【问题标题】:sql statement not working in jspsql语句在jsp中不起作用
【发布时间】:2015-11-17 04:27:42
【问题描述】:

这是我拥有的代码,我认为它的 Sql 字符串无法正常工作。我能够查看表格并点击编辑字段,但我只能更新第一行。我希望能够选择一行,然后根据其 id 对其进行编辑。

//Database View
<%@ page import="java.sql.ResultSet" %>
<%@ page import="java.sql.SQLException" %>
<%@ page import="java.sql.Statement" %>
<%@ page import="java.sql.Connection" %>
<%@ page import="java.sql.DriverManager" %>

<html>
<head>
    <title>Inventory</title>
</head>
<body>

    <%
    Connection connect = null;
    Statement s = null;

    try {
        Class.forName("com.mysql.jdbc.Driver");

        connect =  DriverManager.getConnection("jdbc:mysql://localhost/client", "rootroot", "rootroot");

        s = connect.createStatement();

        String sql = "SELECT * FROM  client ORDER BY id ASC";

        ResultSet rec = s.executeQuery(sql);
        %>
        <table width="600" border="1">
          <tr>
            <th width="91"> <div align="center">id </div></th>
            <th width="198"> <div align="center">Email </div></th>
            <th width="97"> <div align="center">CountryCode </div></th>
            <th width="59"> <div align="center">Budget </div></th>
            <th width="71"> <div align="center">Edit </div></th>
          </tr> 
            <%while((rec!=null) && (rec.next())) { %>
                  <tr>
                    <td><div align="center"><%=rec.getString("id")%></div></td>
                    <td><%=rec.getString("first_name")%></td>
                    <td><%=rec.getString("last_name")%></td>
                    <td><div align="center"><%=rec.getString("blood_type")%></div></td>
                    <td align="right"><%=rec.getString("gender")%></td>

                    <td align="center"> <a href="editpage.jsp?id=<%=rec.getString("id")%>">Edit</a></td>
                  </tr>
            <%}%>
        </table>      
        <%  
        } catch (Exception e) {
            // TODO Auto-generated catch block
            out.println(e.getMessage());
            e.printStackTrace();
        }

        try {
            if(s!=null){
                s.close();
                connect.close();
            }
        } catch (SQLException e) {
            // TODO Auto-generated catch block
            out.println(e.getMessage());
            e.printStackTrace();
        }
    %>
</body>
</html>

//Edit Page 
<%@ page import="java.sql.ResultSet" %>
<%@ page import="java.sql.SQLException" %>
<%@ page import="java.sql.Statement" %>
<%@ page import="java.sql.Connection" %>
<%@ page import="java.sql.DriverManager" %>

<html>
<head>
    <title>ThaiCreate.Com JSP Tutorial</title>
</head>
<body>

    <%  
    Connection connect = null;
    Statement s = null;

    try {
        Class.forName("com.mysql.jdbc.Driver");

        connect =  DriverManager.getConnection("jdbc:mysql://localhost/client", "rootroot", "rootroot");

        s = connect.createStatement();

        String sql ="SELECT * FROM client";

        ResultSet rec = s.executeQuery(sql);
        if(rec != null) {
            rec.next();
        %>
    <form name="frmUpdate" method="post" action="SaveEdit.jsp?id=<%=rec.getString("id")%>"> 
        Update Form
            <table width="428" border="1">  
            <tr>
                <th width="181">
                <div align="left">Product ID </div></th>
                <td width="231"><%=rec.getString("id")%></td>
            </tr>
            <tr>
                <th width="181">
                <div align="left">Name </div></th>
                <td><input type="text" name="txtName" size="20" value="<%=rec.getString("first_name")%>"></td>
            </tr>
            <tr>
                <th width="181">
                <div align="left">Email </div></th>
                <td><input type="text" name="txtEmail" size="20" value="<%=rec.getString("last_name")%>"></td>
            </tr>
            <tr>
                <th width="181">
                <div align="left">CountryCode </div></th>
                <td><input type="text" name="txtCountryCode" size="2" value="<%=rec.getString("blood_type")%>"></td>
            </tr>
            <tr>
                <th width="181">
                <div align="left">Budget </div></th>
                <td><input type="text" name="txtBudget" size="5" value="<%=rec.getString("gender")%>"></td>
            </tr>

            </table> 
        <input type="submit" value="Save">
        </form> 

        <% }

        } catch (Exception e) {
            // TODO Auto-generated catch block
            out.println(e.getMessage());
            e.printStackTrace();
        }

        try {
            if(s!=null){
                s.close();
                connect.close();
            }
        } catch (SQLException e) {
            // TODO Auto-generated catch block
            out.println(e.getMessage());
            e.printStackTrace();
        }
    %>
</body>
</html>

// save page 
<%@ page import="java.sql.ResultSet" %>
<%@ page import="java.sql.SQLException" %>
<%@ page import="java.sql.Statement" %>
<%@ page import="java.sql.Connection" %>
<%@ page import="java.sql.DriverManager" %>

<html>
<head>
    <title>Hello World</title>
</head>
<body>

    <%  
    Connection connect = null;
    Statement s = null;

    try {
        Class.forName("com.mysql.jdbc.Driver");

        connect =  DriverManager.getConnection("jdbc:mysql://localhost/client", "rootroot", "rootroot");

        s = connect.createStatement();

        String strCustomerID = request.getParameter("id");
        String strName = request.getParameter("txtName");
        String strEmail = request.getParameter("txtEmail");
        String strCountryCode = request.getParameter("txtCountryCode");
        String strBudget = request.getParameter("txtBudget");



        String sql = "UPDATE client " +
                "SET first_name = '"+ strName + "' " +
                ", last_name = '"+ strEmail + "' " +
                ", blood_type = '"+ strCountryCode + "' " +
                ", gender = '"+ strBudget + "' " +

                " WHERE id = '" + strCustomerID + "' ";
         s.execute(sql);

         out.println("Record Update Successfully");

        } catch (Exception e) {
            // TODO Auto-generated catch block
            out.println(e.getMessage());
            e.printStackTrace();
        }

        try {
            if(s!=null){
                s.close();
                connect.close();
            }
        } catch (SQLException e) {
            // TODO Auto-generated catch block
            out.println(e.getMessage());
            e.printStackTrace();
        }
    %>
</body>
</html>

【问题讨论】:

  • 请不要写这样的代码。使用 MVC,或者至少将查询移动到 DAO并且请不要使用 scriptlet。
  • Elliot 你认为 Sql 语句有什么问题?
  • @MuneebKhan:永远不要将 SQL 或 Java 代码直接放入 JSP。 JSP 用于呈现数据,而不是用于数据检索或处理

标签: java mysql sql jsp


【解决方案1】:

请尝试 s.executeUpdate(sql);而不是 s.execute(sql);

【讨论】:

  • 感谢您的回复,我已经尝试过了,但没有任何区别。我认为保存页面中的SQL语句不正确,String sql ="SELECT * FROM client";
  • 为什么你认为保存页面出现sql错误?您的测试中显示哪个错误?你能告诉我你的错误吗?
  • 之前我有这个:String sql = "SELECT * FROM customer WHERE CustomerID = '" + id + "' ";那不起作用,所以我也更改了它: String sql ="SELECT * FROM client";然后它开始了,但我只能更新第一行。
  • 首先你应该只在你的查询浏览器中编写和测试sql查询。这样你就可以清楚的知道是不是sql错误了。
【解决方案2】:

首先为 Elliott Frisch 所说的 +1。这种意大利面条式代码是非常糟糕的做法。

无论如何,如果我正确理解您的用例,那么您需要在编辑页面上从 URL/request 获取 id 参数并添加到选择适当的条件中,使其看起来像

"SELECT * FROM client WHERE id = '" + clientId + "' "

如果您不将条件放入其中,它将始终返回整个表,并且根据您的代码,您只需获取第一行并忽略其余行。这是使用 DB 的非常低效的方式。

您应该考虑的另一件事是绑定和所谓的preparedStatement - 尝试用谷歌搜索并了解一些相关信息。使用它的主要原因是避免 SQL 注入,使用它有人可以很容易地弄乱或破坏您的数据库数据。

我个人也会通过列出您真正需要的所有列来替换 *。

【讨论】:

  • 错误:org.apache.jasper.JasperException:PWC6033:JSP PWC6199 的 Javac 编译出错:生成的 servlet 错误:源值 1.5 已过时,将在未来版本中删除 PWC6199:生成的 servlet 错误:目标值 1.5 已过时,将在未来版本中删除 PWC6199:生成的 servlet 错误:要禁止有关过时选项的警告,请使用 -Xlint:-options。 PWC6197:在 jsp 文件中的第 13 行发生错误:/editpage.jsp PWC6199:生成的 servlet 错误:找不到符号符号:变量 Pid 位置:类 org.apache.jsp.editpage_jsp
  • 你一定有错字。错误说:cannot find symbol symbol: variable Pid location at the editpage.jsp line 13
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2013-05-03
  • 2023-03-30
  • 2012-11-15
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多