Get the App
SLTechnology News&Howtos  ›  Network Security  › 

The difference between ${} and # {} in mybatis

Shulou Source: shulou.com Published: 2022-06-01 04:03:47 10月06日 Update

When writing xml files in mybatis, we often encounter the input of parameters to summarize the difference between ${} and # {}:

1.# {} effectively prevent sql injection

# {} what is passed directly is that your parameter value will not be added ""

2. ${} order by sorting must use ${} for example: order by ${id}

${} cannot prevent sql injection without precompiled sql statements

${} will automatically add "".

Summary: it is best to use # {} for security reasons

Tags: Parameters valid security file best statement sort compile Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info Docker Microsoft Xiaomi Huawei