userbean.java

来自「一个基于Eclipse平台和MySQL数据库的一个超市管理系统功能全面」· Java 代码 · 共 41 行

JAVA
41
字号
package com.xdf.supermarket.service;

import java.sql.Connection;
import java.sql.ResultSet;
import java.sql.Statement;

import com.xdf.supermarket.db.DBConnection;
import com.xdf.supermarket.dto.UserDTO;
import com.xdf.supermarket.util.Tools;

public class UserBean extends BaseBean{
	
	public UserDTO findUser(String username,String password){
		Connection conn = null;
		Statement stmt = null;
		ResultSet rs = null;
		UserDTO ud = null;
		try {
			conn = DBConnection.getConnection(); 
			stmt = conn.createStatement();
			//有漏洞  
			String sql = "select * from shop_user where username='"
				+Tools.dan(username)+"' and password='"+Tools.dan(password)+"'";

			rs = stmt.executeQuery(sql);
			if(rs.next()){
				ud = new UserDTO();
				ud.setUsername(username);
				ud.setPassword(password);
				ud.setFlag(rs.getString("flag"));
			}
		} catch (Exception e) {
			e.printStackTrace();
		}finally{
			close(rs);
			close(stmt);
			close(conn);
		}
		return ud;		
	}
}

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?