数据层的编写。。。防sql攻击注入
下面我们首先介绍数据访问层——DAL层:
.net2.0版的DAL层:
public class SqlHelper
{
private static string connStr = "连接字符串";
public static int ExecComm(string sqlStr, SqlParameter[] par)
{
SqlConnection conn = new SqlConnection(connStr);
conn.Open();
SqlCommand comm = new SqlCommand();
comm.Connection = conn;
comm.CommandType = CommandType.Text;
comm.CommandText = sqlStr;
if (par != null)
{
foreach (SqlParameter p in par)
{
comm.Parameters.Add(p);
}
}
int i = comm.ExecuteNonQuery();
conn.Close();
conn.Dispose();
return i;
}
}
public class UserDal
{
public int AddUser(string userName, string password)
{
string sqlStr = "insert into Users (userName,password) values (@userName,@password)";
SqlParameter[] par = {
new SqlParameter("@userName",userName),
new SqlParameter("@password",password)
};
return SqlHelper.ExecComm(sqlStr, par);
}
}
这样就很简单的实现了DAL层。