我写这个主要是为了解决sql注入 原sql有sql注入, 结果:select req_msg_id from account_message_info where req_msg_id in ('1230','1231','1232','1233','1234') and user_card_no in('123','123','123','123','123') 但是#直接替换的话,是只有一个字符串了, 结果: select req_msg_id from account_message_in…