一区二区三区在线-一区二区三区亚洲视频-一区二区三区亚洲-一区二区三区午夜-一区二区三区四区在线视频-一区二区三区四区在线免费观看

服務(wù)器之家:專注于服務(wù)器技術(shù)及軟件下載分享
分類導(dǎo)航

PHP教程|ASP.NET教程|Java教程|ASP教程|編程技術(shù)|正則表達(dá)式|C/C++|IOS|C#|Swift|Android|VB|R語言|JavaScript|易語言|vb.net|

服務(wù)器之家 - 編程語言 - ASP教程 - javascript asp教程添加和修改

javascript asp教程添加和修改

2019-10-22 10:18asp技術(shù)網(wǎng) ASP教程

javascript asp教程添加和修改

The Connection Execute():

If you want to retrieve data from a database then you have no choice but to use a Recordset. However, for the purposes of adding, updating, and deleting data you don't necessarily have to have a Recordset. It's up to you.

For the purposes of adding, updating and deleting you can avoid the Recordset by using the Execute() method.

Get Started:

Below is the script for Lesson 19.

<%@LANGUAGE="JavaScript"%>
var strConnect="Provider=Microsoft.Jet.OLEDB.4.0; Data Source=" 
strConnect += Server.MapPath("\\GOP") + "\\datastores\\gop.mdb;"
<!-- METADATA TYPE="typelib" 
FILE="C:\Program Files\Common Files\System\ado\msado15.dll" -->
<HTML>
<HEAD>
<TITLE>Administrator Page - Changing the Mailing List</TITLE>
</HEAD>
<BODY LINK="red" VLINK="red" ALINK="crimson">
<H2>Administrator Page</H2>
<H3>Changing a the Mailing List</H3>
<%
if (Request.Form("Delete") > "")
	{
	var sql="DELETE FROM Address WHERE ID = " + Request.Form("ID") + ";"
	}
else
	{
	var firstName = new String(Request.Form("firstName"))
	var lastName = new String(Request.Form("lastName"))
	var Address = new String(Request.Form("Address"))
	var City = new String(Request.Form("City"))

	var myRegExp = /[']/g;
	firstName = firstName.replace(myRegExp, ''');
	lastName = lastName.replace(myRegExp, ''');
	Address = Address.replace(myRegExp, ''');
	City = City.replace(myRegExp, ''');
	
	var sql="UPDATE Address SET firstName= '" + firstName + "' , lastName='" 
	sql += lastName + "' , Address='" + Address + "' , City='" 
	sql += City + "' , State='" + Request.Form("State") + "' , Zip='" 
	sql += Request.Form("Zip") + "' WHERE ID = " + Request.Form("ID") + ";"
	}
var objConn=Server.CreateObject("ADODB.Connection");
objConn.Open(strConnect)
objConn.Execute(sql)
objConn.Close()
objConn = null;
Response.Write("The member has been updated in the database.")
Response.Write("<A HREF=\"../files/committee.asp\">")
Response.Write("Click here to see it.</A>")
%>

There's no link to see this one in action. I did that for security reasons. I just want to point out a few highlights.

Danger in The Single Quote:

You'll notice that I replace single quote marks with the HTML encoded equivalent. I did that using the following code.

var myRegExp = /[']/g;
firstName = firstName.replace(myRegExp, ''');

The single quote is the only character you cannot input into a database using an ASP application. Everything else is fair game. DO NOT accept any text from users into your database without replacing all single quotes. To use an analogy, the single quote is like a key that opens up your entire database. Hackers will tear your application to shreds if you let someone input single quotes.

Execute( ):

The only other thing I want to spend any time with is objConn.Execute(sql). The variable sql takes on one of two definitions depending on the result of an "if" statement. In this case sql does all the work, and we never need a recordset.

延伸 · 閱讀

精彩推薦
主站蜘蛛池模板: 亚洲成人影院在线观看 | 深夜a| 四虎在线最新地址公告 | 欧美成人免费tv在线播放 | 国产精品免费综合一区视频 | 涩色爱| 五月一区二区久久综合天堂 | yellow最新视频2019 | 九九热只有精品 | 四虎私人影院 | 久久精品国产免费 | 国产午夜大片 | 爆操俄罗斯美女 | 2020韩国r级理论片在线观看 | 侵犯小男生免费视频网站 | www.爱操 | 视频久久 | www.久久av.com| 亚洲 综合 欧美在线 热 | chinese野外gay军人 | 高清在线观看mv的网址免费 | 波多野结衣女教师在线观看 | 国产成人啪精品午夜在线观看 | 福利一区三区 | 福利片免费一区二区三区 | 男人久久天堂 | www久久久| 四虎在线视频免费观看视频 | 齐天大性之七仙女欲春迅雷链接 | 欧美精品一区二区三区久久 | 性夜a爽黄爽 | 国产福利在线观看永久视频 | 亚洲国产成人在人网站天堂 | 日韩欧美不卡视频 | 美女福利视频一区二区 | 免费看美女被靠到爽的视频 | 四虎影院精品在线观看 | 吻戏辣妞范1000免费体验 | 18岁的老处女 | 全肉一女n男np高h乳 | 久久精品AV一区二区无码 |