SQL错误[42601]:错误:“ 0”或附近的语法错误

时间:2018-09-18 05:37:25

标签: sql postgresql plpgsql dblink

我无法理解ti如何通过select生成数组,并且出现错误

  

SQL错误[42601]:错误:语法错误在“ 0”或附近,在名为“未命名”的dblink连接上发生错误:无法执行查询。

create temporary table house_address as
   (SELECT full_address
    FROM dblink('db_d',
         'drop table if exists _x17092018;
             create temporary table _x17092018 (
             guid character varying,
             full_address character varying,
             address_guid character varying
          ); 
          do $$
             declare
                guids_list character varying[]
                   := ''{(''' ||
                      (SELECT STRING_AGG(DISTINCT guid, ''', ''')
                       FROM lc) ||
                      ''')}'';
                r character varying;
             begin
                foreach r in array guids_list 
                loop
                   insert into _x17092018
                      select r, t.*
                      FROM sm.func_by_houseid(r, TRUE, ''db'') as t;
                end loop;
             END$$;'
         ) AS addr(full_address TEXT)
   );

1 个答案:

答案 0 :(得分:1)

错误必须来自guids_list的初始化。

它的书写方式会以类似的方式出现

{[guid1', 'guid ' containing spaces and quote', 'guid3]}

这显然不是您想要的。此外,正如我试图演示的那样,它可以进行SQL注入。

您可以使用类似的

'guids_list character varying[] := ' ||
   (SELECT quote_literal(array_agg(DISTINCT guid)) FROM lc) || ';'