300 AND author = 'Frank Herbert' GROUP BY year HAVING COUNT(*) > 0"}或者可以通过在单独的参数列表中提取值并在查询字符串中使用问号占位_post _sql?">
赞
踩
通过将值集成到查询字符串本身中,例如可以在查询条件中或在HAVING语句中使用值“内联”:
POST /_sql?format=txt
{
"query": "SELECT YEAR(release_date) AS year FROM library WHERE page_count > 300 AND author = 'Frank Herbert' GROUP BY year HAVING COUNT(*) > 0"
}
或者可以通过在单独的参数列表中提取值并在查询字符串中使用问号占位符(?)来完成此操作:
POST /_sql?format=txt
{
"query": "SELECT YEAR(release_date) AS year FROM library WHERE page_count > ? AND author = ? GROUP BY year HAVING COUNT(*) > ?",
"params": [300, "Frank Herbert", 0]
}
备注:建议将值传递给查询的方法是使用问号占位符,以避免任何尝试黑客入侵或SQL注入的尝试。
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。