## 自定义SQL语句 - sql语句为: ``` select * from user where name={{@name}} and age={{@age}} limit 3 ``` - 此sql语句的编码为`my-select-list` ## 调用测试 ![](https://oss.showapi.com/doc/3111/21/e4c41ad60baa_1612925479704.png?x-oss-process=image/resize,p_100) 其中输入的json串showapi_sql_params,值为: ``` { "name": "李四", "age": 28 } ``` name和age属性将赋值于这个sql语句: ``` select * from user where name={{@name}} and age={{@age}} limit 3 ``` 最终执行的sql语句是: ``` select * from user where name='李四' and age=28 limit 3 ``` >使用{{@变量}}的形式,接口会自动判断是否加单引号,并做sql反注射。