This commit is contained in:
DDD1542
2026-01-16 14:48:21 +09:00
4 changed files with 160 additions and 51 deletions

View File

@@ -254,7 +254,10 @@ class DataService {
key !== "limit" &&
key !== "offset" &&
key !== "orderBy" &&
key !== "userLang"
key !== "userLang" &&
key !== "page" &&
key !== "pageSize" &&
key !== "size"
) {
// 컬럼명 검증 (SQL 인젝션 방지)
if (!/^[a-zA-Z_][a-zA-Z0-9_]*$/.test(key)) {