【问题标题】:SQL Database If-Else statementSQL 数据库 If-Else 语句
【发布时间】:2021-12-07 19:28:31
【问题描述】:
private void btnChange_Click(object sender, EventArgs e)
{
    con.Open();

    SqlCommand cmd = con.CreateCommand();
    cmd.CommandType = CommandType.Text;
    cmd.CommandText = "update Customer set MembershipPoint='" + textMembershipPoint.Text + "' where NameCustomer='" + textNameCustomer.Text + "'";

    cmd.ExecuteNonQuery();

    if (cmd.ExecuteScalar() != null)
    {
        textMembershipPoint.Text = Convert.ToString(cmd.ExecuteScalar());
    }
    else if (cmd.ExecuteScalar() != )
    {
        MessageBox.Show("Invalid Name of Customer.");
    }
    else if (cmd.ExecuteScalar() != )
    {
        MessageBox.Show("Invalid Membership Point. Only Number Allowed.");
    }
    else
    {
        MessageBox.Show("Membership Point is changed.");
    }

    con.Close();

    display_data();
}

我有一个名为Customer 的数据库表,其中包含ID_Customer、NameCustomer 和MembershipPoint 列。

当客户输入的名称不在Customer 表中时,输出将显示“客户名称无效”。

如果客户输入了无效的 MembershipPoint,输出将显示“Invalid Membership Point. Only Number Allowed.”。

如果一切正常,则输出将显示“会员积分已更改。”。

谁能告诉我我需要为 if else 语句做些什么才能实现这一目标?

【问题讨论】:

  • 如果客户名称是 John Paul,并且您的数据库有 100 个 John Pauls.. 您要更新所有这些吗?检查这个docs.microsoft.com/en-us/dotnet/api/…如何正确使用sql命令
  • 您当前正在多次执行 SQL 语句 - 首先使用 .ExecuteNonQuery(),然后可能会使用 ExecuteScalar 多次 - 这绝对是一个大禁忌! 执行 一次 并获取您需要的信息 - 不要一遍又一遍地执行它!
  • SQL Injection alert - 您应该不将您的 SQL 语句连接在一起 - 使用 参数化查询 来避免 SQL 注入 - 查看Little Bobby Tables

标签: c# html sql-server


【解决方案1】:

首先,您必须学习使用参数化查询,以避免出现 #1 漏洞 - SQL 注入!这样做 - 总是 - 没有例外。

其次 - 现在,您正在多次执行 UPDATE 语句,这非常糟糕......只需执行它一次,记录结果,然后在结果 - 不要多次执行 SQL 命令。

第三:普遍接受的最佳实践根据需要同时创建SqlConnection 和SqlCommand - 不要在代码之外的某个地方打开连接,让它挂起存在很长一段时间 - 根据需要在此处创建它(并在完成后释放它)。

所以试试这样的:

private void btnChange_Click(object sender, EventArgs e)
{
    // check if the membership points text is a valid INT or not
    int membershipPoints = 0;
    
    if (!int.TryParse(textMembershipPoint.Text, out membershipPoints))
    {
        MessageBox.Show("Invalid Membership Point. Only Number Allowed.");
        return;
    }

    // use a properly parametrized query
    string updateQuery = "UPDATE dbo.Customer SET MembershipPoint = @Points WHERE NameCustomer = @CustomerName;";
    
    // put your SqlConnection and SqlCommand into a proper "using" block
    using (SqlConnection conn = new SqlConnection(connectionString))
    using (SqlCommand cmd = new SqlCommand (updateQuery, con))
    {
        // define the parameters and set their values
        cmd.Parameters.Add("@Points", SqlDbType.Int).Value = membershipPoints;
        cmd.Parameters.Add("@CustomerName", SqlDbType.VarChar, 100).Value = textNameCustomer.Text;
        
        // open connection, execute UPDATE, record number of rows updated, close connection
        con.Open();
        int rowsUpdated = cmd.ExecuteNonQuery();
        con.Close();
        
        // now reason just on the result
        if (rowsUpdated > 0)
        {
            // some rows were updated --> success
            MessageBox.Show("Success - rows updated");
        }
        else
        {
            // no rows were updated --> 
            MessageBox.Show("No rows updated - most likely invalid customer name");
        }
    }
    
    display_data();
}

【讨论】:

    猜你喜欢
    • 2016-11-10
    • 2015-09-03
    • 2019-04-09
    • 1970-01-01
    • 2014-12-03
    • 2014-11-03
    • 1970-01-01
    • 1970-01-01
    • 2017-02-05
    相关资源
    最近更新 更多