From ea121e2ac6f846e85d28db69b0a9a0af308082be Mon Sep 17 00:00:00 2001
From: 潘志宝 <979469083@qq.com>
Date: 星期一, 20 一月 2025 17:59:17 +0800
Subject: [PATCH] Merge remote-tracking branch 'origin/master'

---
 iailab-module-data/iailab-module-data-biz/src/main/java/com/iailab/module/data/ind/data/controller/admin/IndDataSetController.java |    5 +++++
 1 files changed, 5 insertions(+), 0 deletions(-)

diff --git a/iailab-module-data/iailab-module-data-biz/src/main/java/com/iailab/module/data/ind/data/controller/admin/IndDataSetController.java b/iailab-module-data/iailab-module-data-biz/src/main/java/com/iailab/module/data/ind/data/controller/admin/IndDataSetController.java
index bd83fbe..9983515 100644
--- a/iailab-module-data/iailab-module-data-biz/src/main/java/com/iailab/module/data/ind/data/controller/admin/IndDataSetController.java
+++ b/iailab-module-data/iailab-module-data-biz/src/main/java/com/iailab/module/data/ind/data/controller/admin/IndDataSetController.java
@@ -3,6 +3,8 @@
 import com.iailab.framework.common.pojo.CommonResult;
 import com.iailab.framework.common.pojo.PageResult;
 import com.iailab.framework.common.util.object.BeanUtils;
+import com.iailab.framework.idempotent.core.annotation.Idempotent;
+import com.iailab.module.data.common.xss.SQLFilter;
 import com.iailab.module.data.ind.data.entity.IndDataSetEntity;
 import com.iailab.module.data.ind.data.service.IndDataSetService;
 import com.iailab.module.data.ind.data.vo.IndDataSetPageReqVO;
@@ -45,8 +47,10 @@
 
     @PostMapping("/create")
     @Operation(summary = "创建指标数据集")
+    @Idempotent
     @PreAuthorize("@ss.hasPermission('data:ind-data-set:create')")
     public CommonResult<Boolean> create(@Valid @RequestBody IndDataSetSaveReqVO createReqVO) {
+        SQLFilter.sqlInject2(createReqVO.getQuerySql());
         indDataSetService.create(createReqVO);
         return success(true);
     }
@@ -55,6 +59,7 @@
     @Operation(summary = "修改指标数据集")
     @PreAuthorize("@ss.hasPermission('data:ind-data-set:update')")
     public CommonResult<Boolean> update(@Valid @RequestBody IndDataSetSaveReqVO updateReqVO) {
+        SQLFilter.sqlInject2(updateReqVO.getQuerySql());
         indDataSetService.update(updateReqVO);
         return success(true);
     }

--
Gitblit v1.9.3