模糊查询 like 语句该怎么写?

 

 1  Java 代码中添加 sql 通配符

string wildcardname = “%smi%”;

list<name> names = mapper.selectlike(wildcardname);

<select id=”selectlike”>

select * from foo where bar like #{value}

</select>

 2  sql 语句中拼接通配符会引起 sql 注入 

string wildcardname = “smi”;

list<name> names = mapper.selectlike(wildcardname);

<select id=”selectlike”>

select * from foo where bar like "%"#{value}"%"

</select>

posted @ 2020-11-17 20:06  咔啡  阅读(328)  评论(0编辑  收藏  举报