Multiple Statements with MySQL and JDBC

databases

Cameron Childress pointed out the allowMultiQueries setting in the MySQL JDBC driver on the CFGURU list. It is set to false by default to protect you from SQL Injection attacks. When set to true MySQL will allow multiple SQL statements (seperated by a semi-colon) to be executed in a single CFQUERY tag. If you need to run multiple statements in a single CFQUERY, Dave Watts suggested creating another datasource with this setting turned on, which is only to be used when your running multiple statements.

But don't let this stop you from using prepared statements with CFQUERYPARAM, just because MySQL is safe by default - it is still a best practice, adds performance and type safety.


cfobjective pre-conf training

Related Entries

7 people found this page useful, what do you think?

WAF for CF

Trackbacks

Trackback Address: 357/E720E80266099C317D5792CCF780EA2C

Post a Comment




  



Spell Checker by Foundeo

Recent Entries





Basecamp
pfreitag on twitter