diff --git a/server/internal/api/resellers.go b/server/internal/api/resellers.go index 0dd807a..b08e320 100644 --- a/server/internal/api/resellers.go +++ b/server/internal/api/resellers.go @@ -24,6 +24,7 @@ func ResellersHandler(resellerDB *sql.DB) http.Handler { } func (a *ResellersAPI) list(w http.ResponseWriter, r *http.Request) { + creatorsParam := r.URL.Query().Get("creator") q := r.URL.Query().Get("q") limitStr := r.URL.Query().Get("limit") limit := 2000 @@ -32,9 +33,24 @@ func (a *ResellersAPI) list(w http.ResponseWriter, r *http.Request) { limit = n } } - - sql1 := "SELECT id, COALESCE(name,'') AS name FROM reseller WHERE 1=1" + creators := []string{} + for _, s := range strings.Split(creatorsParam, ",") { + s = strings.TrimSpace(s) + if s != "" { + creators = append(creators, s) + } + } + if len(creators) == 0 { + ok(w, r, []map[string]interface{}{}) + return + } + ph := strings.Repeat("?,", len(creators)) + ph = strings.TrimSuffix(ph, ",") + sql1 := "SELECT id, COALESCE(name,'') AS name FROM reseller WHERE creator IN (" + ph + ")" args := []interface{}{} + for _, c := range creators { + args = append(args, c) + } if q != "" { sql1 += " AND (CAST(id AS CHAR) LIKE ? OR name LIKE ?)" like := "%" + q + "%"