TBogdan
TBogdan

Reputation: 737

Adding strings with special characters within in SQL Server database by C# ASP.NET application

How can I add in a table with a column of type string (in SQL Server) an string like "[email protected]" , I have problems with special character('@' in this case).Thanks

System.Data.SqlClient.SqlConnection con = new System.Data.SqlClient.SqlConnection(
                         "Data Source=BOGDAN-PC\\BOGDAN;Initial Catalog=ePlanning;Integrated Security=SSPI;Connect Timeout=10;TrustServerCertificate=True ");
                string[] id_dep = ddDepartament.SelectedItem.Text.Split('.');
                con.Open();



                string final = tbemailangajat.Text.

                string sqlstring = " Update angajati set nume='" + tbNumeangajat.Text + "' ,prenume= '" + tbPrenumeangajat.Text + "',email= '" + final + "',telefon= '" + tbTelefonAngajat.Text + "',id_functie= " + ddFunctieAngajat.SelectedItem.Text[0].ToString() + ",id_departament= " + ddDepartament.SelectedItem.Text[0].ToString() + " where id_angajat = " + int.Parse(tbID.Text) + ";";
                System.Data.SqlClient.SqlCommand comm = new System.Data.SqlClient.SqlCommand(sqlstring, con);
                //  System.Data.SqlClient.SqlDataReader reader;
                comm.ExecuteNonQuery();
                con.Close();

Upvotes: 0

Views: 3882

Answers (2)

Jason Meckley
Jason Meckley

Reputation: 7591

don't use sql injection, use parameterized queries instead.

command.CommandText = "insert into table (column) values(@p1)";
command.Parameters.AddWithValue("p1", "[email protected]");

Upvotes: 2

Jen Grant
Jen Grant

Reputation: 2074

varchar should allow for the @ symbol, but for some symbols it requires nvarchar instead of varchar. nvarchar stores unicode and is used to support symbols outside of the ASCII range.

Upvotes: 0

Related Questions