Ruby on Rails - 动态SQL查询

Myx*_*tic 6 sql postgresql activerecord ruby-on-rails

我在我的一个控制器中执行以下原始sql查询:

active_users_query = <<-SQL 
       SELECT count(DISTINCT patients.id)
       FROM public.patients, public.subscriptions, public.users, public.calendar_days
       WHERE patients.user_id = users.id 
       AND patients.id = calendar_days.patient_id 
       AND subscriptions.user_id = patients.user_id 
       AND (date_trunc('day',patients.last_sync) > current_date - interval '30 days' 
       OR date_trunc('day', calendar_days.created_at) > current_date - interval '30 days' 
       OR date_trunc('day',users.current_sign_in_at) > current_date - interval '30 days') 
       AND subscriptions.code_id = 2  
SQL
Run Code Online (Sandbox Code Playgroud)

有没有办法可以在这个查询的最后一行添加一些RoR代码来动态生成code_id?

像这样的东西:

AND subscriptions.code_id = '@subscription.code'
Run Code Online (Sandbox Code Playgroud)

dim*_*uch 11

您可以在heredoc字符串中插入Ruby变量

active_users_query = <<-SQL 
       SELECT count(DISTINCT patients.id)
       FROM public.patients, public.subscriptions, public.users, public.calendar_days
       WHERE patients.user_id = users.id 
       AND patients.id = calendar_days.patient_id 
       AND subscriptions.user_id = patients.user_id 
       AND (date_trunc('day',patients.last_sync) > current_date - interval '30 days' 
       OR date_trunc('day', calendar_days.created_at) > current_date - interval '30 days' 
       OR date_trunc('day',users.current_sign_in_at) > current_date - interval '30 days') 
       AND subscriptions.code_id = '#{@subscription.code}'  
SQL
Run Code Online (Sandbox Code Playgroud)

  • 这不会使其容易受到注射吗? (3认同)