JDBC--代码实现增删改查、及SQL注入问题解决

Startment、PreparedStatement对象详解及SQL注入问题


(1)Statement对象详解

1、提取工具类

#db.properties
dirver=com.mysql.jdbc.Driver
url=jdbc:mysql://localhost:3306/jdbcStudy?useUnicode=true&characterEncoding=utf8&useSSl=true
username=root
password=123456
package com.xiao.lesson02.utils;

import java.io.InputStream;
import java.sql.*;
import java.util.Properties;
//工具类
public class jdbcUtils {
   

    private static String dirver;
    private static String url;
    private static String username;
    private static String password;

    static{
   
        try {
   
            InputStream in = jdbcUtils.class.getClassLoader().getResourceAsStream("db.properties");
            Properties properties = new Properties();
            properties.load(in);

            dirver=properties.getProperty("dirver");
            url=properties.getProperty("url");
            username=properties.getProperty("username");
            password=properties.getProperty("password");

            //驱动只需加载一次
            Class.forName(dirver);

        } catch (Exception e) {
   
            e.printStackTrace();
        }
    }

    //获取连接
    public static Connection getConnection() throws SQLException {
   
       return DriverManager.getConnection(url, username, password);
    }

    //释放资源
    public static void release(Connection conn, Statement st, ResultSet rs) throws SQLException {
   
        if (rs != null) {
   
            rs.close();
        }
        if(st!=null){
   
            st.close();
        }
        if(conn!=null){
   
            conn.close();
        }
    }
}

2、编写增、删、改的方法(executeUpdate()

package com.xiao.lesson02;

import com.xiao.lesson02.utils.jdbcUtils;

import java.sql.Connection;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.sql.Statement;

//插入!!(增)
public class TestInsert {
   
    public static void main(String[] args) throws SQLException {
   
        Connection conn=null;
        Statement st=null;
        ResultSet rs=null;

        try {
   
            conn = jdbcUtils.getConnection();  //获取数据库连接
            st=conn.createStatement();  //创建SQL的执行对象
            String sql="insert into users(`id`,`NAME`,`PASSWORD`,`email`,`birthday`) " +
                    "values(4,'狂神','123456','2675295641@qq.com','2021-06-08')";
             int rows= st.executeUpdate(sql); //执行插入
            if(rows>0){
   
                System.out.println("插入成功!!");
            }
        } catch (SQLException e) {
   
            e.printStackTrace();
        }finally{
   
         jdbcUtils.release(conn,st,rs);
        }
    }
}
package com.xiao.lesson02;

import com.xiao.lesson02.utils.jdbcUtils;

import java.sql.Connection;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.sql.Statement;

//删除
public class TestDelete {
   
    public static void main(String[] args) throws SQLException {
   
        Connection conn=null;
        Statement st=null;
        ResultSet rs=null;

        try
  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
package com.tarena.dingdang.filter; 02 03 import java.io.IOException; 04 import java.util.Enumeration; 05 06 import javax.servlet.Filter; 07 import javax.servlet.FilterChain; 08 import javax.servlet.FilterConfig; 09 import javax.servlet.ServletException; 10 import javax.servlet.ServletRequest; 11 import javax.servlet.ServletResponse; 12 import javax.servlet.http.HttpServletRequest; 13 14 public class AntiSqlInjectionfilter implements Filter { 15 16 public void destroy() { 17 // TODO Auto-generated method stub 18 } 19 20 public void init(FilterConfig arg0) throws ServletException { 21 // TODO Auto-generated method stub 22 } 23 24 public void doFilter(ServletRequest args0, ServletResponse args1, 25 FilterChain chain) throws IOException, ServletException { 26 HttpServletRequest req=(HttpServletRequest)args0; 27 HttpServletRequest res=(HttpServletRequest)args1; 28 //获得所有请求参数名 29 Enumeration params = req.getParameterNames(); 30 String sql = ""; 31 while (params.hasMoreElements()) { 32 //得到参数名 33 String name = params.nextElement().toString(); 34 //System.out.println("name===========================" + name + "--"); 35 //得到参数对应值 36 String[] value = req.getParameterValues(name); 37 for (int i = 0; i < value.length; i++) { 38 sql = sql + value[i]; 39 } 40 } 41 //System.out.println("============================SQL"+sql); 42 //有sql关键字,跳转到error.html 43 if (sqlValidate(sql)) { 44 throw new IOException("您发送请求中的参数中含有非法字符"); 45 //String ip = req.getRemoteAddr(); 46 } else { 47 chain.doFilter(args0,args1); 48 } 49 } 50 51 //效验

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值