【问题标题】:Update Statement Syntax Error with Access Database in C# / OledB在 C#/OledB 中使用 Access 数据库更新语句语法错误
【发布时间】:2014-03-30 23:02:27
【问题描述】:

我正在尝试使用 OledB 连接通过 C# 更新 Access 2010 数据库上的数据/记录,并尝试创建一个能够使用数据库插入、更新、删除数据的应用程序。到目前为止,我可以插入数据库并使用 ComboBox 选择一条记录,但目前还没有更新。

出现以下错误:

“System.Data.OleDb.OleDbException”类型的未处理异常 发生在 ClassLibrary2.dll 中

附加信息:UPDATE 语句中的语法错误。

注意:我尝试过使用方括号,但没有太大变化,而是出现了一个致命错误

代码如下:

using System;
using System.Collections.Generic;
using System.Data.OleDb;
using System.Linq;
using System.Text;
using System.Threading.Tasks;
using ClassLibrary;
using System.Data;

namespace ClassLibrary2
{
    public class Class1
    {
        OleDbConnection connection;
        OleDbCommand command;

        private void ConnectTo()
        {
            connection = new OleDbConnection(@"Provider=Microsoft.ACE.OLEDB.12.0;Data Source=F:\CMS\CustomerDatabase.accdb;Persist Security Info=False");
            command = connection.CreateCommand();
        }
        public Class1()
        {
            ConnectTo();
        }

        public void Insert(Customer p)
        {
            try
            {
                command.CommandText = "INSERT INTO CustomerData ([Forename], [Surname], [Email Address], [Home Phone Number], [Mobile Phone Number], [Address], [AreaTown], [County], [Postcode]) VALUES('" + p.Forename1 + "', '" + p.Surname1 + "', '" + p.EAddress1 + "', '" + p.HomePhone1 + "' , '" + p.MobNum1 + "' , '" + p.Address1 + "', '" + p.AreaTown1 + "', '" + p.County1 + "', '" + p.Postcode1 + "')";
                command.CommandType = CommandType.Text;
                connection.Open();

                command.ExecuteNonQuery();
            }
            catch (Exception)
            {
                throw;
            }
            finally
            {
                if (connection != null)
                {
                    connection.Close();
                }
            }
        }

        public List<Customer> FillComboBox()
        {
            List<Customer> CustomersList = new List<Customer>();
            try
            {
                command.CommandText = "SELECT * FROM CustomerData";
                command.CommandType = CommandType.Text;
                connection.Open();

                OleDbDataReader reader = command.ExecuteReader();

                while (reader.Read())
                {
                    Customer p = new Customer();

                    p.Id = Convert.ToInt32(reader["ID"].ToString());
                    p.Forename1 = reader["Forename"].ToString();
                    p.Surname1 = reader["Surname"].ToString();
                    p.EAddress1 = reader["Email Address"].ToString();
                    p.HomePhone1 = reader["Home Phone Number"].ToString();
                    p.MobNum1 = reader["Mobile Phone Number"].ToString();
                    p.Address1 = reader["Address"].ToString();
                    p.AreaTown1 = reader["AreaTown"].ToString();
                    p.County1 = reader["County"].ToString();
                    p.Postcode1 = reader["Postcode"].ToString();

                    CustomersList.Add(p);
                }
                return CustomersList;
            }
            catch (Exception)
            {
                throw;
            }
            finally
            {
                if (connection != null)
                {
                    connection.Close();
                }
            }
        }

        public void Update(Customer oldCustomer, Customer newCustomer)
        {
            try
            {
                command.CommandText = "UPDATE CustomerData SET Forename= '" + newCustomer.Forename1 + "', Surname= '" + newCustomer.Surname1 + "', Email Address= '" + newCustomer.EAddress1 + "', Home Phone Number= '" + newCustomer.HomePhone1 + "', Mobile Phone Number= '" + newCustomer.MobNum1 + "', Address= '" + newCustomer.Address1 + "', AreaTown= '" + newCustomer.AreaTown1 + "', County= '" + newCustomer.County1 + "', Postcode= '" + newCustomer.Postcode1 + "'  WHERE ID= ' + oldCustomer.Id'";
                command.CommandType = CommandType.Text;
                connection.Open();

                command.ExecuteNonQuery();
            }
            catch (Exception)
            {
                throw;
            }
            finally
            {
                if (connection != null)
                {
                    connection.Close();
                }
            }
        }
    }
}

代码有点长见谅

我才刚刚开始使用 C#,所以可能需要更多解释

不介意提供更多细节,请随时询问

【问题讨论】:

标签: c# visual-studio-2010 ms-access oledb


【解决方案1】:

用方括号将包含空格的列名封装起来,类似于您在INSERT 语句中的做法。

..., [Home Phone Number] = '" + newCustomer.HomePhone1 + "', ...

另外,考虑参数化您的查询。它更安全,更容易维护。

..., [Home Phone Number] = @HomePhoneNumber, ...

command.Parameters.AddWithValue("@HomePhoneNumber", newCustomer.HomePhone1);

尽可能避免列名中的空格。您可以轻松地使用下划线,然后您不必记住在引用它们的任何地方都用括号括起来。

【讨论】:

  • 没错,但参数肯定会更安全吗?另外,使用不带空格的常规名称不是更好吗?
  • 是的,你们都是对的,只需要参数化它们。将来我不会使用间距。感谢您的所有帮助
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多