436
Chapter 20: Accessing and Retrieving Data
The
cfqueryparam
tag checks that the value of Emp_ID is an integer data type. If anything else
in the query string is not an integer, such as a SQL statement to delete a table, the
cfquery
tag
does not execute. Instead, the
cfqueryparam
tag returns the following error message:
Invalid data '7 DELETE FROM Employee' for CFSQLTYPE 'CF_SQL_INTEGER'.
Using cfqueryparam with strings
When passing a variable that contains a string to a query, specify a
cfsqltype
value of
cf_sql_char
, and specify the
maxLength
attribute, as in the following example:
<cfquery name = "getFirst" dataSource = "cfsnippets">
SELECT * FROM employees
WHERE LastName =
<cfqueryparam value = "#LastName#"
cfsqltype = "cf_sql_char" maxLength = "17">
</cfquery>
In this case,
cfqueryparam
performs the following checks:
•
It ensures that LastName contains a string.
•
It ensures that the string is 17 characters or less.
•
It escapes the string with single-quotation marks so that it appears as a single value to the
database. Even if a hacker passes a bad URL, it appears as follows:
WHERE LastName = 'Anwar DELETE FROM MyCustomerTable'.
Using cfSqlType
The following table lists the available SQL types against which you can evaluate the
value
attribute of the
cfqueryparam
tag:
Note:
Specifying the
cfsqltype
attribute causes the DBMS to use bind variables, which can greatly
enhance performance.
BIGINT
BIT
CHAR
DATE
DECIMAL
DOUBLE
FLOAT
IDSTAMP
INTEGER
LONGVARCHAR
MONEY
MONEY4
NUMERIC
REAL
REFCURSOR
SMALLINT
TIME
TIMESTAMP
TINYINT
VARCHAR
Содержание COLDFUSION MX 61-DEVELOPING COLDFUSION MX
Страница 1: ...Developing ColdFusion MX Applications...
Страница 22: ...22 Contents...
Страница 38: ......
Страница 52: ...52 Chapter 2 Elements of CFML...
Страница 162: ......
Страница 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Страница 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Страница 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Страница 266: ......
Страница 314: ...314 Chapter 14 Handling Errors...
Страница 344: ...344 Chapter 15 Using Persistent Data and Locking...
Страница 349: ...About user security 349...
Страница 357: ...Security scenarios 357...
Страница 370: ...370 Chapter 16 Securing Applications...
Страница 388: ...388 Chapter 17 Developing Globalized Applications...
Страница 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Страница 410: ......
Страница 426: ...426 Chapter 19 Introduction to Databases and SQL...
Страница 476: ...476 Chapter 22 Using Query of Queries...
Страница 534: ...534 Chapter 24 Building a Search Interface...
Страница 556: ...556 Chapter 25 Using Verity Search Expressions...
Страница 558: ......
Страница 582: ...582 Chapter 26 Retrieving and Formatting Data...
Страница 668: ......
Страница 734: ...734 Chapter 32 Using Web Services...
Страница 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Страница 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Страница 788: ......
Страница 806: ...806 Chapter 35 Sending and Receiving E Mail...