2 回答

TA貢獻1871條經驗 獲得超13個贊
你的意思是如何避免sql注入,比如在運行時連接sql語句?
static final String INVOICE_QUERY = "SELECT inv from Invoice inv WHERE (:createDate IS NULL OR inv.createDate = :createDate) AND (:quantity IS NULL OR inv.quantity = :quantity) AND (:custName IS NULL OR inv.custName = :custName)";
Session session = getHibernateTemplate().getSessionFactory().openSession();
Query query = session.createQuery(INVOICE_QUERY);
query.setDate("createDate", createDate);
if(quantity != null)
query.setLong("quantity", quantity);
else
query.setBigInteger("quantity", null);
if(StringUtils.isNotBlank(custName))
query.setString("custName", custName);
else
query.setString("custName", null);
return query.list();

TA貢獻1789條經驗 獲得超8個贊
您可以查看 CrtitriaAPI 或者您可以通過示例使用休眠功能查詢
實際上,如果您使用帶有彈簧數據模塊的彈簧,您可以查看規格
請查看以下鏈接:
https://dzone.com/articles/hibernate-query-example-qbe https://vladmihalcea.com/query-entity-type-jpa-criteria-api/ https://spring.io/blog/2011/04 /26/advanced-spring-data-jpa-specifications-and-querydsl/
添加回答
舉報