}\r
\r
public static Collection<String> getGroupsByClassfication(String classfication) {\r
- List<String> list = new ArrayList<String>();\r
- String sql = "select * from GROUPS where classification = '" + classfication + "'";\r
+ List<String> list = new ArrayList<>();\r
+ String sql = "select * from GROUPS where classification = ?";\r
try {\r
DB db = new DB();\r
@SuppressWarnings("resource")\r
Connection conn = db.getConnection();\r
- try(Statement stmt = conn.createStatement()) {\r
- try(ResultSet rs = stmt.executeQuery(sql)) {\r
+ try(PreparedStatement stmt = conn.prepareStatement(sql)) {\r
+ stmt.setString(1, classfication);\r
+ try(ResultSet rs = stmt.executeQuery()) {\r
while (rs.next()) {\r
int groupid = rs.getInt("groupid");\r
\r