首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >将SQL转换为ActiveRecord查询

将SQL转换为ActiveRecord查询
EN

Stack Overflow用户
提问于 2014-03-24 11:07:47
回答 1查看 2.5K关注 0票数 1

如何将以下SQL查询转换为ActiveRecord查询,以减少SQL注入?

代码语言:javascript
复制
jacket_colors ||= [2,21,25,20]
jacket_types = JacketType.find_by_sql(<<-SQL)
  SELECT j2.*, t1.no_count
   FROM jeans j2
   INNER JOIN (
     SELECT
     j1.jean_id AS jean_id,
     COUNT(j1.id) AS no_count
     FROM tracks t
     INNER JOIN jacket_types j1 ON j1.track_id = t.id
     INNER JOIN jeans j2 ON j2.id = j1.jean_id
     WHERE t.status = 0
       AND j1.status IN (#{jacket_colors})
       AND t.type != 'TrekkingTrack'
     GROUP BY j1.jean_id
     HAVING COUNT(j1.id) > 0
   ) t1 ON t1.jean_id = j2.id
 SQL

jacket_types随用户输入而变化。

我尝试了以下操作,但这不起作用,并产生了不正确的SQL。

代码语言:javascript
复制
jacket_colors ||= [2,21,25,20]

Jean.joins(:jacket_types, :track)
.select('jeans.jacket_types_id AS jacket_types_id, COUNT(jeans.id) AS no_count').
where('jeans.status IN (?) AND tracks.status = ? AND tracks.type != ?', jacket_colors, 0, 'TrekkingTrack')
.group('jeans.jacket_types_id')
.having('COUNT(jeans.id) > ?', 0)
.select('jacket_types.*, tracks.no_count').explain
EN

回答 1

Stack Overflow用户

回答已采纳

发布于 2014-03-24 14:48:10

请试试看,我想它会成功的。

Rails查询版本:

代码语言:javascript
复制
jacket_colors ||= [2,21,25,20]

Jean.joins(:jacket_types => :track)
 .where('jeans.status IN (?) AND tracks.status = ? AND tracks.type != ?',
 jacket_colors, 0, 'TrekkingTrack').group('jeans.jacket_types_id')
.select('jacket_types.column1, jacket_types.column2, ....., 
 count(jacket_types) no_count').having("no_count > 0")

代码语言:javascript
复制
jacket_colors ||= [2,21,25,20]
jacket_types = JacketType.find_by_sql(<<-SQL)
  SELECT j2.*, t1.no_count
  FROM jeans j2
    INNER JOIN (
      SELECT
      j1.jean_id AS jean_id,
      COUNT(j1.id) AS no_count
      FROM tracks t
        INNER JOIN jacket_types j1 ON j1.track_id = t.id
        INNER JOIN jeans j2 ON j2.id = j1.jean_id
        WHERE t.status = 0
        AND j1.status IN (#{jacket_colors})
        AND t.type != 'TrekkingTrack'
        GROUP BY j1.jean_id
        HAVING COUNT(j1.id) > 0
   ) t1 ON t1.jean_id = j2.id
 SQL
票数 2
EN
页面原文内容由Stack Overflow提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://stackoverflow.com/questions/22607669

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档