2016-07-07 109 views
0

在主项目类中调用此方法时,填写参数等,我收到一个错误。表中的字段列为ID,我正在从用户字段接收用户输入,并将其与SQL表中的ID字段进行比较。如果来自用户的输入与SQL表中的ID字段和PASSWORD字段相匹配,则应将用户发送到主GUI屏幕。然而,这种情况并非如此。连接认证失败JDBC

错误:

run: java.sql.SQLSyntaxErrorException: Comparisons between 'INTEGER' and 'CHAR (UCS_BASIC)' are not supported. Types must be comparable. String types must also have matching collation. If collation does not match, a possible solution is to cast operands to force them to the default collation (e.g. SELECT tablename FROM sys.systables WHERE CAST(tablename AS VARCHAR(128)) = 'T1') at org.apache.derby.client.am.SQLExceptionFactory40.getSQLException(Unknown Source) at org.apache.derby.client.am.SqlException.getSQLException(Unknown Source) at org.apache.derby.client.am.Statement.executeQuery(Unknown Source) at GUI.Login_Check.CoLogin(Login_Check.java:27) at GUI.Login.btnSubmitActionPerformed(Login.java:208) at GUI.Login.access$200(Login.java:17) at GUI.Login$3.actionPerformed(Login.java:110) at javax.swing.AbstractButton.fireActionPerformed(AbstractButton.java:2022) at javax.swing.AbstractButton$Handler.actionPerformed(AbstractButton.java:2346) at javax.swing.DefaultButtonModel.fireActionPerformed(DefaultButtonModel.java:402) at javax.swing.DefaultButtonModel.setPressed(DefaultButtonModel.java:259) at javax.swing.plaf.basic.BasicButtonListener.mouseReleased(BasicButtonListener.java:252) at java.awt.Component.processMouseEvent(Component.java:6525) at javax.swing.JComponent.processMouseEvent(JComponent.java:3324) at java.awt.Component.processEvent(Component.java:6290) at java.awt.Container.processEvent(Container.java:2234) at java.awt.Component.dispatchEventImpl(Component.java:4881) at java.awt.Container.dispatchEventImpl(Container.java:2292) at java.awt.Component.dispatchEvent(Component.java:4703) at java.awt.LightweightDispatcher.retargetMouseEvent(Container.java:4898) at java.awt.LightweightDispatcher.processMouseEvent(Container.java:4533) at java.awt.LightweightDispatcher.dispatchEvent(Container.java:4462) at java.awt.Container.dispatchEventImpl(Container.java:2278) at java.awt.Window.dispatchEventImpl(Window.java:2750) at java.awt.Component.dispatchEvent(Component.java:4703) at java.awt.EventQueue.dispatchEventImpl(EventQueue.java:758) at java.awt.EventQueue.access$500(EventQueue.java:97) at java.awt.EventQueue$3.run(EventQueue.java:709) at java.awt.EventQueue$3.run(EventQueue.java:703) at java.security.AccessController.doPrivileged(Native Method) at java.security.ProtectionDomain$1.doIntersectionPrivilege(ProtectionDomain.java:75) at java.security.ProtectionDomain$1.doIntersectionPrivilege(ProtectionDomain.java:86) at java.awt.EventQueue$4.run(EventQueue.java:731) at java.awt.EventQueue$4.run(EventQueue.java:729) at java.security.AccessController.doPrivileged(Native Method) at java.security.ProtectionDomain$1.doIntersectionPrivilege(ProtectionDomain.java:75) at java.awt.EventQueue.dispatchEvent(EventQueue.java:728) at java.awt.EventDispatchThread.pumpOneEventForFilters(EventDispatchThread.java:201) at java.awt.EventDispatchThread.pumpEventsForFilter(EventDispatchThread.java:116) at java.awt.EventDispatchThread.pumpEventsForHierarchy(EventDispatchThread.java:105) at java.awt.EventDispatchThread.pumpEvents(EventDispatchThread.java:101) at java.awt.EventDispatchThread.pumpEvents(EventDispatchThread.java:93) at java.awt.EventDispatchThread.run(EventDispatchThread.java:82) Caused by: org.apache.derby.client.am.SqlException: Comparisons between 'INTEGER' and 'CHAR (UCS_BASIC)' are not supported. Types must be comparable. String types must also have matching collation. If collation does not match, a possible solution is to cast operands to force them to the default collation (e.g. SELECT tablename FROM sys.systables WHERE CAST(tablename AS VARCHAR(128)) = 'T1') at org.apache.derby.client.am.Statement.completeSqlca(Unknown Source) at org.apache.derby.client.net.NetStatementReply.parsePrepareError(Unknown Source) at org.apache.derby.client.net.NetStatementReply.parsePRPSQLSTTreply(Unknown Source) at org.apache.derby.client.net.NetStatementReply.readPrepareDescribeOutput(Unknown Source) at org.apache.derby.client.net.StatementReply.readPrepareDescribeOutput(Unknown Source) at org.apache.derby.client.net.NetStatement.readPrepareDescribeOutput_(Unknown Source) at org.apache.derby.client.am.Statement.readPrepareDescribeOutput(Unknown Source) at org.apache.derby.client.am.Statement.flowExecute(Unknown Source) at org.apache.derby.client.am.Statement.executeQueryX(Unknown Source) ... 41 more

代码:

public static void CoLogin(String username, String password){ 
    try{ 
     String dbuser = ""; 
     String dbpass = ""; 
     String url = "jdbc:derby://localhost:1527/Java-App"; 
     String user = username; 
     String pass = password; 
     Connection con = DriverManager.getConnection(url, "admin", "admin"); 

     Statement stmt = con.createStatement(); 
     String SQL = "SELECT * FROM MEMBERS WHERE ID='" + user + "' && PASSWORD='" + pass + "'"; 
     ResultSet rs = stmt.executeQuery(SQL); 

     while(rs.next()){ 
      dbuser= rs.getString("ID"); 
      dbpass = rs.getString("PASSWORD"); 
     } 
     if(user.equals(dbuser) && pass.equals(dbpass)){ 
       Main x = new Main(); 
       x.setVisible(true); 
     } 
     else{ 
      Login x = new Login(); 
      x.setVisible(true); 
     } 

     //Connection con = DriverManager.getConnection(url, user,  pass); 

    } 
    catch(SQLException error){ 
     System.out.println(error.getMessage()); 
    } 
+0

您的错误描述“但是,情况并非如此”太含糊。更深入地挖掘问题根源的一个好方法是调试。检查rs.next()是否至少返回一次“true”。检查由rs.getString(“ID”)和rs.getString(“PASSWORD”)返回的值。检查系统错误日志中是否没有错误。这将缩小根本问题的范围,即使您无法理解其原因,请再次返回结果,我们可以提供帮助。 –

+0

'&&'甚至可以工作吗?我本来期望它是'AND'。您还应该使用参数化查询,而不是将值直接转储到查询字符串中以避免SQL注入。 – JonK

+0

@RobertoLinares我添加了一个sout来打印rs.getString的值,它只是返回发生相同的连接认证失败。所以它基本上直接到了catch语句。 –

回答

0

你的问题可能有很多原因。

但是,如果用户键入username =“”,password =“”他将在任何情况下进行身份验证。还介意SQL injection

1

根据你的日志,你的错误的根本原因是在momment您建立与数据库的连接,在日线:

Connection con = DriverManager.getConnection(url, "admin", "admin"); 

讯息话题Connection authentication failure occurred. Reason: Userid or password invalid.告诉你,“管理员”错误用户或passowrd用于连接到您的德比数据库是不正确的。

你可以做的是,使用验证的数据连接到数据库,检查他们在像数据源资源管理器在Eclpise或数据库资源管理器在Netbeans的数据库客户端之前。一旦确定数据库的验证数据是正确的,请在代码中使用它。

+0

此外,有关Derby如何实现连接身份验证的背景信息,请参阅手册中的身份验证章节:https://db.apache.org/derby/docs/10.12/security/ –

+0

谢谢,它是大写的admin 。但是我遇到了另一个错误。 –

+0

好吧,这个错误似乎与'MEMBERS'表中的数据类型有关。在你的查询中,你假设'ID'和'PASSWORD'字段的类型是'VARCHAR',但是错误表明其中一个实际上是'INTEGER'类型,所以查询中的比较无效。再次检查数据类型,我也建议你先在数据库客户端尝试查询。 –