Sysnet.Common/DBUtil.cs

(完整代码) 1KB

using System;
using System.Collections.Generic;
using System.Data.SqlClient;
using System.Linq;
using System.Text;
using System.Threading.Tasks;

namespace Sysnet.Common
{
    /// <summary>
    ///     Utility classes for dealing with databases.
    /// </summary>
    public static class DBUtil
    {
        /// <summary>
        ///     Creates a SQL command from a command format string and
        ///     parameters to avoid SQL injection attacks.
        /// </summary>
        /// <param name="commandFormatString">
        ///     SQL command string with format substitution points for
        ///     parameters.
        /// </param>
        /// <param name="parameters">Parameters to substitute into the SQL command string.</param>
        /// <returns><see cref="SqlCommand"/> using parameters.</returns>
        public static SqlCommand CreateSqlCommandWithParameters(
            string commandFormatString,
            params object[] parameters)
        {
            SqlCommand command = new SqlCommand();

            Util.RequireNotNullOrEmpty(commandFormatString, "commandFormatString");
            Util.RequireNotNull(parameters, "parameters");

            string[] paramLabels = new string[parameters.Length];
            for (int paramIndex = 0; paramIndex < parameters.Length; paramIndex++)
            {
                paramLabels[paramIndex] = string.Format("@{0}", paramIndex);
                command.Parameters.AddWithValue(paramLabels[paramIndex], parameters[paramIndex]);
            }

            command.CommandText = string.Format(commandFormatString, paramLabels);
            return command;

        } //*** createSqlCommandWithParameters

    } //*** class SqlUtil
}

24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明

AI 解读

登录后可用,每次 10 积分,解读结果公开显示在下面。

还没有人解读过这个文件。