如何限制查询不接收无效字段?无效参数请求返回404页面
解决查询参数限制与404返回问题
我来帮你搞定这两个需求,咱们一步步调整代码:
1. 限制仅接收有效参数值
首先,我们需要先定义哪些type是合法的——你可以选择固定枚举值(适合类型不会频繁变动的场景),或者动态从数据库查询(适合类型会随时更新的场景),然后在控制器里先做参数校验。
2. 查询无结果时返回404
执行完查询后,判断返回的结果数组长度,如果为空就返回404状态码,而不是空数组。
修改后的控制器代码
场景一:固定合法类型列表
如果你的论坛类型是固定的(比如tech、lifestyle、news),直接写死枚举值即可:
function getPosts(req, res) { // 定义所有允许的forum_type值 const allowedTypes = ['tech', 'lifestyle', 'news']; const type = req.params.type; // 第一步:校验参数是否合法 if (!allowedTypes.includes(type)) { return res.status(404).send({ message: '无效的帖子类型' }); } // 执行查询(这里把隐式连接改成显式JOIN,更规范) posts.sequelize.query( "SELECT forum.id, forum.forum_type, posts.id, posts.post_topic_author_id, posts.post_topic_title, posts.forum_type_id FROM posts JOIN forum ON posts.forum_type_id = forum.id WHERE forum.forum_type = ?", { replacements: [type], type: posts.sequelize.QueryTypes.SELECT } ) .then(foundPosts => { // 第二步:判断查询结果是否为空 if (foundPosts.length === 0) { return res.status(404).send({ message: '该类型下暂无帖子' }); } // 有结果则正常返回 res.status(200).send({ posts: foundPosts }); }) .catch(err => { res.status(500).send({ message: 'Ocurrio un error: ' + err }); }); }
场景二:动态从数据库获取合法类型
如果论坛类型是在forum表中动态维护的,我们可以先查询所有有效的类型再校验:
// 改成async函数方便异步操作 async function getPosts(req, res) { const type = req.params.type; try { // 从forum表获取所有有效的forum_type const validTypes = await posts.sequelize.models.forum.findAll({ attributes: ['forum_type'], raw: true }).then(types => types.map(item => item.forum_type)); // 校验参数合法性 if (!validTypes.includes(type)) { return res.status(404).send({ message: '无效的帖子类型' }); } // 执行查询 const foundPosts = await posts.sequelize.query( "SELECT forum.id, forum.forum_type, posts.id, posts.post_topic_author_id, posts.post_topic_title, posts.forum_type_id FROM posts JOIN forum ON posts.forum_type_id = forum.id WHERE forum.forum_type = ?", { replacements: [type], type: posts.sequelize.QueryTypes.SELECT } ); // 判断结果是否为空 if (foundPosts.length === 0) { return res.status(404).send({ message: '该类型下暂无帖子' }); } res.status(200).send({ posts: foundPosts }); } catch (err) { res.status(500).send({ message: 'Ocurrio un error: ' + err }); } }
额外优化:路由层参数校验(可选)
如果你的合法类型是固定的,也可以在路由层直接用正则限制参数格式,提前拦截无效请求:
const postsController = require('../controllers').posts; module.exports = (app) => { app.post('/api/post-create', postsController.create); app.put('/api/post-update/:id', postsController.update); // 仅允许tech/lifestyle/news三种类型的参数 app.get('/api/post-get/:type(tech|lifestyle|news)', postsController.getPosts); }
这样修改后:
- 当用户输入不存在的
type参数时,会直接返回404 - 当
type合法但没有对应帖子时,也会返回404而不是空数组
内容的提问来源于stack exchange,提问作者JuanP Moreno
相关产品推荐
相关产品推荐

