Hibernate uses several solutions to prevent SQL injection, hibernatesql
Several solutions to prevent SQL Injection in Hibernate
Hibernate is an open-source object relationship ing framework that encapsulates JDBC objects in a lightweight manner, so that Java programmers can use the object programming thinking to manipulate the database as they wish.
While obtaining convenient operations, the problem of SQL Injection deserves our close attention. The following describes how to avoid SQL injection:
1. Bind the parameter name:
Query query=session.createQuery(hql);query.setString(“name”,name);
2. Specify the parameter location:
Query query=session.createQuery(hql);query.setString(0,name1);query.setString(1,name2);...
3. setParameter () method:
Query query=session.createQuery(hql); query.setParameter(“name”,name,Hibernate.STRING);
4. setProperties () method:
Entity entity=new Entity();entity.setXx(“xx”);entity.setYy(100);Query query=session.createQuery(“from Entity c where c.xx=:xx and c.yy=:yy ”); query.setProperties(entity);
5. HQL splicing method,This method is the most commonly used method and is easy to ignore and easy to inject. It is usually used to filter out special characters of parameters. We recommend that you use the StringEscapeUtils of the Spring toolkit. the escapeSql () method filters parameters:
public static void main(String[] args) { String str = StringEscapeUtils.escapeSql("'"); System.out.println(str);}
Output result :''
Thank you for reading this article. I hope it will help you. Thank you for your support for this site!