EclipseLink-错误?简单原生 SQL 查询异常

EclipseLink-Bug? Simple native SQL query exception

我无法使用 EclipseLink 执行以下查询:

String query = "insert into A_TEST (TEST_NAME) values ('Ain''t it cool? It''s cool, or?')";


    EntityManagerFactory emf = Persistence.createEntityManagerFactory("jdbc-unit");
    EntityManager em = null;

    try {
        em = emf.createEntityManager();
        em.getTransaction().begin();

        Query q = em.createNativeQuery(query);
        //q.setHint(QueryHints.BIND_PARAMETERS, HintValues.FALSE);
        q.executeUpdate();

        em.getTransaction().commit();

    } catch (Exception ex) {
        ex.printStackTrace();
    } finally {
        try {
            if (em != null) {
                if (em.getTransaction().isActive()) 
                    em.getTransaction().rollback();
                em.close();
            }
        } catch (Exception ex) {
            ex.printStackTrace();
        }
    }

堆栈跟踪:

javax.persistence.PersistenceException: Exception [EclipseLink-4002] (Eclipse Persistence Services - 2.5.2.v20140319-9ad6abd): org.eclipse.persistence.exceptions.DatabaseException
Internal Exception: java.sql.SQLException: Ungültiger Spaltenindex
Error Code: 17003
Call: insert into A_TEST (TEST_NAME) values ('Ain''t it cool? It''s cool, or?)
bind => [1 parameter bound]
Query: DataModifyQuery(sql="insert into A_TEST (TEST_NAME) values ('Ain''t it cool? It''s cool, or?)")
at org.eclipse.persistence.internal.jpa.QueryImpl.executeUpdate(QueryImpl.java:308)
at persistence.test.ErrorTest.main(ErrorTest.java:43)

我发现问题出在问号和引号上。如果我删除它是有效的。这些字符的顺序似乎也很重要。

有人知道这个问题吗?

PS: "q.setHint(QueryHints.BIND_PARAMETERS, HintValues.FALSE);" 行再次出现异常。


我已经解决了:q.setHint(QueryHints.BIND_PARAMETERS, HintValues.TRUE);适合我

我会依靠查询参数为我做适当的转义。检查 EclipseLink help pages。如果此类查询的一部分是用户输入,则将整个 SQL 作为字符串传递也可能导致安全问题(SQL 注入)。

query = "insert into A_TEST (TEST_NAME) values (?)";
...
query.setParameter(1, "Ain't it cool? It's cool, or?");