【发布时间】:2017-07-26 07:30:13
【问题描述】:
我已经看到一些讨论通过命名参数来防止 SQL 注入的主题,但是 hibernate 语句怎么样
currentSession().update(object);
或
currentSession().save(object)?
这些安全吗?或者总是使用命名参数更安全,比如
currentSession().createQuery("update Object set field=:field where id=:id").setParameter("field", field).setParameter("id", id).executeUpdate()?
【问题讨论】:
标签: java hibernate sql-injection