public class UserController {
private Connection conn;
public void processUser(HttpServletRequest request) {
String userId = request.getParameter("id"); // Source
String query = "SELECT * FROM users WHERE id = " + userId; // Flow
Statement stmt = conn.createStatement();
ResultSet rs = stmt.executeQuery(query); // Sink
}
}