2 回答
TA贡献1851条经验 获得超4个赞
根据您的环境,您还应该转义查询值。如果您使用 mysql,您应该可以使用以下内容:
app.post('/visitors/store', (req, res) => {
const name = req.body.name;
const company = req.body.company;
con.query("INSERT INTO visitors(name, company) VALUES(?,?)", [name, company], (results) => {
res.json(results);
});
或不转义:
app.post('/visitors/store', (req, res) => {
const name = req.body.name;
const company = req.body.company;
con.query(`INSERT INTO visitors(name, company) VALUES(${name}, ${company})`, (results) => {
res.json(results);
});
TA贡献1802条经验 获得超5个赞
只需停止查询字符串并在其中包含实际变量:
app.post('/visitors/store', (req, res) => {
const name = req.body.name;
const company = req.body.company;
con.query("INSERT INTO visitors(name, company) VALUES('" + name + "','" + company + "')", (results) => {
res.json(results);
});
});
- 2 回答
- 0 关注
- 76 浏览
添加回答
举报