一、模糊查询

1.1、抽象接口

List<Map<String,Object>> selectLIKEUser(Map<String,Object> parmsMap);
复制代码

1.2、xml

<select id="selectLIKEUser" resultType="map" parameterType="map">
        select
               *
        from
             user
        where
            name like "%"#{name}"%"

    </select>
复制代码

1.3、测试类

@Test
    public void selectLIKEUser() {
        SqlSession session = MybatisUtils.getSession();
        UserMapper mapper = session.getMapper(UserMapper.class);
        Map<String,Object> parmsMap = new HashMap<>();
        parmsMap.put("name","面");
        List<Map<String,Object>> resultList = mapper.selectLIKEUser(parmsMap);

        for (Map map: resultList){
            System.out.println(map);
        }
        session.close();
    }
复制代码

1.4、执行结果

mybatis模糊查询(mybatis中的模糊查询是怎样实现的)(1)

mybatis模糊查询(mybatis中的模糊查询是怎样实现的)(2)

二、SQL注入

2.1、#和$的区别

2.2、#和$验证

①我们使用log4j来将SQL执行语句打印在控制台上。

<dependency>
            <groupId>org.apache.logging.log4j</groupId>
            <artifactId>log4j-core</artifactId>
            <version>2.6.1</version>
        </dependency>
复制代码
log4j.rootLogger=DEBUG,console,file

log4j.appender.console = org.apache.log4j.ConsoleAppender
log4j.appender.console.Target = System.out
log4j.appender.console.Threshold=DEBUG
log4j.appender.console.layout = org.apache.log4j.PatternLayout
log4j.appender.console.layout.ConversionPattern=[%c]-%m%n

log4j.appender.file = org.apache.log4j.RollingFileAppender

log4j.appender.file.File=log/tibet.log

log4j.appender.file.MaxFileSize=10mb
log4j.appender.file.Threshold=ERROR
log4j.appender.file.layout=org.apache.log4j.PatternLayout
log4j.appender.file.layout.ConversionPattern=[%p][%d{yy-MM-dd}][%c]%m%n

log4j.logger.org.mybatis=DEBUG
log4j.logger.java.sql=DEBUG
log4j.logger.java.sql.Statement=DEBUG
log4j.logger.java.sql.ResultSet=DEBUG
log4j.logger.java.sql.PreparedStatement=INFO

复制代码
<settings>
        <setting name="logImpl" value="STDOUT_LOGGING"></setting>
    </settings>
复制代码

②SQL-xml

<select id="getUserInfoById" resultType="com.dbright.pojo.User">
        select * from user where id = #{id}
    </select>
复制代码
<select id="getUserInfoById" resultType="com.dbright.pojo.User">
        select * from user where id = ${id}
    </select>
复制代码

③分别执行结果

mybatis模糊查询(mybatis中的模糊查询是怎样实现的)(3)

$

mybatis模糊查询(mybatis中的模糊查询是怎样实现的)(4)

2.3、如何模拟sql注入?

mybatis模糊查询(mybatis中的模糊查询是怎样实现的)(5)

结果:查出了所有的数据,不安全

mybatis模糊查询(mybatis中的模糊查询是怎样实现的)(6)

如何解决呢?