【问题标题】:How to assign 'NULL' word to a text box (if the textbox is empty) during time?如何在一段时间内将“NULL”字分配给文本框(如果文本框为空)?
【发布时间】:2016-04-18 07:34:04
【问题描述】:

我在从尝试插入的 C# 工具执行 SQL 查询时遇到问题。

如果字符串为空(不是用户输入的),我需要插入 NULL 值。我尝试使用 DB 空值和普通字符串“NULL”来执行 NULL 插入,但我得到的只是一个空值(NULL 关键字的插入),这给了我错误。

如果有人对此有解决方案,请告诉我......

下面是我的代码

if (comboBox_ConfacValue.Text == "")
{
    comboBox_ConfacValue.Text = DBNull.Value.ToString();
}

if (combobox_conversionDescription.Text == "")
{
    combobox_conversionDescription.Text = "NULL";
}

try
{
    con.Open();

    if (MessageBox.Show("Do you really want to Insert these values?", "Confirm Insert", MessageBoxButtons.YesNo) == DialogResult.Yes)
    {
        SqlDataAdapter SDA = new SqlDataAdapter(@" insert INTO Table1 (alpha1,alpha2,alpha3)  VALUES ('" + comboBox_ConfacValue.Text + "','" + combobox_conversionDescription.Text + "','"+ combobox_Description.Text + "',')",con)

        SDA.SelectCommand.ExecuteNonQuery();
        MessageBox.Show("Inserted successfully.");
    }
}

【问题讨论】:

  • 空值必须在插入表 1 (...) 值 ('1',null) 而不是 ('1','null') 的插入中设置无符号。您的插入产生('1','null')。更好的方法是将参数设置为连接
  • 您使用的是什么数据库?
  • 如果有人键入 '); DROP TABLE Table1;--了解Sql Injection及使用参数
  • 伙计们,我明白了...如果我使用子查询值怎么办,每个值都需要一个子查询,所以那时我不能使用你的建议?
  • @blogprogramisty.net.... 是的,我知道应该这样使用它,但是由于我对每个参数值都使用了子查询,所以我没有其他选择可以继续使用这种方法....跨度>

标签: c# .net winforms windows-applications


【解决方案1】:

您应该避免使用这种代码。连接字符串以生成 sql 命令是灾难的根源。解析错误是常见的错误,但更糟糕的敌人潜伏在这种模式背后,称为Sql Injection

    try
    {
        con.Open();
        if (MessageBox.Show("Do you really want to Insert these values?", "Confirm Insert", MessageBoxButtons.YesNo) == DialogResult.Yes)
        {
            // Now the command text is no more built from pieces of 
            // of user input and it is a lot more clear
            SqlCommand cmd = new SqlCommand(@"insert INTO Table1 
                (alpha1,alpha2,alpha3)  
                VALUES (@a1, @a2, @a3)", con);
            // For every parameter placeholder add the respective parameter
            // and set the DbNull.Value when you need it
            cmd.Parameters.Add("@a1", SqlDbType.NVarChar).Value =
                string.IsNullOrEmpty(comboBox_ConfacValue.Text) ? 
                              DbNull.Value : comboBox_ConfacValue.Text);  

            cmd.Parameters.Add("@a2", SqlDbType.NVarChar).Value = 
                string.IsNullOrEmpty(combobox_conversionDescription.Text ) ? 
                              DbNull.Value : combobox_conversionDescription.Text );  

            cmd.Parameters.Add("@a3", SqlDbType.NVarChar).Value = 
                string.IsNullOrEmpty(combobox_Description.Text ) ? 
                              DbNull.Value : combobox_Description.Text );  

            // Run the command, no need to use all the infrastructure of
            // an SqlDataAdapter here....
            int rows = cmd.ExecuteNonQuery();

            // Check the number of rows added before message...
            if(rows > 0) MessageBox.Show("Inserted Successfully.");

【讨论】:

  • 如果我需要对参数值使用子查询怎么办?
  • 从Sql Parser(在服务器上)的角度来看,参数占位符的位置没有区别。
  • 但是我不确定我是否真正理解了您对 subquery 的含义无论如何,如果我的建议不起作用,最好发布一个新问题子查询的完整示例
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多