sql参数化


 public bool IsInsert(string userName, string password, string remark, string mail, int departId, int power)
 {
 string sql = "insert into S_Admin(UserName,Password,Remark,Mail,DepartId,Power)values(@UserName,@Password,@Remark,@Mail,@DepartId,@Power)";
 SqlConnection connection = new SqlConnection(System.Configuration.ConfigurationManager.ConnectionStrings[""].ToString());
 SqlCommand command = new SqlCommand(sql, connection);
 command.Parameters.Add("@UserName",SqlDbType.NVarChar, 60).Value = userName;
 command.Parameters.Add("@Password", SqlDbType.NVarChar, 60).Value = password;
 command.Parameters.Add("@Remark", SqlDbType.NVarChar, 60).Value = remark;
 command.Parameters.Add("@Mail", SqlDbType.NVarChar, 60).Value = mail;
 command.Parameters.Add("@DepartId", SqlDbType.Int, 4).Value = departId;
 command.Parameters.Add("@Power", SqlDbType.Int, 4).Value = power;
 connection.Open();
 int rowsAffected = command.ExecuteNonQuery();
 connection.Close();
 command.Dispose();
 return rowsAffected > 0;
}

原文地址:https://www.cnblogs.com/YyuTtian/p/4434062.html