zoukankan      html  css  js  c++  java
  • PreparedStatement解决sql注入问题

    总结 PreparedStatement解决sql注入问题
    :sql中使用?做占位符
    2.得到PreparedStatement对象
    PreparedStatement pst=conn.prepareStatement(String sql);
    pst.setString(1,"aaa");//设置 第一个?的占位符赋值
    pst.setString(2,"bbb");
     
     
     
    // 查找用户 使用PreparedStatement 解决了 sql注入问题
         public User findUser(User user) {
               String sql = "select * from user where username='?' and password='?'";
               Connection conn = null;
               PreparedStatement pst = null;
               ResultSet rs = null;
                try {
                    conn = jdbcUtils. getConnection();
                    pst = conn.prepareStatement(sql);
                    pst.setString(1, user.getUsername());
                    pst.setString(2, user.getPassword());
                    rs = pst.executeQuery();
                     if (rs.next()) {
                         User u = new User();
                         u.setId(rs.getInt( "id"));
                         u.setUsername(rs.getString( "username"));
                         u.setPassword(rs.getString( "password"));
                         u.setEmail(rs.getString( "email"));
                          return u;
                    }
               } catch (Exception e) {
                     // TODO Auto-generated catch block
                    e.printStackTrace();
               }
                return null;
         }
  • 相关阅读:
    使用自己的key对app进行签名
    pl/sql中文乱码解决办法
    Oracle存储过程中创建表的权限
    pl/sql中获得sql语句执行后影响的行数
    申请Android Map APIKey
    vs快捷键
    ODAC安装配置与使用详解
    .net不安装Oracle11g客户端直接使用ODAC
    android通过USB使用真机调试程序
    pl/sql中实现字符串分割
  • 原文地址:https://www.cnblogs.com/haofaner/p/5652757.html
Copyright © 2011-2022 走看看