?
Solved

JSP page won't accept a variable in the Order By statement.

Posted on 2004-04-05
3
Medium Priority
?
220 Views
Last Modified: 2010-04-01
I have the code below in my JSP page.  
The problem I am running into, is that when I use a variable in the Order By statement for the query, it doesn't recognize it.
If I hard code the Order By, it works.

This first part of code is looking for the Order_by in the url, if not found it defaults.
The second part of code is my query.

Can anyone see what I am doing wrong?
I outputed the URL variable Order_by to the screen, and it gets passed OK.
If I need to include all my page code, then let me know.

 <%
String ORDER_BY = request.getParameter("ORDER_BY");
if( ORDER_BY == null ) ORDER_BY = "CURDATE DESC";
%>

java.sql.ResultSet columns = statement.executeQuery("SELECT * FROM MYTABLE WHERE REQOPEN='OPEN' AND NODENAME='CST'  order by '"+ORDER_BY+"'");

0
Comment
Question by:g118481
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 19

Expert Comment

by:Kuldeepchaturvedi
ID: 10761186
remove the quotes that you are putting in the ORDER_BY
java.sql.ResultSet columns = statement.executeQuery("SELECT * FROM MYTABLE WHERE REQOPEN='OPEN' AND NODENAME='CST'  order by "+ORDER_BY);

that will work

0
 
LVL 1

Author Comment

by:g118481
ID: 10762365
Your answer does not make sense to me.
Please clarify.

Cheers
0
 
LVL 19

Accepted Solution

by:
Kuldeepchaturvedi earned 600 total points
ID: 10762722
In SQL you always do the order by column name...
In your code above while creating a query you are putting single quotes around the order by variable... and hence your query will not work if you do that..
Assuming that your parameter values comes out to be DESC..
 your code will print out
SELECT * FROM MYTABLE WHERE REQOPEN='OPEN' AND NODENAME='CST'  order by 'DESC'

while after my changes it will be

SELECT * FROM MYTABLE WHERE REQOPEN='OPEN' AND NODENAME='CST'  order by DESC

which is the right syntax for the query..
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We are witnesses that everyone is saying that our children shouldn't "play" with a technology because it is dangerous. This article is going to prove that they are wrong.
In today's business world, data is more important than ever for informing marketing campaigns. Accessing and using data, however, may not come naturally to some creative marketing professionals. Here are four tips for adapting to wield data for insi…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question