mybatis模糊查詢的幾種寫法:http://blog.csdn.net/returnme/article/details/7185411mybatis
一開始,我喜歡這種寫法,由於它夠簡單: SELECT * FROM tableName WHERE name LIKE '%${text}%'; spa
惋惜,這種寫法有注入漏洞。詳見這裏。.net
---------------------------------------------blog
因此,對用戶輸入的信息進行模糊查詢時,我以爲這樣最好:
get
SELECT * FROM tableName WHERE name LIKE CONCAT('%', #{empname}, '%')table