fix: escape 'key' as reserved word in all MySQL queries with backticks

This commit is contained in:
2026-06-20 23:21:24 +08:00
parent 99fb89c60d
commit 735126ff56
7 changed files with 22 additions and 22 deletions
+2 -2
View File
@@ -60,7 +60,7 @@ func (h *ReviewHandler) Review(c *gin.Context) {
topN = *req.TopN
} else {
var topNStr string
h.db.QueryRow(`SELECT value FROM user_settings WHERE user_id = ? AND key = 'review.top_n'`, user.ID).Scan(&topNStr)
h.db.QueryRow("SELECT value FROM user_settings WHERE user_id = ? AND `key` = 'review.top_n'", user.ID).Scan(&topNStr)
if topNStr != "" {
if n, err := strconv.Atoi(topNStr); err == nil && n > 0 {
topN = n
@@ -74,7 +74,7 @@ func (h *ReviewHandler) Review(c *gin.Context) {
concurrency = *req.Concurrency
} else {
var concStr string
h.db.QueryRow(`SELECT value FROM user_settings WHERE user_id = ? AND key = 'review.concurrency'`, user.ID).Scan(&concStr)
h.db.QueryRow("SELECT value FROM user_settings WHERE user_id = ? AND `key` = 'review.concurrency'", user.ID).Scan(&concStr)
if concStr != "" {
if n, err := strconv.Atoi(concStr); err == nil && n > 0 {
concurrency = n