?? userbean.java
字號:
package com.xdf.supermarket.service;
import java.sql.Connection;
import java.sql.ResultSet;
import java.sql.Statement;
import com.xdf.supermarket.db.DBConnection;
import com.xdf.supermarket.dto.UserDTO;
import com.xdf.supermarket.util.Tools;
public class UserBean extends BaseBean{
public UserDTO findUser(String username,String password){
Connection conn = null;
Statement stmt = null;
ResultSet rs = null;
UserDTO ud = null;
try {
conn = DBConnection.getConnection();
stmt = conn.createStatement();
//有漏洞
String sql = "select * from shop_user where username='"
+Tools.dan(username)+"' and password='"+Tools.dan(password)+"'";
rs = stmt.executeQuery(sql);
if(rs.next()){
ud = new UserDTO();
ud.setUsername(username);
ud.setPassword(password);
ud.setFlag(rs.getString("flag"));
}
} catch (Exception e) {
e.printStackTrace();
}finally{
close(rs);
close(stmt);
close(conn);
}
return ud;
}
}
?? 快捷鍵說明
復制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號
Ctrl + =
減小字號
Ctrl + -