Click here to Skip to main content
15,896,153 members
Please Sign up or sign in to vote.
1.00/5 (1 vote)
See more:
C#
public bool Insert(User user)
        {
            SqlConnection con = new SqlConnection(new Connection().GetConnectionString());

            string sql = "INSERT INTO User (Email) values (@Email)";
            con.Open();
            SqlCommand cmd = new SqlCommand(sql, con);
            cmd.Parameters.Add("@Email", SqlDbType.VarChar);
            cmd.Parameters["@Email"].Value = User.email;
            //cmd.ExecuteNonQuery();

            bool isInserted = cmd.ExecuteNonQuery() > 0;
            return isInserted;

        }
Posted
Updated 3-Mar-15 0:00am
v2
Comments
Thanks7872 3-Mar-15 6:11am    
By writing code.

How to:
1. SQL Update[^]
2. SQL Delete[^]
However, modify them to use parameterized query so as to prevent sql injection[^]. For example:
Update Parameter:
string sql = "UPDATE users set email = @email where userid= @userid"
SqlCommand cmd = new SqlCommand(sql, con);
cmd.Parameters.AddWithValue("@userid",txtUserID);
cmd.Parameters.AddWithValue("@email",txtEmail);
cmd.ExecuteNonQuery();

Delete Parameter:
string sql = "DELETE FROM users where userid= @userid"
SqlCommand cmd = new SqlCommand(sql, con);
cmd.Parameters.AddWithValue("@userid",txtUserID);
cmd.ExecuteNonQuery();
 
Share this answer
 
v3

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900