How should I sanitize database input in Java?

前端 未结 5 2150
我在风中等你
我在风中等你 2020-12-31 07:10

Could someone please point me to a good beginner guide on safely running SQL queries formed partly from user input? I\'m using Java, but a language neutral guide is fine to

5条回答
  •  感情败类
    2020-12-31 07:36

    Normally, you shouldn't create a query concatenating input, but using PreparedStatement instead.

    That lets you specify in which places you'll be setting your parameters inside your query, so Java will take care of sanitizing all inputs for you.

提交回复
热议问题