预编译SQL更安全高效(能防止SQL注入)

PreparedStatement pstmt = conn.prepareStatement("SELECT * FROM user WHERE username = ? AND password = ?");
pstmt.setString(1, "daqiao"); 
pstmt.setString(2, "123456");
ResultSet resultSet = pstmt.executeQuery();

 

posted @ 2025-08-07 17:04  休玛  阅读(4)  评论(0)    收藏  举报