2018-06-12 12:33

public class CustSqlServerDialect extends SqlServerDialect {
public void fillStatement(PreparedStatement pst, Object... paras) throws SQLException {
for (int i=0; i Object value = paras[i];

if (value instanceof java.sql.Date) {
pst.setDate(i + 1, (java.sql.Date)value);
} else if (value instanceof java.util.Date) {
java.util.Date date = (java.util.Date) value;
pst.setDate(i + 1, new java.sql.Date(date.getTime()));
}
else if (value instanceof java.sql.Timestamp) {
pst.setTimestamp(i + 1, (java.sql.Timestamp)value);
} else {
pst.setObject(i + 1, value);
}
}
}
}
继承扩展一个Dialect,重写 fillStatement 方法,打完收工!

2018-03-19 13:46

sql 注入漏洞

2016-12-04 19:28

@jcdilon alert(JSON.stringify(data)); 看一下就全明白了!