gpt4 book ai didi

javascript asp教程添加和修改

转载 作者:qq735679552 更新时间:2022-09-29 22:32:09 34 4
gpt4 key购买 nike

CFSDN坚持开源创造价值,我们致力于搭建一个资源共享平台,让每一个IT人在这里找到属于你的精彩世界.

这篇CFSDN的博客文章javascript asp教程添加和修改由作者收集整理,如果你对这篇文章有兴趣,记得点赞哟.

The Connection Execute()

If you want to retrieve data from a database then you have no choice but to use a Recordset. However, for the purposes of adding, updating, and deleting data you don't necessarily have to have a Recordset. It's up to you. 。

For the purposes of adding, updating and deleting you can avoid the Recordset by using the Execute() method. 。

Get Started

Below is the script for Lesson 19. 。

<%@LANGUAGE="JavaScript"%>var strConnect="Provider=Microsoft.Jet.OLEDB.4.0; Data Source=" strConnect += Server.MapPath("\\GOP") + "\\datastores\\gop.mdb;"<!-- METADATA TYPE="typelib" FILE="C:\Program Files\Common Files\System\ado\msado15.dll" --><HTML><HEAD><TITLE>Administrator Page - Changing the Mailing List</TITLE></HEAD><BODY LINK="red" VLINK="red" ALINK="crimson"><H2>Administrator Page</H2><H3>Changing a the Mailing List</H3><%if (Request.Form("Delete") > "")	{	var sql="DELETE FROM Address WHERE ID = " + Request.Form("ID") + ";"	}else	{	var firstName = new String(Request.Form("firstName"))	var lastName = new String(Request.Form("lastName"))	var Address = new String(Request.Form("Address"))	var City = new String(Request.Form("City"))	var myRegExp = /[']/g;	firstName = firstName.replace(myRegExp, ''');	lastName = lastName.replace(myRegExp, ''');	Address = Address.replace(myRegExp, ''');	City = City.replace(myRegExp, ''');		var sql="UPDATE Address SET firstName= '" + firstName + "' , lastName='" 	sql += lastName + "' , Address='" + Address + "' , City='" 	sql += City + "' , State='" + Request.Form("State") + "' , Zip='" 	sql += Request.Form("Zip") + "' WHERE ID = " + Request.Form("ID") + ";"	}var objConn=Server.CreateObject("ADODB.Connection");objConn.Open(strConnect)objConn.Execute(sql)objConn.Close()objConn = null;Response.Write("The member has been updated in the database.")Response.Write("<A HREF=\"../files/committee.asp\">")Response.Write("Click here to see it.</A>")%>

There's no link to see this one in action. I did that for security reasons. I just want to point out a few highlights. 。

Danger in The Single Quote

You'll notice that I replace single quote marks with the HTML encoded equivalent. I did that using the following code. 。

var myRegExp = /[']/g;firstName = firstName.replace(myRegExp, ''');

The single quote is the only character you cannot input into a database using an ASP application. Everything else is fair game. DO NOT accept any text from users into your database without replacing all single quotes. To use an analogy, the single quote is like a key that opens up your entire database. Hackers will tear your application to shreds if you let someone input single quotes. 。

Execute( )

The only other thing I want to spend any time with is  objConn.Execute(sql) . The variable  sql  takes on one of two definitions depending on the result of an "if" statement. In this case  sql  does all the work, and we never need a recordset. 。

最后此篇关于javascript asp教程添加和修改的文章就讲到这里了,如果你想了解更多关于javascript asp教程添加和修改的内容请搜索CFSDN的文章或继续浏览相关文章,希望大家以后支持我的博客! 。

34 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com