【问题标题】:MySQLSyntaxErrorException - Invalid Parameters in Prepared StatementMySQLSyntaxErrorException - 准备好的语句中的参数无效
【发布时间】:2013-01-26 15:37:56
【问题描述】:

我有如下代码。我已经尝试过堆栈中的其他解决方案,但似乎没有任何效果。产生错误的Java代码如下所示。

public Connection getConnection() 
    {
      try 
      {
        conn = DriverManager.getConnection(CONNSTR, USER, PASS);
        return conn;
      }
      catch (SQLException e) 
      {
        e.printStackTrace();
        return null;
      }
    }

    public boolean AuthenticateUser() 
    {   
        String UserName = "User";
        String Password = "Password";

        try 
        {
            PreparedStatement  pstmt = null;
            ResultSet          rs   = null;
            conn = getConnection();

            String strSQL = "SELECT UserName " +
                      "  FROM Users " +
                      " WHERE UserId   = ?  AND " + 
                      "       Password = ?";

          pstmt = (PreparedStatement) conn.prepareStatement(strSQL);
          pstmt.setString(1, UserName);
          pstmt.setString(2, Password);

          System.out.println(strSQL);

          rs = pstmt.executeQuery(strSQL);

          System.out.println(rs.getRow());

          rs.last();
          int TotalRows = rs.getRow();
          System.out.println(TotalRows);

          if(TotalRows > 0)
            return true;
          else
            return false;  

        } 
        catch (SQLException e) 
        {
          e.printStackTrace();
          return false;
        }         
    }

数据库的表结构如下所示

CREATE TABLE Users(Id INT NOT NULL PRIMARY KEY AUTO_INCREMENT,
                   UserName VARCHAR(255),
                   UserId VARCHAR(255),
               Password VARCHAR(255))

错误如下Image

例外情况如下

com.mysql.jdbc.exceptions.jdbc4.MySQLSyntaxErrorException: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '?  AND          Password = ?' at line 1
    at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
    at sun.reflect.NativeConstructorAccessorImpl.newInstance(Unknown Source)
    at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(Unknown Source)
    at java.lang.reflect.Constructor.newInstance(Unknown Source)
    at com.mysql.jdbc.Util.handleNewInstance(Util.java:411)
    at com.mysql.jdbc.Util.getInstance(Util.java:386)
    at com.mysql.jdbc.SQLError.createSQLException(SQLError.java:1052)
    at com.mysql.jdbc.MysqlIO.checkErrorPacket(MysqlIO.java:3609)
    at com.mysql.jdbc.MysqlIO.checkErrorPacket(MysqlIO.java:3541)
    at com.mysql.jdbc.MysqlIO.sendCommand(MysqlIO.java:2002)
    at com.mysql.jdbc.MysqlIO.sqlQueryDirect(MysqlIO.java:2163)
    at com.mysql.jdbc.ConnectionImpl.execSQL(ConnectionImpl.java:2618)
    at com.mysql.jdbc.ConnectionImpl.execSQL(ConnectionImpl.java:2568)
    at com.mysql.jdbc.StatementImpl.executeQuery(StatementImpl.java:1557)
    at com.apryll.db.util.dbUtil.AuthenticateUser(dbUtil.java:55)
    at com.apryll.db.Login.doPost(Login.java:42)
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:641)
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:722)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:304)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:210)
    at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:240)
    at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:164)
    at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:462)
    at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:164)
    at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:100)
    at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:562)
    at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:118)
    at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:395)
    at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:250)
    at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:188)
    at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:302)
    at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(Unknown Source)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
    at java.lang.Thread.run(Unknown Source)

【问题讨论】:

  • 你遇到了什么异常?你能发布完整的堆栈跟踪吗?
  • 不添加快照。在此处复制并发布异常。我什至看不到那张图片。
  • 你能右键选择查看图片吗
  • 为什么要再次将 SQL 作为参数传递给 executeQuery 方法?在 API 中找不到该签名...
  • 非常感谢阿德里安·洛佩斯。 Gr8

标签: java jsp jdbc


【解决方案1】:

您将变量 UserName 作为第一个查询参数传递,但在查询中您使用的是一个 int 而不是 String 的 UserId。

希望对你有帮助,

【讨论】:

  • 感谢您的回复。不,我检查了它的字符串主字段保留为 Id
  • 请检查表结构
【解决方案2】:

您再次将 SQL 传递给 executeQuery 方法。该签名不会出现在 API 中。该方法不需要参数。

executeQuery() javaDoc

【讨论】:

  • 它确实出现在 StatementPreparedStatement 的超类)的 API 中,但是当从 PreparedStatement 调用接受查询字符串的 Statement 方法时,驱动程序应该抛出异常或CallableStatement.
猜你喜欢
  • 2016-03-23
  • 2020-05-29
  • 2020-11-26
  • 2018-07-04
  • 1970-01-01
  • 2021-12-23
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多