Tqla是一种轻巧的小型文本解析器,可包裹golang text/template
标准库。tqla的主要目的是解析文本模板,并用占位符替换任何变量。用占位符替换的变量将添加到可以传递给标准db驱动程序的args切片中。
类似的库也暴露于sql注入,因为它们使用文本/模板库进行简单的文本替换。Tqla通过如上所述利用DB占位符来防止sql注入 这里.
当前,tqla不会尝试进行任何sql验证,将来可能会更改。
以下是有关如何使用它的简单示例:
package main
import (
"database/sql"
"log"
"github.com/VauntDev/tqla"
_ "github.com/mattn/go-sqlite3"
)
type todo struct {
Id int
Title string
Description string
Completed bool
}
const db = "example.db"
const todoSchema = `create table if not exists todos (
id integer primary key,
title text not null,
description text not null,
completed boolean default 0
);
`
func main() {
log.Println("connecting to db... ")
db, err := sql.Open("sqlite3", db)
if err != nil {
log.Fatal(err)
}
defer db.Close()
log.Println("creating table is it does not exist... ")
if _, err := db.Exec(todoSchema); err != nil {
log.Fatal(err)
}
todos := []*todo{
{Id: 1, Title: "todo 1", Description: "first todo", Completed: false},
{Id: 2, Title: "todo 2", Description: "second todo", Completed: false},
{Id: 3, Title: "todo 3", Description: "third todo", Completed: false},
{Id: 4, Title: "todo 4", Description: "fourth todo", Completed: false},
{Id: 5, Title: "todo 5", Description: "fith todo", Completed: false},
}
t, err := tqla.New(tqla.WithPlaceHolder(tqla.Dollar))
if err != nil {
log.Fatal(err)
}
log.Println("adding todos...")
insertStmt, insertArgs, err := t.Compile(`
{{ $len := 4 -}}
INSERT INTO 'todos' ('id', 'title', 'description', 'completed')
VALUES {{ range $i, $v := . }}
( {{$v.Id}}, {{$v.Title}}, {{$v.Description}}, {{ $v.Completed }} ){{if lt $i $len}},{{else}};{{end -}}
{{end}}
`, todos)
if err != nil {
log.Fatal(err)
}
if _, err := db.Exec(insertStmt, insertArgs...); err != nil {
log.Fatal(err)
}
log.Println("looking up todo...")
selectStmt, selectArgs, err := t.Compile(`select * from todos where id={{ . }}`, 5)
if err != nil {
log.Fatal(err)
}
todo := &todo{}
row := db.QueryRow(selectStmt, selectArgs...)
if err := row.Scan(&todo.Id, &todo.Title, &todo.Description, &todo.Completed); err != nil {
log.Fatal(err)
}
log.Println("found: ", todo)
}
传送门:tqla