先看这个文章
http://www.itpub.net/viewthread.php?tid=1441454&pid=17785072&page=1&extra=page%3D1#pid17785072
再看以下处理:
这里主要展现存储函数的一种用法, 比如, 参数是一串用逗号分隔的id, "123,124,125,126", 取得对应的4条记录, 先写一个存储函数, 用来解析id字符串:
- createorreplacefunctionstr2varList(p_stringinvarchar2)returnVarTableType
- as
- v_strlongdefaultp_string||',';
- v_nvarchar2(2000);
- v_dataVarTableType:=VarTableType();
- begin
- loop
- v_n:=instr(v_str,',');
- exitwhen(nvl(v_n,0)=0);
- v_data.extend;
- v_data(v_data.count):=ltrim(rtrim(substr(v_str,1,v_n-1)));
- v_str:=substr(v_str,v_n+1);
- endloop;
- returnv_data;
- end;
create or replace function str2varList( p_string in varchar2 ) return VarTableType
as
v_str long default p_string || ',';
v_n varchar2(2000);
v_data VarTableType := VarTableType();
begin
loop
v_n :=instr( v_str, ',' );
exit when (nvl(v_n,0) = 0);
v_data.extend;
v_data( v_data.count ) := ltrim(rtrim(substr(v_str,1,v_n-1)));
v_str := substr( v_str, v_n+1 );
end loop;
return v_data;
end;
然后查询语句这样写:
- SELECTid,name,birthday,address
- FROMtable(STR2VARLIST('123,124,125,126'))t,t_usere
- WHEREe.id=t.column_value
SELECT id, name, birthday, address
FROM table(STR2VARLIST('123,124,125,126')) t, t_user e
WHERE e.id = t.column_value
也可以这样写:
- SELECTid,name,birthday,address
- FROMt_usere
- WHEREidin(select*fromthe(selectcast(str2varlist(#ids#)asvartabletype)fromdual))
SELECT id, name, birthday, address
FROM t_user e
WHERE id in (select * from the (select cast(str2varlist(#ids#) as vartabletype) from dual))
我们在处理这种情况的时候一般都是将id拼成一段sql, 比如这样:id in(123, 124, 125), 这样虽然能解决问题, 但是不是很安全, 如果有SQL注入的话就会导致问题.