Click here to Skip to main content
15,922,584 members
Home / Discussions / C#
   

C#

 
GeneralRe: string.Empty and null Pin
radic.feng27-Aug-05 18:10
radic.feng27-Aug-05 18:10 
Questionparameterized query Pin
nidhelp25-Aug-05 15:11
nidhelp25-Aug-05 15:11 
AnswerRe: parameterized query Pin
jdkulkarni25-Aug-05 18:32
jdkulkarni25-Aug-05 18:32 
GeneralRe: parameterized query Pin
nidhelp25-Aug-05 18:53
nidhelp25-Aug-05 18:53 
GeneralRe: parameterized query Pin
jdkulkarni25-Aug-05 18:59
jdkulkarni25-Aug-05 18:59 
GeneralRe: parameterized query Pin
nidhelp25-Aug-05 19:20
nidhelp25-Aug-05 19:20 
GeneralRe: parameterized query Pin
jdkulkarni25-Aug-05 19:29
jdkulkarni25-Aug-05 19:29 
GeneralRe: parameterized query Pin
nidhelp25-Aug-05 19:40
nidhelp25-Aug-05 19:40 
GeneralRe: parameterized query Pin
jdkulkarni25-Aug-05 19:47
jdkulkarni25-Aug-05 19:47 
GeneralRe: parameterized query Pin
nidhelp25-Aug-05 20:02
nidhelp25-Aug-05 20:02 
GeneralRe: parameterized query Pin
jdkulkarni25-Aug-05 20:47
jdkulkarni25-Aug-05 20:47 
GeneralRe: parameterized query Pin
nidhelp25-Aug-05 20:58
nidhelp25-Aug-05 20:58 
GeneralRe: parameterized query Pin
nidhelp25-Aug-05 21:19
nidhelp25-Aug-05 21:19 
GeneralRe: parameterized query Pin
jdkulkarni25-Aug-05 23:48
jdkulkarni25-Aug-05 23:48 
GeneralRe: parameterized query Pin
nidhelp26-Aug-05 5:42
nidhelp26-Aug-05 5:42 
GeneralRe: parameterized query Pin
jdkulkarni28-Aug-05 18:19
jdkulkarni28-Aug-05 18:19 
GeneralRe: parameterized query Pin
Luis Alonso Ramos25-Aug-05 19:43
Luis Alonso Ramos25-Aug-05 19:43 
GeneralRe: parameterized query Pin
jdkulkarni25-Aug-05 19:54
jdkulkarni25-Aug-05 19:54 
GeneralRe: parameterized query Pin
Daniel Turini26-Aug-05 2:12
Daniel Turini26-Aug-05 2:12 
GeneralRe: parameterized query Pin
Not Active26-Aug-05 3:08
mentorNot Active26-Aug-05 3:08 
GeneralRe: parameterized query Pin
jdkulkarni26-Aug-05 3:23
jdkulkarni26-Aug-05 3:23 
GeneralRe: parameterized query Pin
Not Active26-Aug-05 3:33
mentorNot Active26-Aug-05 3:33 
AnswerRe: parameterized query Pin
Luis Alonso Ramos26-Aug-05 3:54
Luis Alonso Ramos26-Aug-05 3:54 
Just type something with a ' in there and you code will blow up. If you have a text box where I enter a date, and I change the culture of the operating system, you'll get erroneous date.

It's really easy to have parameterized queries, and even access has them. Compare this:
string sql = "SELECT * FROM Users WHERE UserName = '" + txtUserName.Text "' AND Password = '" + txtPassword.Text + "'";
OleDbCommand cmd = new OleDbCommand(cmd, conn);
to this:
string sql = "SELECT * FROM Users WHERE UserName = ? AND Password = ?";
OleDbCommand cmd = new OleDbCommand(cmd, conn);
cmd.Parameters.Add("", txtUserName.Text);  // In Access, parameter name doesn't
cmd.Parameters.Add("", txtPassword.Text);  // matter, it's by position
Easier to read in my opinion, way much more secure and robust, and easier to maintain.

-- LuisR




Luis Alonso Ramos
Intelectix - Chihuahua, Mexico

Not much here: My CP Blog!


The amount of sleep the average person needs is five more minutes. -- Vikram A Punathambekar, Aug. 11, 2005
GeneralRe: parameterized query Pin
nidhelp26-Aug-05 6:10
nidhelp26-Aug-05 6:10 
QuestionTEXT BOX TEXT TO DOUBLE? Pin
...---...25-Aug-05 14:56
...---...25-Aug-05 14:56 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.