C#C
C#3y ago
Aria🎶

Parameterising this sql?

void Insert()
        {
            string query = "INSERT INTO StudentTable (YearGroup,FormGroup,FirstName,LastName,ScienceType) VALUES" + "(@studentID,@yearGroup,@formGroup,@firstName,@lastName,@scienceType";
            cmd = new OleDbCommand(query, connection);
            
            cmd.Parameters.AddWithValue("@yearGroup",formGroupTextBox);
            cmd.Parameters.AddWithValue("@formGroup",formGroupTextBox.Text);
            cmd.Parameters.AddWithValue("@firstName",firstNameTextBox.Text);
            cmd.Parameters.AddWithValue("@lastName",lastNameTextBox.Text);
            cmd.Parameters.AddWithValue("@scienceType",scienceClassTextBox.Text);
            
            connection.Open();
            cmd.ExecuteNonQuery();
            connection.Close();
            GetDatabaseConnection1();
        }
Screenshot_34.png
Was this page helpful?