【问题标题】:Python's string formatting throws error when applied within mysql在 mysql 中应用时,Python 的字符串格式会引发错误
【发布时间】:2018-11-04 19:25:22
【问题描述】:

我用 python 编写了一个脚本来从网站上抓取一些数据并将它们存储在 mysql 中。如果我选择两个选项来插入数据,我的脚本会成功完成这项工作:

mycursor.execute("INSERT INTO webdata (name,bubble,review) VALUES ('{}','{}','{}')".format(name,bubble,review))
mycursor.execute("INSERT INTO webdata (name,bubble,review) VALUES (%s,%s,%s)",(name,bubble,review))

但是,当我尝试使用 python's new string formatting 执行相同操作时会引发错误,如下所示:

mycursor.execute("INSERT INTO webdata (name,bubble,review) VALUES (f'{name},{bubble},{review}')")

它抛出的错误:

line 429, in _handle_result
    raise errors.get_exception(packet)
mysql.connector.errors.ProgrammingError: 1064 (42000): You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near ''{name},{bubble},{review}')' at line 1

我哪里出了问题以及如何解决它,因为我非常愿意坚持最后的格式样式?

【问题讨论】:

  • 对参数化查询使用第二个选项:bobby-tables.comdon`t do string interpolation

标签: python mysql python-3.x string-formatting


【解决方案1】:

最好让 MySQL 连接器使用 %s 绑定变量。这避免了 SQL 注入。这是一个工作示例。

import MySQLdb

# set up db connection
dbApi = MySQLdb
connection = MySQLdb.connect(
    host    = <hostname>,
    user    = <databasename>,
    passwd  = password,
    db      = <dbname>,
    port    = 3306,
    charset = "utf8")
cursor = connection.cursor(dbApi.cursors.DictCursor)

# insert records
records = [['George', 'Ten', 'Good'],
           ['Ringo', 'Ten', 'Good'],
           ['Paul', 'Ten', 'Good'],
           ['John', 'Ten', 'Good']]
insert_sql = 'insert into webdata (name, bubble, review) values (%s, %s, %s)'

for record in records:
    cursor.execute(insert_sql, record)

# list record
sql = 'select * from webdata'
cursor.execute(sql)
data = cursor.fetchall()
print 'data:', data

connection.commit()
cursor.close()

【讨论】:

    【解决方案2】:

    如果你想编写不受 SQL 注入漏洞攻击的代码,你不能将 f-strings 用于数据库,就这么简单。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2013-07-23
      • 1970-01-01
      • 1970-01-01
      • 2019-06-12
      • 1970-01-01
      • 2012-04-16
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多