jfinal-club.log 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147
  1. 2021-03-26 12:51:56
  2. [ERROR]-[Thread: XNIO-1 task-4]-[com.jfinal.core.ActionHandler.handle()]: com.jfinal.club._admin.data.wxuser.AdminWxUserController.export() : /admin/wxuser/export?all=0&ids=1000
  3. com.jfinal.plugin.activerecord.ActiveRecordException: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
  4. at com.jfinal.plugin.activerecord.Model.find(Model.java:690)
  5. at com.jfinal.plugin.activerecord.Model.find(Model.java:703)
  6. at com.jfinal.plugin.activerecord.Model.find(Model.java:710)
  7. at com.jfinal.club._admin.data.wxuser.AdminWxUserController.export(AdminWxUserController.java:93)
  8. at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  9. at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
  10. at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
  11. at java.lang.reflect.Method.invoke(Method.java:498)
  12. at com.jfinal.aop.Invocation.invoke(Invocation.java:97)
  13. at com.jfinal.club._admin.admin_interface.ContentPathInterface.intercept(ContentPathInterface.java:20)
  14. at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
  15. at com.jfinal.club._admin.admin_interface.AdminSessionInterface.intercept(AdminSessionInterface.java:40)
  16. at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
  17. at com.jfinal.core.ActionHandler.handle(ActionHandler.java:89)
  18. at com.jfinal.core.JFinalFilter.doFilter(JFinalFilter.java:90)
  19. at io.undertow.servlet.core.ManagedFilter.doFilter(ManagedFilter.java:61)
  20. at io.undertow.servlet.handlers.FilterHandler$FilterChainImpl.doFilter(FilterHandler.java:131)
  21. at io.undertow.servlet.handlers.FilterHandler.handleRequest(FilterHandler.java:84)
  22. at io.undertow.servlet.handlers.security.ServletSecurityRoleHandler.handleRequest(ServletSecurityRoleHandler.java:62)
  23. at io.undertow.servlet.handlers.ServletChain$1.handleRequest(ServletChain.java:68)
  24. at io.undertow.servlet.handlers.ServletDispatchingHandler.handleRequest(ServletDispatchingHandler.java:36)
  25. at io.undertow.servlet.handlers.RedirectDirHandler.handleRequest(RedirectDirHandler.java:68)
  26. at io.undertow.servlet.handlers.security.SSLInformationAssociationHandler.handleRequest(SSLInformationAssociationHandler.java:132)
  27. at io.undertow.servlet.handlers.security.ServletAuthenticationCallHandler.handleRequest(ServletAuthenticationCallHandler.java:57)
  28. at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
  29. at io.undertow.security.handlers.AbstractConfidentialityHandler.handleRequest(AbstractConfidentialityHandler.java:46)
  30. at io.undertow.servlet.handlers.security.ServletConfidentialityConstraintHandler.handleRequest(ServletConfidentialityConstraintHandler.java:64)
  31. at io.undertow.security.handlers.AuthenticationMechanismsHandler.handleRequest(AuthenticationMechanismsHandler.java:60)
  32. at io.undertow.servlet.handlers.security.CachedAuthenticatedSessionHandler.handleRequest(CachedAuthenticatedSessionHandler.java:77)
  33. at io.undertow.security.handlers.AbstractSecurityContextAssociationHandler.handleRequest(AbstractSecurityContextAssociationHandler.java:43)
  34. at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
  35. at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
  36. at io.undertow.servlet.handlers.SessionRestoringHandler.handleRequest(SessionRestoringHandler.java:119)
  37. at io.undertow.servlet.handlers.ServletInitialHandler.handleFirstRequest(ServletInitialHandler.java:269)
  38. at io.undertow.servlet.handlers.ServletInitialHandler.access$100(ServletInitialHandler.java:78)
  39. at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:133)
  40. at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:130)
  41. at io.undertow.servlet.core.ServletRequestContextThreadSetupAction$1.call(ServletRequestContextThreadSetupAction.java:48)
  42. at io.undertow.servlet.core.ContextClassLoaderSetupAction$1.call(ContextClassLoaderSetupAction.java:43)
  43. at io.undertow.servlet.handlers.ServletInitialHandler.dispatchRequest(ServletInitialHandler.java:249)
  44. at io.undertow.servlet.handlers.ServletInitialHandler.access$000(ServletInitialHandler.java:78)
  45. at io.undertow.servlet.handlers.ServletInitialHandler$1.handleRequest(ServletInitialHandler.java:99)
  46. at io.undertow.server.Connectors.executeRootHandler(Connectors.java:376)
  47. at io.undertow.server.HttpServerExchange$1.run(HttpServerExchange.java:830)
  48. at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
  49. at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
  50. at java.lang.Thread.run(Thread.java:748)
  51. Caused by: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
  52. at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:725)
  53. at com.alibaba.druid.wall.WallFilter.connection_prepareStatement(WallFilter.java:253)
  54. at com.alibaba.druid.filter.FilterChainImpl.connection_prepareStatement(FilterChainImpl.java:448)
  55. at com.alibaba.druid.proxy.jdbc.ConnectionProxyImpl.prepareStatement(ConnectionProxyImpl.java:342)
  56. at com.alibaba.druid.pool.DruidPooledConnection.prepareStatement(DruidPooledConnection.java:346)
  57. at sun.reflect.GeneratedMethodAccessor6.invoke(Unknown Source)
  58. at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
  59. at java.lang.reflect.Method.invoke(Method.java:498)
  60. at com.jfinal.plugin.activerecord.SqlReporter.invoke(SqlReporter.java:58)
  61. at com.sun.proxy.$Proxy5.prepareStatement(Unknown Source)
  62. at com.jfinal.plugin.activerecord.Model.find(Model.java:676)
  63. at com.jfinal.plugin.activerecord.Model.find(Model.java:688)
  64. ... 46 more
  65. Caused by: com.alibaba.druid.sql.parser.ParserException: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id
  66. at com.alibaba.druid.sql.parser.SQLParser.printError(SQLParser.java:239)
  67. at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:362)
  68. at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:79)
  69. at com.alibaba.druid.wall.WallProvider.checkInternal(WallProvider.java:620)
  70. at com.alibaba.druid.wall.WallProvider.check(WallProvider.java:574)
  71. at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:712)
  72. ... 57 more
  73. 2021-03-26 12:52:02
  74. [ERROR]-[Thread: XNIO-1 task-2]-[com.jfinal.core.ActionHandler.handle()]: com.jfinal.club._admin.data.wxuser.AdminWxUserController.export() : /admin/wxuser/export?all=0&ids=1000
  75. com.jfinal.plugin.activerecord.ActiveRecordException: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
  76. at com.jfinal.plugin.activerecord.Model.find(Model.java:690)
  77. at com.jfinal.plugin.activerecord.Model.find(Model.java:703)
  78. at com.jfinal.plugin.activerecord.Model.find(Model.java:710)
  79. at com.jfinal.club._admin.data.wxuser.AdminWxUserController.export(AdminWxUserController.java:93)
  80. at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  81. at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
  82. at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
  83. at java.lang.reflect.Method.invoke(Method.java:498)
  84. at com.jfinal.aop.Invocation.invoke(Invocation.java:97)
  85. at com.jfinal.club._admin.admin_interface.ContentPathInterface.intercept(ContentPathInterface.java:20)
  86. at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
  87. at com.jfinal.club._admin.admin_interface.AdminSessionInterface.intercept(AdminSessionInterface.java:40)
  88. at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
  89. at com.jfinal.core.ActionHandler.handle(ActionHandler.java:89)
  90. at com.jfinal.core.JFinalFilter.doFilter(JFinalFilter.java:90)
  91. at io.undertow.servlet.core.ManagedFilter.doFilter(ManagedFilter.java:61)
  92. at io.undertow.servlet.handlers.FilterHandler$FilterChainImpl.doFilter(FilterHandler.java:131)
  93. at io.undertow.servlet.handlers.FilterHandler.handleRequest(FilterHandler.java:84)
  94. at io.undertow.servlet.handlers.security.ServletSecurityRoleHandler.handleRequest(ServletSecurityRoleHandler.java:62)
  95. at io.undertow.servlet.handlers.ServletChain$1.handleRequest(ServletChain.java:68)
  96. at io.undertow.servlet.handlers.ServletDispatchingHandler.handleRequest(ServletDispatchingHandler.java:36)
  97. at io.undertow.servlet.handlers.RedirectDirHandler.handleRequest(RedirectDirHandler.java:68)
  98. at io.undertow.servlet.handlers.security.SSLInformationAssociationHandler.handleRequest(SSLInformationAssociationHandler.java:132)
  99. at io.undertow.servlet.handlers.security.ServletAuthenticationCallHandler.handleRequest(ServletAuthenticationCallHandler.java:57)
  100. at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
  101. at io.undertow.security.handlers.AbstractConfidentialityHandler.handleRequest(AbstractConfidentialityHandler.java:46)
  102. at io.undertow.servlet.handlers.security.ServletConfidentialityConstraintHandler.handleRequest(ServletConfidentialityConstraintHandler.java:64)
  103. at io.undertow.security.handlers.AuthenticationMechanismsHandler.handleRequest(AuthenticationMechanismsHandler.java:60)
  104. at io.undertow.servlet.handlers.security.CachedAuthenticatedSessionHandler.handleRequest(CachedAuthenticatedSessionHandler.java:77)
  105. at io.undertow.security.handlers.AbstractSecurityContextAssociationHandler.handleRequest(AbstractSecurityContextAssociationHandler.java:43)
  106. at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
  107. at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
  108. at io.undertow.servlet.handlers.SessionRestoringHandler.handleRequest(SessionRestoringHandler.java:119)
  109. at io.undertow.servlet.handlers.ServletInitialHandler.handleFirstRequest(ServletInitialHandler.java:269)
  110. at io.undertow.servlet.handlers.ServletInitialHandler.access$100(ServletInitialHandler.java:78)
  111. at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:133)
  112. at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:130)
  113. at io.undertow.servlet.core.ServletRequestContextThreadSetupAction$1.call(ServletRequestContextThreadSetupAction.java:48)
  114. at io.undertow.servlet.core.ContextClassLoaderSetupAction$1.call(ContextClassLoaderSetupAction.java:43)
  115. at io.undertow.servlet.handlers.ServletInitialHandler.dispatchRequest(ServletInitialHandler.java:249)
  116. at io.undertow.servlet.handlers.ServletInitialHandler.access$000(ServletInitialHandler.java:78)
  117. at io.undertow.servlet.handlers.ServletInitialHandler$1.handleRequest(ServletInitialHandler.java:99)
  118. at io.undertow.server.Connectors.executeRootHandler(Connectors.java:376)
  119. at io.undertow.server.HttpServerExchange$1.run(HttpServerExchange.java:830)
  120. at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
  121. at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
  122. at java.lang.Thread.run(Thread.java:748)
  123. Caused by: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
  124. at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:725)
  125. at com.alibaba.druid.wall.WallFilter.connection_prepareStatement(WallFilter.java:253)
  126. at com.alibaba.druid.filter.FilterChainImpl.connection_prepareStatement(FilterChainImpl.java:448)
  127. at com.alibaba.druid.proxy.jdbc.ConnectionProxyImpl.prepareStatement(ConnectionProxyImpl.java:342)
  128. at com.alibaba.druid.pool.DruidPooledConnection.prepareStatement(DruidPooledConnection.java:346)
  129. at sun.reflect.GeneratedMethodAccessor6.invoke(Unknown Source)
  130. at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
  131. at java.lang.reflect.Method.invoke(Method.java:498)
  132. at com.jfinal.plugin.activerecord.SqlReporter.invoke(SqlReporter.java:58)
  133. at com.sun.proxy.$Proxy5.prepareStatement(Unknown Source)
  134. at com.jfinal.plugin.activerecord.Model.find(Model.java:676)
  135. at com.jfinal.plugin.activerecord.Model.find(Model.java:688)
  136. ... 46 more
  137. Caused by: com.alibaba.druid.sql.parser.ParserException: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id
  138. at com.alibaba.druid.sql.parser.SQLParser.printError(SQLParser.java:239)
  139. at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:362)
  140. at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:79)
  141. at com.alibaba.druid.wall.WallProvider.checkInternal(WallProvider.java:620)
  142. at com.alibaba.druid.wall.WallProvider.check(WallProvider.java:574)
  143. at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:712)
  144. ... 57 more