【发布时间】:2011-09-02 18:19:02
【问题描述】:
我的 ASP.net 4.0 VB 站点上有一个搜索引擎,我需要在其中将搜索结果与其各个页面链接起来。我知道这可以简单地在搜索文本框之后使用提交按钮来完成,但提交按钮不适合我页面上的搜索栏旁边,而且它看起来也不正确。
以前的方法是,结果存储在一个隐藏的 div 中,在那里它们变成了指向其页面的链接。我希望旧搜索的代码可以合并到新搜索中,但我不知道它会去哪里。我能想到的唯一方法是在一段时间或 for 循环中将代码放在 web 服务中。我可能离这里很远,但这就是为什么我要问最好的方法是什么?
<WebMethod()> _
Public Function GetCompletionList(ByVal prefixText As String, ByVal count As Integer) As String()
Dim ProductSql As String = "Select ProductName FROM Product WHERE ProductName LIKE '" & prefixText & "%'"
Dim sqlConn As New SqlConnection
sqlConn.Open()
Dim myCommand As New SqlCommand(ProductSql, sqlConn)
Dim myReader As SqlDataReader = myCommand.ExecuteReader()
Dim myTable As New DataTable
myTable.TableName = "ProductSearch"
myTable.Load(myReader)
sqlConn.Close()
Dim items As String() = New String(myTable.Rows.Count - 1) {}
Dim i As Integer = 0
For Each dr As DataRow In myTable.Rows
items.SetValue(dr("ProductName").ToString(), i)
i += 1
Next
Return items
End Function
<asp:ScriptManager ID="ScriptManager1" runat="server">
<Services>
<asp:ServiceReference Path="ProductSearch.asmx" />
</Services>
</asp:ScriptManager>
<asp:TextBox ID="Search" runat="server" AutoComplete="off"></asp:TextBox>
<asp:AutoCompleteExtender ID="AutoCompleteExtender1" runat="server" TargetControlID="Search" ServicePath="~/ProductSearch.asmx" ServiceMethod="GetCompletionList" MinimumPrefixLength="1" CompletionSetCount="120" EnableCaching="true" CompletionListCssClass="results">
</asp:AutoCompleteExtender>
【问题讨论】:
-
永远不要在 SQL 查询中使用字符串连接。您应该使用带参数的 SqlCommand 对象。您的代码中存在巨大的脚本注入漏洞!
-
哦,是的,对不起,我忘了提。我知道我的代码存在 SQL 注入漏洞,我只想让网站正常工作。一旦我让网站正常工作,我将返回并确保所有代码安全。我对sql注入或防止它一无所知,所以一旦一切完成,我会研究一下。 :) 不过谢谢!
-
@jlg,简称SQL注入,可以让攻击者删除你数据库中的所有记录。所以一定要仔细阅读它!
标签: asp.net vb.net web-services search