【问题标题】:Why do I keep getting the SQL parameter index out of range exception?为什么我总是让 SQL 参数索引超出范围异常?
【发布时间】:2015-07-02 10:32:18
【问题描述】:

我查看了类似的问题,并遵循了编写查询以插入数据库的语法,但我不断收到此异常。我显然没有看到什么。它在“ insertStatement.setInt(1, schoolID);”处停止运行.我读到这意味着查询的语法不正确。请告诉我哪里出错了。我根本看不到。

package Servlets;

import java.io.IOException;
import java.io.PrintWriter;
import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.Statement;
import java.sql.Timestamp;
import java.text.ParseException;
import java.text.SimpleDateFormat;
import java.util.Date;
import java.util.logging.Level;
import java.util.logging.Logger;
import javax.persistence.EntityManager;
import javax.persistence.EntityManagerFactory;
import javax.persistence.Persistence;
import javax.servlet.ServletContext;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import jpa.entities.School;

/**
 *
 * @author Timothy
 */
@WebServlet(name = "SchoolFormServlet", urlPatterns = {"/SchoolFormServlet"})
public class SchoolFormServlet extends HttpServlet {

    /**
     * Processes requests for both HTTP <code>GET</code> and <code>POST</code>
     * methods.
     *
     * @param request servlet request
     * @param response servlet response
     * @throws ServletException if a servlet-specific error occurs
     * @throws IOException if an I/O error occurs
     */
    protected void processRequest(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException, ParseException {
        response.setContentType("text/html;charset=UTF-8");
        try (PrintWriter out = response.getWriter()) {
            /* TODO output your page here. You may use following sample code. */
            ServletContext sc = this.getServletContext();
            sc.getAttribute("schoolForm");
            Integer schoolId = Integer.parseInt(request.getParameter("schoolID"));
            String schoolName = request.getParameter("schoolName");
            Integer periods = Integer.parseInt(request.getParameter("periods"));
            Integer repeatDays = Integer.parseInt(request.getParameter("repeatDays"));
            String scheduleBlock = request.getParameter("scheduleBlock");
            Integer semesters = Integer.parseInt(request.getParameter("semesters"));
            String rangeForLunch = request.getParameter("rangeForLunch");
            String schoolYear = request.getParameter("schoolYear");
            initAndExecuteQuery(schoolId,schoolName,semesters,periods,repeatDays,scheduleBlock,rangeForLunch,schoolYear);

            out.println("<!DOCTYPE html>");
            out.println("<html>");
            out.println("<head>");
            out.println("<title>Servlet SchoolFormServlet</title>");            
            out.println("</head>");
            out.println("<body>");
            out.println("<h1>Servlet SchoolFormServlet at " + request.getContextPath() + "</h1>");
            out.println("</body>");
            out.println("</html>");
        }
    }

    // <editor-fold defaultstate="collapsed" desc="HttpServlet methods. Click on the + sign on the left to edit the code.">
    /**
     * Handles the HTTP <code>GET</code> method.
     *
     * @param request servlet request
     * @param response servlet response
     * @throws ServletException if a servlet-specific error occurs
     * @throws IOException if an I/O error occurs
     */
    @Override
    protected void doGet(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException {
        try {
            processRequest(request, response);
        } catch (ParseException ex) {
            Logger.getLogger(SchoolFormServlet.class.getName()).log(Level.SEVERE, null, ex);
        }
    }

    /**
     * Handles the HTTP <code>POST</code> method.
     *
     * @param request servlet request
     * @param response servlet response
     * @throws ServletException if a servlet-specific error occurs
     * @throws IOException if an I/O error occurs
     */
    @Override
    protected void doPost(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException {
        try {
            processRequest(request, response);
        } catch (ParseException ex) {
            Logger.getLogger(SchoolFormServlet.class.getName()).log(Level.SEVERE, null, ex);
        }
    }

    /**
     * Returns a short description of the servlet.
     *
     * @return a String containing servlet description
     */
    @Override
    public String getServletInfo() {
        return "Short description";
    }// </editor-fold>

    public void initAndExecuteQuery(Integer schoolID,String schoolName, Integer semesters,Integer periods,Integer repeatDays,String scheduleBlock,String rangeForLunch, String schoolYear) {
      // JDBC driver name and database URL
      String jdbcDriver ="com.mysql.jdbc.Driver";  
      String url ="jdbc:mysql://173.194.104.102:3306/hssp_schema?zeroDateTimeBehavior=convertToNull";
      Connection connection = null;
      ResultSet resultSet = null;
      Statement statement = null;
      //  Database credentials
      String userName = "admin_aamir";
      String passWord = "tommybrown"; 


        try {
            Class.forName("com.mysql.jdbc.Driver").newInstance();
            connection = DriverManager.getConnection(url, userName , passWord);

          // Execute SQL query

         String sql;
         sql = "INSERT INTO School VALUES ('"+schoolID+" ','"+schoolName+" ','"+semesters+" ','"+periods+" ','"+repeatDays+" ','"+scheduleBlock+" ','"+rangeForLunch+" ','"+schoolYear+" ')";
         PreparedStatement insertStatement = connection.prepareStatement(sql);
         insertStatement.setInt(1, schoolID);
         insertStatement.setString(2,schoolName);
         insertStatement.setInt(3,periods);
         insertStatement.setInt(4,repeatDays);
         insertStatement.setString(5,scheduleBlock);
         insertStatement.setString(6,rangeForLunch);
         insertStatement.setString(7,schoolYear);
         insertStatement.executeQuery();
         insertStatement.close();
         connection.close();

        }
        catch (Exception e) {
            e.printStackTrace();

        }



   }


}

【问题讨论】:

  • 这些是你真正的数据库凭据吗?
  • 我尝试连接 :) 但收到“ERROR 2013 (HY000): Lost connection to MySQL server at 'reading initial communication packet', system error: 0”
  • 看在你的份上,我希望这些不是有效的数据库凭据。如果是,请编辑它们。

标签: java mysql jsp servlets web-applications


【解决方案1】:

您需要在 SQL 字符串中添加问号以告诉它它有参数——而不是直接附加它们。

sql = "INSERT INTO School VALUES(?, ?, ? ...)

MySQL 连接器实现将用您设置的参数值替换这些问号(它不会像您的代码那样将它们粘贴到其中,因为这会使它容易受到SQL injection 的攻击) )。

【讨论】:

  • 我应该这样做:“INSERT INTO School VALUES ('"?+schoolID+" ','"?+schoolName+" ','"?+semesters+" ');问号去哪儿了?
  • @user4789552:就像 yshavit 向您展示的那样。 INSERT INTO School VALUES ( ? , ? , ? )。尽管我们希望有一个列列表,而不是依赖于表中列的数量和顺序,例如INSERT INTO school ( id, name, periods) VALUES ( ? , ? , ? )。 (这些问号是绑定占位符,您使用setIntsetString 等方法为 SQL 文本中的每个问号占位符提供一个值。
  • 你想多了。 :) 您不需要将值放入 SQL 字符串中。真的,只是问号。数据库从那里获取它。将问号想象为“这里有东西”,而set... 方法则说明了这些东西是什么。
【解决方案2】:

正确的语法是

插入表名(FIELD1、FIELD2、FIELD3)值(?、?、?)

所以你需要第一个括号内的列名和相同数量的 ?在第二。然后你的 setX(1, value) 语句在执行前填写问号所在的位置。

【讨论】:

  • 这是怎么回事 : sql = "INSERT INTO School (schoolId,schoolName,semesters,periods,repeatDays,scheduleBlock,rangeForLunch,schoolYear) VALUES (?,?,?,?,?,?,?, ?)";
  • 这就是我现在所拥有的:"INSERT INTO School VALUES(?,?,?,?,?,?,?,?)";但它不起作用
  • @user4789552:在插入语句中提供列列表,对应于绑定占位符的顺序。 INSERT INTO School (id, name, periods, ... ) VALUES ( ? , ? , ? ... ),就像 arcy 演示的那样。 (我们不知道表中列的名称,或者它们出现的顺序,所以我们不能给你你需要的确切陈述。)...顺便说一句...“它没有' t work" 并不能充分描述您所观察到的行为。
【解决方案3】:

School( ...... ) 内输入您的数据库表列名,在values(?,?,?.....) 内根据您要插入数据库的列名数输入问号,因为您当前的情况是 8 列,所以输入 8 个问号。

 String sql;
         sql = "INSERT INTO School(schoolID,schoolName,semesters,periods,repeatDays,scheduleBlock,rangeForLunch,schoolYear) VALUES (?,?,?,?,?,?,?,?)";
         PreparedStatement insertStatement = connection.prepareStatement(sql);
         insertStatement.setInt(1, schoolID);
         insertStatement.setString(2,schoolName);
         insertStatement.setInt(3,periods);
         insertStatement.setInt(4,repeatDays);
         insertStatement.setString(5,scheduleBlock);
         insertStatement.setString(6,rangeForLunch);
         insertStatement.setString(7,schoolYear); 
        // you have missing 1 line for number 8 , since you wanted to insert 8 data into 8 column 
         insertStatement.executeQuery();
         insertStatement.close();
         connection.close();

【讨论】:

    【解决方案4】:

    方法一: 编写如下代码

    String sql;
         sql = "INSERT INTO School VALUES ('"+schoolID+" ','"+schoolName+" ','"+semesters+" ','"+periods+" ','"+repeatDays+" ','"+scheduleBlock+" ','"+rangeForLunch+" ','"+schoolYear+" ')";
         PreparedStatement insertStatement = connection.prepareStatement(sql);
    int valid = insertStatement.executeUpdate();
    if(valid == 1)
       System.out.println("insertion successfull");
    else
       System.out.println("problem while inserting data in database");
    

    希望它对你有用。它适用于我的情况。

    方法二:

    编写如下代码

    String sql;
         sql = "INSERT INTO School VALUES ('"+schoolID+" ','"+schoolName+" ','"+semesters+" ','"+periods+" ','"+repeatDays+" ','"+scheduleBlock+" ','"+rangeForLunch+" ','"+schoolYear+" ')";
        sql = "INSERT INTO School VALUES(?,?,?,?,?,?,?,?)";
        PreparedStatement insertStatement = connection.prepareStatement(sql);
         insertStatement.setInt(1, schoolID);
         insertStatement.setString(2,schoolName);
         insertStatement.setInt(3,semesters)   // you forgot to write this statement assuming the data types are correct
         insertStatement.setInt(4,periods);
         insertStatement.setInt(5,repeatDays);
         insertStatement.setString(6,scheduleBlock);
         insertStatement.setString(7,rangeForLunch);
         insertStatement.setString(8,schoolYear);
    
         int valid = insertStatement.executeUpdate();
         if(valid == 1)
              System.out.println("insertion successfull");
         else
              System.out.println("problem while inserting data in database");
    

    希望你理解这两种方法

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2016-07-01
      • 1970-01-01
      • 2011-12-05
      • 2012-02-16
      • 2011-03-16
      • 1970-01-01
      相关资源
      最近更新 更多