duanji1026 2016-01-31 05:27
浏览 92

MySQL MATCH查询的格式化字符串

I'm trying to construct a MySQL fulltext search query from user input, but I'm confused as how to best format it for insertion into the prepared statement the sql module creates. Essentially right now I'm taking the term, splitting it on spaces, and creating a slice with the words. Then I format the slice parts with a + in front. So right now the input will look like "+my +cool +search"

A small snippet example

terms := strings.Split(strings.TrimSpace("my cool search"), " ")

var searchquery []string

for _, term := range terms {
    searchquery = append(searchquery, fmt.Sprintf("+%s", term))
}

dbase.Query(`SELECT blah FROM blah WHERE blah
AND MATCH(title) AGAINST (? IN BOOLEAN MODE)`, strings.Join(searchquery, " "))

The problem is it doesn't seem to escape characters the way I'd expect, because the IN BOOLEAN MODE has certain special operators like the +, -, >, < symbols. If a user inserts any of those characters it messes up the search. I've read you need to enclose terms with double quotes, but does that mean the sql driver isn't doing it when it inserts the parameter? It's ambiguous as to what the '?' is being replaced with, I guess.

I haven't been able to find many examples of how to dynamically construct these types of queries on the internet either, so maybe theres a completely better way to do it in general? Thanks!

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥20 测距传感器数据手册i2c
    • ¥15 RPA正常跑,cmd输入cookies跑不出来
    • ¥15 求帮我调试一下freefem代码
    • ¥15 matlab代码解决,怎么运行
    • ¥15 R语言Rstudio突然无法启动
    • ¥15 关于#matlab#的问题:提取2个图像的变量作为另外一个图像像元的移动量,计算新的位置创建新的图像并提取第二个图像的变量到新的图像
    • ¥15 改算法,照着压缩包里边,参考其他代码封装的格式 写到main函数里
    • ¥15 用windows做服务的同志有吗
    • ¥60 求一个简单的网页(标签-安全|关键词-上传)
    • ¥35 lstm时间序列共享单车预测,loss值优化,参数优化算法