【发布时间】:2020-07-18 17:51:42
【问题描述】:
我正在创建应用程序,但我有一个问题。
客户端在文本框中写入用户名,例如3个字母并在数据库中搜索(访问)并添加数据库。
示例:用户:Rui。 并在数据库中搜索所有名称用户“Rui”。
//libraries
using Microsoft.VisualStudio.OLE.Interop;
using System;
using System.Collections.Generic;
using System.ComponentModel;
using System.Data;
using System.Data.OleDb;
using System.Diagnostics;
using System.Drawing;
using System.IO;
using System.Linq;
using System.Linq.Expressions;
using System.Reflection;
using System.Runtime.InteropServices;
using System.Text;
using System.Threading.Tasks;
using System.Windows.Forms;
private void textBox1_TextChanged(object sender, EventArgs e)
{
OleDbConnection conexao = new OleDbConnection(string.Format(@"Provider=Microsoft.ACE.OLEDB.12.0;Data Source= {0}\Teste.accdb", Path.GetDirectoryName(Assembly.GetEntryAssembly().Location)));
List<string> Users = new List<string>();
OleDbCommand STK = new OleDbCommand($"SELECT NºCliente, NomeUser, CodigoPostal, NIF", conexao);
STK.CommandText = $" SELECT* FROM MyTable WHERE Str(Lista_Pokemon) like '*{textBox1.Text}*'";
User.Clear();
//this code is invention, probably is wrong
for(int d=0; d<Stk.Count()-1; d++)
User.Add(...);
}
如果你能帮助我,谢谢。这个项目是c#,net framework,数据库是Access 2010。目前我不创建类,但如果你需要告诉我,我需要创建。
【问题讨论】:
-
您的代码中有
comando和STK。你实际使用的是哪一个? -
对不起,stk...我的坏@AlexanderPetrov
-
参数化你的查询,看起来容易受到 SQL 注入的攻击。