The difference between ${} and # {} in mybatis
When writing xml files in mybatis, we often encounter the input of parameters to summarize the difference between ${} and # {}:
1.# {} effectively prevent sql injection
# {} what is passed directly is that your parameter value will not be added ""
2. ${} order by sorting must use ${} for example: order by ${id}
${} cannot prevent sql injection without precompiled sql statements
${} will automatically add "".
Summary: it is best to use # {} for security reasons