我試圖用一個文本框作爲過濾器的GridView和最後寫這樣的代碼:這是將文本框綁定到gridview的正確方法嗎?
Protected Sub Button1_Click(ByVal sender As Object, ByVal e As System.EventArgs) Handles Button1.Click
Try
SqlDataSource1.ConnectionString = "connection string goes here"
SqlDataSource1.SelectCommand = "SELECT * FROM TABLE WHERE area LIKE '" + TextBox1.Text + "%'"
'GridView1.DataSource = SqlDataSource1.SelectCommand
SqlDataSource1.DataBind()
GridView1.DataBind()
Catch ex As Exception
MsgBox(ex.ToString)
End Try
End Sub
它的工作原理。不過,我覺得這太簡單,不安全。你能否告訴我應該如何以更專業的方式做到這一點?
準備使用或參數化語句 – thunderbird