首页 > 代码库 > ibatis order by 防止sql注入
ibatis order by 防止sql注入
(1) 排序控制
select TABLE_NAME, TABLESPACE_NAME from user_tables order by TABLE_NAME $ordertype$
Where the user input ordertype ASC, DESC. On this keyword, use the $ordertype: SQLKEYWORD$ replacement $ ordertype $.
(2)排序字段
sql statement metadata. If the sql statement, there is user input metadata. Table name, field names and so on.
For example the following sql:
select TABLE_NAME, TABLESPACE_NAME from user_tables order by $ orderByColumn $.
Which is the field in the database orderByColumn. Of this metadata, use: $ orderByColumn: METADATA $ replacement $ orderByColumn $.
ibatis order by 防止sql注入
声明:以上内容来自用户投稿及互联网公开渠道收集整理发布,本网站不拥有所有权,未作人工编辑处理,也不承担相关法律责任,若内容有误或涉及侵权可进行投诉: 投诉/举报 工作人员会在5个工作日内联系你,一经查实,本站将立刻删除涉嫌侵权内容。