国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 編程 > ASP > 正文

javascript asp教程添加和修改

2024-05-04 10:58:19
字體:
來源:轉載
供稿:網友

The Connection Execute():

If you want to retrieve data from a database then you have no choice but to use a Recordset. However, for the purposes of adding, updating, and deleting data you don't necessarily have to have a Recordset. It's up to you.

For the purposes of adding, updating and deleting you can avoid the Recordset by using the Execute() method.

Get Started:

Below is the script for Lesson 19.

<%@LANGUAGE="JavaScript"%>var strConnect="Provider=Microsoft.Jet.OLEDB.4.0; Data Source=" strConnect += Server.MapPath("http://GOP") + "http://datastores//gop.mdb;"<!-- METADATA TYPE="typelib" FILE="C:/Program Files/Common Files/System/ado/msado15.dll" --><HTML><HEAD><TITLE>Administrator Page - Changing the Mailing List</TITLE></HEAD><BODY LINK="red" VLINK="red" ALINK="crimson"><H2>Administrator Page</H2><H3>Changing a the Mailing List</H3><%if (Request.Form("Delete") > "")	{	var sql="DELETE FROM Address WHERE ID = " + Request.Form("ID") + ";"	}else	{	var firstName = new String(Request.Form("firstName"))	var lastName = new String(Request.Form("lastName"))	var Address = new String(Request.Form("Address"))	var City = new String(Request.Form("City"))	var myRegExp = /[']/g;	firstName = firstName.replace(myRegExp, ''');	lastName = lastName.replace(myRegExp, ''');	Address = Address.replace(myRegExp, ''');	City = City.replace(myRegExp, ''');		var sql="UPDATE Address SET firstName= '" + firstName + "' , lastName='" 	sql += lastName + "' , Address='" + Address + "' , City='" 	sql += City + "' , State='" + Request.Form("State") + "' , Zip='" 	sql += Request.Form("Zip") + "' WHERE ID = " + Request.Form("ID") + ";"	}var objConn=Server.CreateObject("ADODB.Connection");objConn.Open(strConnect)objConn.Execute(sql)objConn.Close()objConn = null;Response.Write("The member has been updated in the database.")Response.Write("<A HREF=/"../files/committee.asp/">")Response.Write("Click here to see it.</A>")%>

There's no link to see this one in action. I did that for security reasons. I just want to point out a few highlights.

Danger in The Single Quote:

You'll notice that I replace single quote marks with the HTML encoded equivalent. I did that using the following code.

var myRegExp = /[']/g;firstName = firstName.replace(myRegExp, ''');

The single quote is the only character you cannot input into a database using an ASP application. Everything else is fair game. DO NOT accept any text from users into your database without replacing all single quotes. To use an analogy, the single quote is like a key that opens up your entire database. Hackers will tear your application to shreds if you let someone input single quotes.

Execute( ):

The only other thing I want to spend any time with is objConn.Execute(sql). The variable sql takes on one of two definitions depending on the result of an "if" statement. In this case

發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
主站蜘蛛池模板: 务川| 台中县| 东兰县| 增城市| 双峰县| 封开县| 濮阳市| 东阳市| 开封县| 阿勒泰市| 庆安县| 甘肃省| 托克逊县| 鄂州市| 惠水县| 泸定县| 武邑县| 东港市| 蓬溪县| 宜兰县| 开封市| 黔东| 新巴尔虎左旗| 沈丘县| 嘉鱼县| 民丰县| 伊宁县| 剑阁县| 阿荣旗| 巴中市| 昌邑市| 沈阳市| 嵩明县| 丰县| 石景山区| 巴塘县| 武冈市| 亚东县| 淮滨县| 三明市| 冷水江市|