ASP.NET Parameters.AddWithValue 簡易化 SQL 指令

 

   Default.aspx.vb (必要部分)
 
   Private Sub Insert_Record(ByVal AAA As String(), ByVal BBB As Integer)
      Dim connectionString1 As String = "Data Source=.\SqlExpress; Initial Catalog=aa; Integrated Security=SSPI"
      Dim con1 As SqlConnection = New SqlConnection(connectionString1)
      con1.Open()
 
      Dim SqlString1 As String = "INSERT INTO School (School_ID, School_Name) VALUES (@School_ID, @School_Name)"
 
      Dim cmd1 As SqlCommand = New SqlCommand(SqlString1, con1)
 
      cmd1.Parameters.AddWithValue("@School_ID", BBB.ToString.Trim)
      cmd1.Parameters.AddWithValue("@School_Name", AAA(0).ToString.Trim)
 
      cmd1.ExecuteNonQuery()
      con1.Close()
   End Sub