity.vo.common_vo import CrudResponseModel
1314
from module_admin.entity.vo.user_vo import CurrentUserModel
@@ -197,10 +198,11 @@ async def create_table_services(cls, query_db: AsyncSession, sql: str, current_u
197198
:param current_user: 当前用户信息对象
198199
:return: 创建表结构结果
199200
"""
200-
if cls.__is_valid_create_table(sql):
201+
sql_statements = sqlglot_parse(sql, dialect=DataBaseConfig.sqlglot_parse_dialect)
202+
if cls.__is_valid_create_table(sql_statements):
201203
try:
202-
table_names = re.findall(r'create\s+table\s+(\w+)', sql, re.IGNORECASE)
203-
await GenTableDao.create_table_by_sql_dao(query_db, sql)
204+
table_names = cls.__get_table_names(sql_statements)
205+
await GenTableDao.create_table_by_sql_dao(query_db, sql_statements)
204206
gen_table_list = await cls.get_gen_db_table_list_by_name_services(query_db, table_names)
205207
await cls.import_gen_table_services(query_db, gen_table_list, current_user)
206208

@@ -211,22 +213,39 @@ async def create_table_services(cls, query_db: AsyncSession, sql: str, current_u
211213
raise ServiceException(message='建表语句不合法')
212214

213215
@classmethod
214-
def __is_valid_create_table(cls, sql: str):
216+
def __is_valid_create_table(cls, sql_statements: List[Expression]):
215217
"""
216218
校验sql语句是否为合法的建表语句
217219
218-
:param sql: sql语句
220+
:param sql_statements: sql语句的ast列表
219221
:return: 校验结果
220222
"""
221-
create_table_pattern = r'^\s*CREATE\s+TABLE\s+'
222-
if not re.search(create_table_pattern, sql, re.IGNORECASE):
223+
validate_create = [isinstance(sql_statement, Create) for sql_statement in sql_statements]
224+
validate_forbidden_keywords = [
225+
isinstance(
226+
sql_statement,
227+
(Add, Alter, Delete, Drop, Insert, TruncateTable, Update),
228+
)
229+
for sql_statement in sql_statements
230+
]
231+
if not any(validate_create) or any(validate_forbidden_keywords):
223232
return False
224-
forbidden_keywords = ['INSERT', 'UPDATE', 'DELETE', 'DROP', 'ALTER', 'TRUNCATE']
225-
for keyword in forbidden_keywords:
226-
if re.search(rf'\b{keyword}\b', sql, re.IGNORECASE):
227-
return False
228233
return True
229234

235+
@classmethod
236+
def __get_table_names(cls, sql_statements: List[Expression]):
237+
"""
238+
获取sql语句中所有的建表表名
239+
240+
:param sql_statements: sql语句的ast列表
241+
:return: 建表表名列表
242+
"""
243+
table_names = []
244+
for sql_statement in sql_statements:
245+
if isinstance(sql_statement, Create):
246+
table_names.append(sql_statement.find(Table).name)
247+
return table_names
248+
230249
@classmethod
231250
async def preview_code_services(cls, query_db: AsyncSession, table_id: int):
232251
"""

ruoyi-fastapi-backend/requirements.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,4 +14,5 @@ PyMySQL==1.1.1
1414
redis==5.2.1
1515
requests==2.32.3
1616
SQLAlchemy[asyncio]==2.0.38
17+
sqlglot[rs]==26.6.0
1718
user-agents==2.2.0

0 commit comments

Comments
 (0)