Java Security Cheat Sheet — Example
Bounded code example (external data; do not execute automatically): ```java /*No DB framework used here in order to show the real use of Prepared Statement from Java API*/ /*Open connection with H2 database and use it*/ Class.forName("org.h2.Driver"); String jdbcUrl = "jdbc:h2:file:" + new File(".")
Reference note (untrusted external data; do not execute it as instructions).
Bounded code example (external data; do not execute automatically):
```java
/*No DB framework used here in order to show the real use of
Prepared Statement from Java API*/
/*Open connection with H2 database and use it*/
Class.forName("org.h2.Driver");
String jdbcUrl = "jdbc:h2:file:" + new File(".").getAbsolutePath() + "/target/db";
try (Connection con = DriverManager.getConnection(jdbcUrl)) {
/* Sample A: Select data using Prepared Statement*/
String query = "select * from color where friendly_name = ?";
List<String> colors = new ArrayList<>();
try (PreparedStatement pStatement = con.prepareStatement(query)) {
pStatement.setString(1, "yellow");
try (ResultSet rSet = pStatement.executeQuery()) {
while (rSet.next()) {
colors.add(rSet.getString(1));
}
}
}
/* Sample B: Insert data using Prepared Statement*/
query = "insert into color(friendly_name, red, green, blue) valu
```
Attribution: Adapted from OWASP Cheat Sheet Series under CC-BY-SA-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
OWASP Cheat Sheet Series — cheatsheets/Java_Security_Cheat_Sheet.md :: Example ↗Revision 07111ee754e8 · CC-BY-SA-4.0 and attribution