Parameterized queries to different data providers
- From: Dino Buljubasic <dino@xxxxxxxxxxxxxxxxxxx>
- Date: Tue, 29 Nov 2005 20:35:04 GMT
Hi,
I would like to build my app so it can connect to SQL Server, Oracle
or mySQL and query data.
Data queries should be parameterized to reduce impact of SQL
Injection.
SQLServer Dataprovider uses named parameters (i.e. @name)
OracleClient Dataprovider uses named parameters (i.e. :name)
mySQL ODBC Dataprovider uses question marks (i.e. ?) on the place of a
parameter (so order of question marks is important)
How do I write my queries easily so they will work with all 3 of these
data providers?
For example how do I write this to work with all tree:
SELECT a1, a2 FROM table1 WHERE a1 = 'blah' AND a2 = 'blahblah'
thank you
_dino_
.
- Follow-Ups:
- Re: Parameterized queries to different data providers
- From: Martin Robins
- Re: Parameterized queries to different data providers
- From: Marina
- Re: Parameterized queries to different data providers
- From: Miha Markic [MVP C#]
- Re: Parameterized queries to different data providers
- Prev by Date: Re: Concurrency Violations in SqlCeDataAdapter
- Next by Date: Re: Parameterized queries to different data providers
- Previous by thread: Re: VS2005 / Stored Procedure
- Next by thread: Re: Parameterized queries to different data providers
- Index(es):
Relevant Pages
|