Java JDBC के CRUD Operations
In this page:
PreparedStatement statement = connection.prepareStatement("INSERT INTO table_name (col1, col2) VALUES (?, ?)");
statement.setString(1, value1);
statement.setInt(2, value2);
statement.executeUpdate();
Create Operation (INSERT)
नए records सुरक्षित रूप से जोड़ने के लिए, raw string concatenation से SQL बनाने से बचें, जो SQL injection का दरवाज़ा खोल देता है। PreparedStatements query structure को एक बार compile करते हैं और raw input values को parameters के रूप में bind करते हैं, user-supplied data को कभी SQL के रूप में interpret होने से बचाते हुए।
उदाहरण: Create Operation (INSERT)
import java.util.*;
public class Main {
public static void main(String[] args) {
List<String> table = new ArrayList<>();
String sql = "INSERT INTO users (name) VALUES (?)"; // bound parameter, not concatenated
String name = "Riya";
table.add(name); // simulated insert
System.out.println("Executed: " + sql + " with [" + name + "]");
}
}
Login to try C/C++/Java/PHP code in the editor
Update Operation (UPDATE)
UPDATE statements मौजूदा rows को modify करते हैं, जिसमें बदलने वाले columns और WHERE clause दोनों concatenated strings के बजाय bound PreparedStatement parameters के रूप में पास किए जाते हैं। बाद में हमेशा executeUpdate() की return value जांचें, क्योंकि यह बताती है कि असल में कितनी rows मेल खाईं और बदली गईं।
उदाहरण: Update Operation (UPDATE)
// Import java.util.* so it can be used by its short name
import java.util.*;
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) {
// Create a new ArrayList object and store it in table
List<String> table = new ArrayList<>(List.of("Riya"));
String sql = "UPDATE users SET name = ? WHERE name = ?";
// Declare rowsChanged and set it to table.contains("Riya") ? 1 : 0
int rowsChanged = table.contains("Riya") ? 1 : 0;
table.set(0, "Riya Sharma");
// Print a line to the console
System.out.println("Executed: " + sql + " -- rows changed: " + rowsChanged);
}
}
Login to try C/C++/Java/PHP code in the editor
Batch SQL Operations
Batch processing कई individual INSERT, UPDATE, या DELETE statements को साथ bundle करके और executeBatch() के ज़रिए एक single network round trip में database को भेजकर bulk data tasks को तेज़ करती है, बजाय हर row के लिए वह round-trip cost एक बार चुकाने के।
उदाहरण: Batch SQL Operations
// Import java.util.* so it can be used by its short name
import java.util.*;
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) {
List<String> batch = List.of(
"INSERT INTO logs VALUES ('a')",
"INSERT INTO logs VALUES ('b')",
"INSERT INTO logs VALUES ('c')"
);
// Print a line to the console
System.out.println("Sending " + batch.size() + " statements in a single round trip via executeBatch()");
}
}
Login to try C/C++/Java/PHP code in the editor
Read Operation (SELECT)
database से data वापस पढ़ना एक PreparedStatement के ज़रिए execute किए SELECT query से किया जाता है। results एक ResultSet के रूप में वापस आते हैं, जिसे आप next() का उपयोग करके row by row iterate करते हैं, हर column को उसके संबंधित typed getter method से निकालते हुए।
उदाहरण: Read Operation (SELECT)
import java.util.*;
public class Main {
public static void main(String[] args) {
List<String> table = List.of("Riya", "Aman");
String sql = "SELECT name FROM users";
for (String row : table) { // simulates iterating a ResultSet with next()
System.out.println(row);
}
}
}
Login to try C/C++/Java/PHP code in the editor
Delete Operation (DELETE)
Rows हटाने के लिए DELETE statement उपयोग होता है, फिर से PreparedStatement के ज़रिए ताकि row identifier SQL string में concatenate होने के बजाय एक bound parameter के रूप में पास हो। executeUpdate() असल में हटाई गई rows की संख्या return करता है, जिसे जांचना यह पुष्टि करने के लिए उचित है कि delete आपकी उम्मीद से मेल खाता है।
उदाहरण: Delete Operation (DELETE)
// Import java.util.* so it can be used by its short name
import java.util.*;
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) {
// Create a new ArrayList object and store it in table
List<String> table = new ArrayList<>(List.of("Riya", "Aman"));
String sql = "DELETE FROM users WHERE name = ?";
// Declare target and set it to "Aman"
String target = "Aman";
// Declare removed and set it to table.remove(target)
boolean removed = table.remove(target);
// Print a line to the console
System.out.println("Executed: " + sql + " -- rows removed: " + (removed ? 1 : 0));
}
}
Login to try C/C++/Java/PHP code in the editor
"... WHERE name = '" + name + "'"जैसे string concatenation से SQL बनाना, जो SQL injection की अनुमति देता है;?placeholders का उपयोग करें।- बिना
WHEREclause केUPDATEयाDELETEलिखना, जो table की हर row बदल देता है या हटा देता है। addBatch()से statements जोड़ना लेकिनexecuteBatch()call करना भूल जाना, जिससे database को कुछ नहीं भेजा जाता।
Chapter Quiz — Complete all 4 topics to unlock
0/4 topics done
Complete these topics first: