SqlCommand command = new SqlCommand(queryString, myConnection);
command.CommandText =
"SELECT CustomerID, CompanyName FROM Customers "
+ "WHERE Country = @Country AND City = @City";
command.Parameters.Add(paramArray);
想知道ado.net源码是怎么实现的.
或是看过的人,给说一说.
它是怎么实现过滤的呢?
你可以通过SQL Server Proflier工具监视一下SQL SERVER最终执行的是什么?
下面是储存过程的形式执行SQL,防止SQL脚本的攻击。
SqlCommand command = new SqlCommand(queryString, myConnection);
command.CommandText =
"SELECT CustomerID, CompanyName FROM Customers "
+ "WHERE Country = @Country AND City = @City";
command.Parameters.Add(paramArray);