5 ms·
I think you are talking about this example: ResultSet rs = DB."SELECT * FROM Person p WHERE p.last_name = \{name}"; This when it becomes valid java will not a
by jerven 4y ago
I think you are talking about this example:
ResultSet rs = DB."SELECT * FROM Person p WHERE p.last_name = \{name}";
This when it becomes valid java will not allow an SQL injection attack. The name part would be properly passed as a parameter. Not a string concatenation.
Per https://openjdk.org/jeps/430 https://openjdk.org/jeps/430
If that was not the example you where thinking about, sorry :)
Otherwise yes don't build parameterized SQL out of strings !
- drdec 4y agoThanks for the correction
- jhhh 4y agoMy main complaint about this new feature is that it has such poor conceptual clarity that people already familiar with Java will almost always misinterpret what is happening in exactly the same way. I've seen people post similar comments to the one you're correcting on reddit as well.