2 回答
TA贡献1871条经验 获得超13个赞
你的意思是如何避免sql注入,比如在运行时连接sql语句?
static final String INVOICE_QUERY = "SELECT inv from Invoice inv WHERE (:createDate IS NULL OR inv.createDate = :createDate) AND (:quantity IS NULL OR inv.quantity = :quantity) AND (:custName IS NULL OR inv.custName = :custName)";
Session session = getHibernateTemplate().getSessionFactory().openSession();
Query query = session.createQuery(INVOICE_QUERY);
query.setDate("createDate", createDate);
if(quantity != null)
query.setLong("quantity", quantity);
else
query.setBigInteger("quantity", null);
if(StringUtils.isNotBlank(custName))
query.setString("custName", custName);
else
query.setString("custName", null);
return query.list();
TA贡献1789条经验 获得超8个赞
您可以查看 CrtitriaAPI 或者您可以通过示例使用休眠功能查询
实际上,如果您使用带有弹簧数据模块的弹簧,您可以查看规格
请查看以下链接:
https://dzone.com/articles/hibernate-query-example-qbe https://vladmihalcea.com/query-entity-type-jpa-criteria-api/ https://spring.io/blog/2011/04 /26/advanced-spring-data-jpa-specifications-and-querydsl/
添加回答
举报