Click here to Skip to main content
15,892,746 members
Please Sign up or sign in to vote.
0.00/5 (No votes)
my code works fine.. i was thinking if theirs another way to parameterized my query?
please help.. newbie..

something like..

string query = "Select * from tblresident where gender=@1";


What I have tried:

SqlConnection cnn = new SqlConnection(cs.constring());
cnn.Open();
string query = "Select * from tblresident where gender='"+textBox1.Text+"'";
SqlDataAdapter da = new SqlDataAdapter(query, cnn);
DataSet ds = new DataSet();
da.Fill(ds, "tblresident");
rpt.Load(System.Windows.Forms.Application.StartupPath + "\\reports\\CrystalReport1.rpt");
rpt.SetDataSource(ds);
crystalReportViewer1.ReportSource = rpt;
Posted
Updated 1-Nov-17 17:51pm

1 solution

Yes
SqlConnection cnn = new SqlConnection(cs.constring());
cnn.Open();
string query = "Select * from tblresident where gender=@gender";
SqlCommand cmd = new SqlCommand(query, cnn);
cmd.Parameters.AddWithValue("@gender", textBox1.Text);
SqlDataAdapter da = new SqlDataAdapter(cmd);
DataSet ds = new DataSet();
da.Fill(ds, "tblresident");
 
Share this answer
 
v2
Comments
akosisugar 2-Nov-17 21:04pm    
thank you sir!
Karthik_Mahalingam 2-Nov-17 22:32pm    
Welcome

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900