本帖最后由 林嘉健 于 2013-1-12 20:13 编辑
王继光 发表于 2013-1-12 19:55
cmd.Parameters.Add(new SqlParameter("username", strName));
cmd.Para ...
字符串呢 我忘记复制上面的代码了。。 - protected void Button1_Click(object sender, EventArgs e)
- {
- //传递form表单里各节点的数据并获得(post方式)
- string strName = Request.Form["txtName"];
- string strPwd = Request.Form["txtPwd"];
- object objectName = null;
- if (strName.Length <= 0)
- {
- objectName = DBNull.Value;
- }
- else
- {
- objectName = strName;
- }
- object objectPwd = null;
- if (strPwd.Length <= 0)
- {
- objectPwd = DBNull.Value;
- }
- else
- {
- objectPwd = strPwd;
- }
- using (SqlConnection conn = new SqlConnection(@"Data Source=.\SQLEXPRESS;AttachDbFilename=|DataDirectory|\Database.mdf;
- Integrated Security=True;User Instance=True"))
- {
- conn.Open();
- using (SqlCommand cmd = conn.CreateCommand())
- {
- cmd.CommandText = "select * from t_User where Username = @username and Password = @userpassword";
- cmd.Parameters.Add(new SqlParameter("@username", strName));
- cmd.Parameters.Add(new SqlParameter("@userpassword", strPwd));
- DataSet dataset = new DataSet();
- SqlDataAdapter ada = new SqlDataAdapter(cmd);
- ada.Fill(dataset);
- DataTable table = dataset.Tables[0];
- for (int i = 0; i < table.Rows.Count; i++)
- {
- DataRow row = table.Rows[i];
- string dbpassword = Convert.ToString(row["userpassword"]);
- if (dbpassword == strPwd)
- {
- Response.Write("<script>alert('登录成功')</script>");
- Session["pageusername"] = strName;
- Session["pageuserpassword"] = strPwd;
- Server.Transfer("buy.aspx");
- }
- //string dbpassword = Convert.ToString(row["userpassword"]);
- Response.Write(dbpassword);
- }
- }
- }
- }
复制代码
|