MyBatis # 与 $

版权声明:本文为博主原创文章,未经博主允许不得转载。 https://blog.csdn.net/cszhang570221322/article/details/83903107

status:1

ids:(1,2,3)

  eg.1

UPDATE answer_student SET status=#{status} WHERE  studentNumber  in  #{ids}
UPDATE answer_student SET status="1" WHERE  studentNumber  in  "(1)";

 会报错

eg.2

UPDATE answer_student SET status=#{status} WHERE  studentNumber  in  ${ids}
UPDATE answer_student SET status="1" WHERE  studentNumber  in  (1);

 但有sql注入问题

猜你喜欢

转载自blog.csdn.net/cszhang570221322/article/details/83903107