存在注入风险的写法 QueryWrapper queryWrapper = new QueryWrapper(); queryWrapper.inSql("id","select goods_id from t_goods where goods_name like '%"+dto.getGoodsName()+"%'"