搜索查询中的引号出错

时间:2015-07-14 09:02:09

标签: c# mysql

我正在使用SQL查询显示报告。在此报告中,用户可以按客户搜索。所以我创建了一个搜索功能。搜索字段是客户(从下拉列表中选择),搜索字词是用户输入要搜索的文本框中的内容:

StringBuilder SQL = new StringBuilder(SearchSQL);
if (SearchFieldKey != null && SearchFieldKey.Length > 0)
{
  if (SearchTerms != null)
  {
    SQL.Append(" HAVING ");
    for (int i = 0; i < SearchFieldKey.Length; i++)
    {
      if (SearchFields.ContainsKey(SearchFieldKey[i]))
      {
        SQL.Append(SearchFields[SearchFieldKey[i]] + " LIKE ?parameter" + i.ToString());
        param.Add(new MySqlParameter("parameter" + i.ToString(),
          "%" + SearchTerms[i] + "%"));

        if (i != SearchFieldKey.Length - 1)
          SQL.Append(" OR ");
      }
      else
        throw new Exception("Error: Attempted to search on invalid field. Check SearchFields Argument.");
    }
  }
}

SQL.Append(" '); ");
SQL.Append ("prepare stmt from @sql; execute stmt; deallocate prepare stmt;");

此函数将HAVING查询添加到显示报告(SearchSQL)的查询的末尾。问题在于LIKE附近的引号。查询结束返回:

WHERE c.Company_ID = ', 135,
' GROUP BY c.ID  HAVING c.Name LIKE "%TEST%" ');

但由于引用位于语句的末尾,因此无法读取传入其中的参数,因此我收到此错误:

  

您的SQL语法有错误;检查与MySQL服务器版本对应的手册,以便在第23行的'?parameter0'附近使用正确的语法

所以我需要这样的查询:

WHERE c.Company_ID = ', 135,
' GROUP BY c.ID HAVING c.Name LIKE', "%TEST%" );

在LIKE之后看到引号已经移动并且添加了逗号。这是我需要做的工作来使查询工作。但是当我尝试在我当前的代码中执行此操作时会导致错误。

  

您的SQL语法有错误;检查与MySQL服务器版本对应的手册,以便在第23行'%TEST%'附近使用正确的语法

那么我需要在搜索功能中做些什么呢?

我将查询粘贴到MySQL Workbench中,以便更清楚地看到发生了什么。

问题在于:

enter image description here

查看LIKE“%PRL%”是如何全部为绿色,因为它包含在引号中,因此它没有读取参数。

现在看看应该如何:

enter image description here

在关闭之后关闭引用,现在可以读取参数。所以问题在于我的代码。我需要改变什么才能让它发挥作用?

这是完整的SearchSQL函数:

private static string SearchSQL
{
  get
  {
    return @"SET group_concat_max_len=10000000;
             set @sql = null;
             select group_concat(distinct
               concat('MAX(CASE WHEN pt.Code = ''', 
                             pt.Code ,
                           ''' THEN jp.AdvisedQty ELSE 0 END) AS `',
                           pt.Code, '`')
                     ) into @sql
                                                                                            FROM customer c
                 LEFT JOIN job_address ja ON c.AccountCode = ja.Code AND c.Company_ID = ja.Company_ID
                 JOIN  AddressType jat ON ja.AddressType = jat.ID and jat.Description = 'Debtor'
                 LEFT JOIN job_new jn ON ja.JobID = jn.ID
                 LEFT JOIN job_pieces jp ON ja.JobID = jp.ID
                 LEFT JOIN piecestype pt on jp.TypeID = pt.ID
                 WHERE c.Company_ID = ?compid;

                 set @sql = concat('select c.Name, COUNT(distinct jn.ID) as Jobs,
                   SUM((select COUNT(ID) from jobstat where Status = ''DEL'' AND JobID = jn.ID)) as Delivered,
                  SUM((select COUNT(ID) from jobstat where Status = ''POD'' AND JobID = jn.ID)) as POD,
                  (select COUNT(job_debriefs.ID) from job_debriefs WHERE JobID = jn.JobNo) as Debriefs,
                  sum(jn.OutTurn) as Outturn,
                  SUM(jn.ActualWeight) as GrossWt,
                  SUM(jn.CBM) as CBM,
                  jn.Department,
                  (SELECT Name FROM job_address WHERE AddressType =3 AND JobID = jn.ID) as CollectName,
                  (SELECT Name FROM job_address WHERE AddressType =2 AND JobID = jn.ID) as DeliverName,
                  ', @sql, ' 
                  FROM customer c
                   LEFT JOIN job_address ja ON c.AccountCode = ja.Code AND c.Company_ID = ja.Company_ID
                   JOIN  AddressType jat ON ja.AddressType = jat.ID and jat.Description = ''Debtor''
                   LEFT JOIN job_new jn ON ja.JobID = jn.ID
                   LEFT JOIN job_pieces jp ON ja.JobID = jp.ID
                   LEFT JOIN piecestype pt on jp.TypeID = pt.ID
                   WHERE c.Company_ID = ', ?compid,
                    ' GROUP BY c.ID";
  }
}

1 个答案:

答案 0 :(得分:0)

以下是这个问题的答案:

 StringBuilder SQL = new StringBuilder(SearchSQL);
            if (SearchFieldKey != null && SearchFieldKey.Length > 0)
            {
                if (SearchTerms != null)
                {
                    SQL.Append(" HAVING ");
                    for (int i = 0; i < SearchFieldKey.Length; i++)
                    {
                        if (SearchFields.ContainsKey(SearchFieldKey[i]))
                        {

                            SQL.Append(SearchFields[SearchFieldKey[i]] + " LIKE ', ?parameter" + i.ToString());
                            param.Add(new MySqlParameter("parameter" + i.ToString(), "\'%" + SearchTerms[i] + "%\'"));

                            if (i != SearchFieldKey.Length - 1)
                                SQL.Append("', OR ");

                        }
                        else
                            throw new Exception("Error: Attempted to search on invalid field. Check SearchFields Argument.");
                    }
                }

            }
            else
            {
                SQL.Append("'");
            }

            SQL.Append("); ");
            SQL.Append ("prepare stmt from @sql; execute stmt; deallocate prepare stmt;");

在LIKE之后我错过了一个空格,我添加了一个关闭引用的其他内容