diff --git a/Src/Asp.Net/SqlSugar/Utilities/DbExtensions.cs b/Src/Asp.Net/SqlSugar/Utilities/DbExtensions.cs index 1a2b9c8c4..542cd3e03 100644 --- a/Src/Asp.Net/SqlSugar/Utilities/DbExtensions.cs +++ b/Src/Asp.Net/SqlSugar/Utilities/DbExtensions.cs @@ -68,7 +68,7 @@ namespace SqlSugar { if (value != null) { - if (value.IsContainsIn(";", "--")) + if (value.IsContainsIn(";", "--")) { throw new Exception($"{value} format error "); } @@ -76,6 +76,15 @@ namespace SqlSugar { throw new Exception($"{value} format error "); } + else if (value.ToLower().Contains(" update ") + || value.ToLower().Contains(" delete ") + || value.ToLower().Contains(" drop ") + || value.ToLower().Contains(" alert ") + || value.ToLower().Contains(" create ") + || value.ToLower().Contains(" insert ")) + { + Check.ExceptionEasy($"{value} format error ", value+ "不能存在 空格+【update drop 等】+空格 "); + } } return value; }