作者iFEELing (ing)
看板java
标题Re: [问题] 找不出nullpoint的问题点....
时间Sun Jun 6 20:34:22 2010
※ 引述《dream1124 (全新开始)》之铭言:
: 这边是一个简单的web程式
: jsp档填表单,再送给servlet更改资料库的档案
: 但实作时一直产生nullPointerException 可是我检查不出哪里有null问题
: 请问有人方便帮我看一下吗?
: 原始码都不长,也都尽量写成方法,请您放心
: 谢谢
: servlet原始码︰http://docs.google.com/View?id=dcxxq5ff_26cfgs72gq
: jsp表单原始码︰http://docs.google.com/View?id=dcxxq5ff_27cxk8wccq
我觉得这个servlet实在是很经典啊....
//empProfile是用来储存输入资料的javabean
package emp;
import javax.servlet.*;
import javax.servlet.http.*;
import java.io.*;
import java.sql.*;
import java.util.*;
public class modEmpServlet extends HttpServlet{
private Connection con;
private empProfile emp;
public modEmpServlet() {
}
public void doPost(HttpServletRequest req, HttpServletResponse res)
throws IOException, ServletException {
setConnection(out);
首先...out...这是啥? System.out ??
emp.setEmp_num( Integer.parseInt( req.getParameter("emp_num") ) );
emp.setEmp_name( req.getParameter("emp_num") );
emp.setEmp_phone( req.getParameter("emp_phone") );
emp.setEmp_address( req.getParameter("emp_address") );
emp.setStore_num( Integer.parseInt( req.getParameter("store_num") ) );
emp.setEmp_gender( req.getParameter("emp_gender") );
输入之前 check 变数了吗? 没确认有没有值就运算是会炸的喔
try {
String update = "UPDATE employeement SET EMP_NAME=" +
emp.getEmp_name()
+ ", EMP_PHONE=" + emp.getEmp_phone()
+ ", EMP_ADDRESS=" + emp.getEmp_address()
+ ", STORE_NUM=" + Integer.toString(
emp.getStore_num() )
+ ", EMP_GENDER=" + emp.getEmp_gender()
+ " WHERE EMP_NUM=" + Integer.toString(
emp.getEmp_num() );
Statement stmt = con.createStatement();
这边是SQL Injection的基本案例...
stmt.executeUpdate(update);
execute 之後通常有个return值 你可以确认一下改到多少行
stmt.close();
con.close();
}//try
catch(SQLException sqle) {
然後 喔喔 把 Exception 吃的乾乾净净...这样炸了就死无对证了
}//catch
}//doPost
public void doGet(HttpServletRequest req, HttpServletResponse res) throws
IOException, ServletException {
doPost(req, res);
}//doGet
public void setConnection(PrintWriter out) {
String classForName = "com.mysql.jdbc.Driver";
String url = "隐私问题, 不在google docs中公开";
String dbSchema = "不公开";
String user = "web_manager";
String pw = "web";
try{
Class.forName(classForName);
con = DriverManager.getConnection(url+dbSchema, user, pw);
}
catch(Exception sqle) {
这边也是吃了 Exception 之後就假装它不存在...
}//catch
}//setConnection()
}
--
And they... Will dance if they want to dance Please brother take a chance
You know they're gonna go Which way they wanna go
All we know is that we don't know
What is gonna be Please brother let it be
Life on the other hand won't let you understand
Why we're all part of the masterplan _
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 122.117.3.226
1F:推 superlubu:SQL Injection... 曾有 Contractor 被我用这玩了两星期 06/06 20:38