Re: PreparedStatements, LIKE and the % operator

Поиск
Список
Период
Сортировка
От Barry Lind
Тема Re: PreparedStatements, LIKE and the % operator
Дата
Msg-id D5C55DA5-283C-43A3-A990-450079009651@xythos.com
обсуждение исходный текст
Ответ на PreparedStatements, LIKE and the % operator  ("j.random.programmer" <javadesigner@yahoo.com>)
Список pgsql-jdbc
I would suggest:

LIKE '%' || ? || '%'


On Feb 2, 2007, at 10:58 PM, j.random.programmer wrote:

> Hi:
>
> I am using postgres 8.2 with the 8.2.504 jdbc3 driver.
>
> I am getting data from a untrusted source. Hence a
> prepared
> statement. I also need a partial match.
>
> String query =  " select * from table_foo where bar =
> LIKE %?% "
> PreparedStatement ps = con.prepareStatement(query);
> ps.setString(1, "haha");
> ....
>
> This craps out when run. Try adding single quotes
> before and
> after the: %?%
>
> String query =   " select * from table_foo where bar =
> LIKE '%?%'  "
> PreparedStatement ps = con.prepareStatement(query);
> ps.setString(1, "haha");
> ...
>
> This craps out too.
>
> A quick search of the archives doesn't shed light on
> this issue. I
> don't need a JDBC escape since I want to use a % char.
>
> So how do I use LIKE within a prepared statement ? I'm
> sure I'm
> missing something obvious here....
>
> Best regards,
> --j
>
>
>
>
>
> ______________________________________________________________________
> ______________
> Don't pick lemons.
> See all the new 2007 cars at Yahoo! Autos.
> http://autos.yahoo.com/new_cars.html
>
> ---------------------------(end of
> broadcast)---------------------------
> TIP 7: You can help support the PostgreSQL project by donating at
>
>                 http://www.postgresql.org/about/donate


В списке pgsql-jdbc по дате отправления:

Предыдущее
От: Thomas Kellerer
Дата:
Сообщение: Re: PreparedStatements, LIKE and the % operator
Следующее
От: Miroslav Šulc
Дата:
Сообщение: Re: JDBC and arrays