Despite the fact that others have already said that this is not a good idea. You can simply "mimic" the behavior of the PreparedStatement through your HTTP call.
Just send some parameters to the call, for example
/sqlInterperter.do?sql=somesql_with_params¶m1=...¶m2=...
At the very least, you can reuse prepared statements on the receiving side.
(However, anyone can send you any statements! Best of all: don't do this)
source share