SQL parameterisering
The snippet can be accessed without any authentication.
Authored by
Peter Ravnholt
Eksempel på parameterisering ved ADO.NET kald.
File.cs 412 B
using (var conn = new SqlConnection("my database connection string"))
{
var cmd = conn.CreateCommand();
cmd.CommandText = "select * from Data where name=@name";
cmd.Parameters.Add("name", SqlDbType.NVarChar, 200);
var reader = await cmd.ExecuteReaderAsync();
if (reader.HasRows)
await reader.ReadAsync();
return reader["SomeColumn"];
}
Please register or sign in to comment