【问题标题】:Update user profile in website更新网站中的用户资料
【发布时间】:2018-06-19 18:16:38
【问题描述】:

在我的asp.net网站中,如果旧密码正确,我们可以更新用户的电子邮件地址、密码、地点和个人信息。现在我要做的是,登录,然后使用此代码进行更新:

 protected void update_profile(object sender, EventArgs e)
    {
        string constr = ConfigurationManager.ConnectionStrings["Khulna_website"].ConnectionString;
        using (SqlConnection connection = new SqlConnection(constr))
        {
            string user_email = (string)(Session["User"]);
            string pass = encrypt_pass(old_password.Text);
            if (pass != (string)(Session["Password"]))
            {
                pass_err_message.Text = "Wrong password";
                pass = (string)Session["Password"];
            }
            else
            {
                pass = encrypt_pass(new_password.Text);
            }
            string insertQuery = "update dbo.users set user_password=@new_password, user_place = @new_place, user_about=@new_about where user_email =" +user_email;
            SqlCommand com = new SqlCommand(insertQuery, connection);
            connection.Open();
            com.Parameters.AddWithValue("@new_password", pass);
            com.Parameters.AddWithValue("@new_about", new_about.Text);
            com.Parameters.AddWithValue("@new_place", new_place.Text);
            try
            {
                com.ExecuteNonQuery();
                upload_err_message.Text = "Successfully uploaded";
                connection.Close();
            }
            catch (Exception ex)
            {
                profile_settings_err_message.Text = "Update error: " + ex.Message;
            }

        }

    }

但是当我尝试更新时,它说:更新错误:无法绑定多部分标识符“abcde@gmail.com”。我的会话消失了!我想可能是由于外键,所以我删除了数据库的所有外键,但它仍然在发生。这里有什么问题?

编辑:我已经添加了外键,因为我需要它们来删除级联。我只是删除了它们,看看它是否有效。

【问题讨论】:

  • 您不应该通过字符串连接形成 SQL 查询。如果你看到它,那是一种巨大的代码气味。您应该停止并重新评估:您可能需要使用参数。如果您不遵循此建议,您可能会遇到类似的问题,甚至更糟的是SQL Injection Attacks。
  • 您似乎以加密形式存储密码。这不是一个好主意。密码应该是单向散列和加盐的。然后您将比较密码的散列形式以确定有效性。
  • 谢谢,我会处理的

标签: asp.net sql-update


【解决方案1】:

我只是猜测,但我相信您的问题会在这里找到:

"... user_email =" +user_email;

尝试做类似的事情

"... user_email = @email";
com.Parameters.AddWithValue("@email", user_email);

这是更好的方法......但是,如果您想变得懒散,您应该能够将电子邮件用单引号括起来。

"... user_email = '" + user_email + "'";

我希望这会有所帮助!

【讨论】:

  • 是的,它有效,但是会话停止了!但为什么它以前不起作用?!
  • 也许会话超时了?我不知道您的应用程序是如何设置的,但这是可能的。不知道为什么会话不起作用,我只知道您应该始终清理您的查询!
猜你喜欢
  • 1970-01-01
  • 2019-10-24
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多