如何在不重写多个SQL语句的情况下查询(SQL)数量可变的用户输入

问题描述 投票:0回答:1

我正在创建一个Web应用程序(使用Flask),用户可以在其中选择和输入变量,然后将根据所选变量从数据集中产生输出。这些可能的变量可以在下面的html POST表单中看到,并被馈送到后端以允许在其他代码块中看到SQL查询。

我正在遇到的问题,当用户选择某些输入变量但将其他变量留为空白时,查询将返回所有数据。例如,如果从表单的下拉菜单之一中选择了“金融犯罪”的值,但没有填写其他下拉菜单/文本输入,则查询将返回所有可能的结果。而我想要的结果是查询返回具有Category = Financial Crime的所有行。

我知道我可以编写一条if语句,以排除任何带有值''的输入变量,但这将需要针对每个可能的结果重新编写查询,而且我确信必须有一条途径来以更简单,更简单的方式执行此操作优化方式。代码如下,在此先感谢您的任何答复。

HTML:

<form method="POST">

                <div class="row">
                    <div class="col">
                        <p>Enter Company/Product name:</p>
                        <input type="text" name="name" class="form-control">
                    </div>

                    <br><br>

                    <div class="col">
                        <p>Enter Keywords (delimited by comma):</p>
                        <input type="text" name="keywords" class="form-control">
                    </div>

                </div>

                <br>

                <div class="row">
                    <div class="col-sm text-left">
                        <label for="category">Choose a category: </label>
                    <br>
                        <select name="category" id="category">
                            <option value="">Select Category</option>
                            <option value="Financial Crime">Financial Crime</option>
                            <option value="Regulatory Change">Regulatory Change</option>
                        </select>
                    </div>

                    <div class="col-sm text-center">
                        <label for="maturity">Choose maturity: </label>
                    <br>
                        <select name="maturity" id="maturity">
                            <option value="">Select Maturity</option>
                            <option value="Incumbent">Incumbent</option>
                            <option value="Challenger">Challenger</option>
                            <option value="New kid">New kid</option>
                        </select>
                    </div>

                    <div class="col-sm text-right">
                        <label for="under_tech">Choose underlying tech: </label>
                            <br>
                            <select name="under_tech" id="under_tech">
                                <option value="">Select Underlying Tech</option>
                                <option value="AI/ML">AI/ML</option>
                                <option value="Cloud">Cloud</option>
                                <option value="Blockchain">Blockchain</option>
                            </select>
                    </div>
                </div>

                <br><br>
                <div class="row float-right">
                    <input class="btn btn-primary" type="submit" value="Search">
                </div>
            </form>

Python(Flask)/ SQL:

@app.route('/advancedsearch', methods=['GET', 'POST'])
def advancedsearch():
    if request.method == 'POST':
        category = request.form.get('category')
        maturity = request.form.get('maturity')
        under_tech = request.form.get('under_tech')
        keywords = request.form.get('keywords')
        name = request.form.get('name')
        attribs = [name,keywords,category,maturity,under_tech]

        with db.connect() as conn:
            # Query to find products with selected attributes
            qry = """SELECT CompanyName,ProductName,Category,CompanyWebsite,Logo
                    FROM directory_data.full_dataset
                    WHERE Company_description LIKE %s
                    AND Underlying_Tech LIKE %s
                    AND Company_Maturity LIKE %s
                    AND Category LIKE %s
                    AND CompanyName LIKE %s OR ProductName LIKE %s"""
            results = conn.execute(qry, ("%"+attribs[1]+"%","%"+attribs[4]+"%","%"+attribs[3]+"%","%"+attribs[2]+"%","%"+attribs[0]+"%","%"+attribs[0]+"%")).fetchall()

        if results:
            return render_template('advancedsearch.html', results=results, attribs=attribs)
        else:
            error = 'Results not found'
            return render_template('advancedsearch.html', error=error, attribs=attribs)
    return render_template('advancedsearch.html')
python html mysql sql flask
1个回答
0
投票

SQL具有通配符%,表示“匹配所有内容”。

在您的视图中,将其分配为所有缺少或为空的变量的默认值:

category = request.form.get('category') or '%'
maturity = request.form.get('maturity') or '%'
etc.

然后您的查询应该可以根据需要运行。

© www.soinside.com 2019 - 2024. All rights reserved.