mirror of
https://github.com/go-admin-team/go-admin.git
synced 2026-09-29 04:27:17 +00:00
Get and Update found their row with First(&model, id). GORM reads a string passed that way as a SQL condition rather than a key, so with a string primary key the path parameter went into the WHERE clause as written: "c-1" failed as the expression c - 1, and GET /…/1=1 returned a row. Both now filter on clause.PrimaryColumn with the id as a bound value, which GORM resolves to the model's own quoted key column whatever it is called. Delete keeps Delete(&model, ids): a slice is always taken as key values.