Sysnet.Common/DBUtil.cs
(完整代码) 1KBusing System;
using System.Collections.Generic;
using System.Data.SqlClient;
using System.Linq;
using System.Text;
using System.Threading.Tasks;
namespace Sysnet.Common
{
/// <summary>
/// Utility classes for dealing with databases.
/// </summary>
public static class DBUtil
{
/// <summary>
/// Creates a SQL command from a command format string and
/// parameters to avoid SQL injection attacks.
/// </summary>
/// <param name="commandFormatString">
/// SQL command string with format substitution points for
/// parameters.
/// </param>
/// <param name="parameters">Parameters to substitute into the SQL command string.</param>
/// <returns><see cref="SqlCommand"/> using parameters.</returns>
public static SqlCommand CreateSqlCommandWithParameters(
string commandFormatString,
params object[] parameters)
{
SqlCommand command = new SqlCommand();
Util.RequireNotNullOrEmpty(commandFormatString, "commandFormatString");
Util.RequireNotNull(parameters, "parameters");
string[] paramLabels = new string[parameters.Length];
for (int paramIndex = 0; paramIndex < parameters.Length; paramIndex++)
{
paramLabels[paramIndex] = string.Format("@{0}", paramIndex);
command.Parameters.AddWithValue(paramLabels[paramIndex], parameters[paramIndex]);
}
command.CommandText = string.Format(commandFormatString, paramLabels);
return command;
} //*** createSqlCommandWithParameters
} //*** class SqlUtil
}
24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明
AI 解读
登录后可用,每次 10 积分,解读结果公开显示在下面。
还没有人解读过这个文件。
