使用Params

时间:2017-03-08 08:16:20

标签: mysql vb.net visual-studio insert insert-into

我有这个DataTable我想插入数据,但每次执行此代码时都会出错。

"未知数据类型"

我在模块上有一个函数(所以我不必重写它,我可以从每个表单调用它)来打开MySQL连接。

Imports MySql.Data.MySqlClient
Imports System.Net.Mail

Module Module1
Public MyConnection As New MySqlConnection
Public lastLogon As String = Today.Day & "/" & Today.Month & "/" & Today.Year & TimeOfDay.Hour & ":" & TimeOfDay.Minute & ":" & TimeOfDay.Second
Function ServerConnection()
    Try
        MyConnection.ConnectionString = "server=127.0.0.1;user=root;password=password;database=titulo"
        MyConnection.Open()
        Return True
    Catch ex As Exception
        Return False
    End Function
    'Don't mind this
    + Function SendMail(SendTo As String, subject As String, message As String)
End Function
End Module

所以我使用ServerConnection函数调用它并将连接存储到一个名为MyConnection的公共var中,我可以从其他表单中调用它。

问题是,我有这个代码来创建一个将数据插入表格的帐户:(我很抱歉西班牙语。只需检查代码,不要介意SendMail功能)

 Private Sub btnDo_Click(sender As Object, e As EventArgs) Handles btnDo.Click
    If txtUsername.Text <> "" And txtPassword.Text <> "" And txtPassword2.Text <> "" And txtEmail.Text <> "" Then
        If mailUsed = False Then
            If userUsed = False Then
                If txtPassword.Text <> txtPassword2.Text Then
                    lblError.Text = "Revise sus contraseñas."
                Else
                    lblError.Text = ""
                    Try
                        ServerConnection()
                        Dim MyCommand As New MySqlCommand("INSERT INTO titulo.accounts(id, accountName, accountPassword, accountMail, accountLogon) VALUES(0, @username, @password, @email, @logon)", MyConnection)
                        MyCommand.Parameters.Add("@username", SqlDbType.VarChar, 10).Value = txtUsername.Text
                        MyCommand.Parameters.Add("@password", SqlDbType.VarChar, 16).Value = txtPassword.Text
                        MyCommand.Parameters.Add("@email", SqlDbType.VarChar, 60).Value = txtEmail.Text
                        MyCommand.Parameters.Add("@logon", SqlDbType.VarChar, 22).Value = "First Session."
                        MyCommand.ExecuteNonQuery()
                        Try
                            SendMail(txtEmail.Text, "Nueva cuenta en TITULO", txtUsername.Text & Environment.NewLine & " Se ha creado una cuenta a su nombre en " & My.Application.Info.AssemblyName & Environment.NewLine & "Nombre de cuenta: " & txtUsername.Text & Environment.NewLine & "Contraseña: " & txtPassword.Text)
                        Catch ex As Exception
                            MsgBox(ex.Message)
                        Finally
                            MsgBox("Cuenta creada. Correo enviado a: " & txtEmail.Text & ".")
                        End Try

                    Catch ex As Exception
                        MessageBox.Show("Error en la base de datos." & Environment.NewLine & ex.Message)
                    Finally
                        MyConnection.Close()
                    End Try

                    MsgBox("La cuenta " & txtUsername.Text & " ha sido creada." & Environment.NewLine & "Revise su correo " & txtEmail.Text & " para revisar sus datos.")
                End If
            Else
                lblError.Text = "Ya existe una cuenta con ese nombre."
            End If
        Else
            lblError.Text = "Ese correo ya esta en uso."
        End If
    Else
        lblError.Text = "Revise sus datos."
    End If
End Sub

再次,抱歉西班牙语。 titulo数据库上的我的帐户表具有以下数据类型 id INT NOT NULL AUTO_INCREMENT,

accountName VARCHAR(10)NOT NULL,

accountPassword VARCHAR(16)NOT NULL,

accountMail VARCHAR(60)NOT NULL,

accountLogon VARCHAR(22)NOT NULL,

如果提供任何帮助,我将非常感激。

1 个答案:

答案 0 :(得分:1)

MySql代码应使用MySqlDbType枚举来定义参数的数据类型。您正在使用SqlDbType。

此代码会告诉您两个人没有相同的价值

int x = (int)SqlDbType.VarChar;
int y = (int)MySqlDbType.VarChar;
Console.WriteLine("SqlDbType.VarChar = " + x);   
Console.WriteLine("MySqlDbType.VarChar = " + y);

输出

SqlDbType.VarChar = 22 
MySqlDbType.VarChar = 253

与您的实际问题无关,但我需要告知您代码中存在很大的安全风险。不要以纯文本格式存储密码。始终使用散列算法和salt密钥来存储用户密码的不可逆字节。

Best way to store password in database