javascript asp教程添加和修改

所属分类: 网络编程 / ASP编程 阅读数: 621
收藏 0 赞 0 分享

The Connection Execute():

If you want to retrieve data from a database then you have no choice but to use a Recordset. However, for the purposes of adding, updating, and deleting data you don't necessarily have to have a Recordset. It's up to you.

For the purposes of adding, updating and deleting you can avoid the Recordset by using the Execute() method.

Get Started:

Below is the script for Lesson 19.

<%@LANGUAGE="JavaScript"%>
var strConnect="Provider=Microsoft.Jet.OLEDB.4.0; Data Source=" 
strConnect += Server.MapPath("\\GOP") + "\\datastores\\gop.mdb;"
<!-- METADATA TYPE="typelib" 
FILE="C:\Program Files\Common Files\System\ado\msado15.dll" -->
<HTML>
<HEAD>
<TITLE>Administrator Page - Changing the Mailing List</TITLE>
</HEAD>
<BODY LINK="red" VLINK="red" ALINK="crimson">
<H2>Administrator Page</H2>
<H3>Changing a the Mailing List</H3>
<%
if (Request.Form("Delete") > "")
	{
	var sql="DELETE FROM Address WHERE ID = " + Request.Form("ID") + ";"
	}
else
	{
	var firstName = new String(Request.Form("firstName"))
	var lastName = new String(Request.Form("lastName"))
	var Address = new String(Request.Form("Address"))
	var City = new String(Request.Form("City"))

	var myRegExp = /[']/g;
	firstName = firstName.replace(myRegExp, '&#39;');
	lastName = lastName.replace(myRegExp, '&#39;');
	Address = Address.replace(myRegExp, '&#39;');
	City = City.replace(myRegExp, '&#39;');
	
	var sql="UPDATE Address SET firstName= '" + firstName + "' , lastName='" 
	sql += lastName + "' , Address='" + Address + "' , City='" 
	sql += City + "' , State='" + Request.Form("State") + "' , Zip='" 
	sql += Request.Form("Zip") + "' WHERE ID = " + Request.Form("ID") + ";"
	}
var objConn=Server.CreateObject("ADODB.Connection");
objConn.Open(strConnect)
objConn.Execute(sql)
objConn.Close()
objConn = null;
Response.Write("The member has been updated in the database.")
Response.Write("<A HREF=\"../files/committee.asp\">")
Response.Write("Click here to see it.</A>")
%>

There's no link to see this one in action. I did that for security reasons. I just want to point out a few highlights.

Danger in The Single Quote:

You'll notice that I replace single quote marks with the HTML encoded equivalent. I did that using the following code.

var myRegExp = /[']/g;
firstName = firstName.replace(myRegExp, '&#39;');

The single quote is the only character you cannot input into a database using an ASP application. Everything else is fair game. DO NOT accept any text from users into your database without replacing all single quotes. To use an analogy, the single quote is like a key that opens up your entire database. Hackers will tear your application to shreds if you let someone input single quotes.

Execute( ):

The only other thing I want to spend any time with is objConn.Execute(sql). The variable sql takes on one of two definitions depending on the result of an "if" statement. In this case sql does all the work, and we never need a recordset.

更多精彩内容其他人还在看

ASP编程入门进阶(廿一):DAO SQL之建立数据库表

ASP编程入门进阶(廿一):DAO SQL之建立数据库表
收藏 0 赞 0 分享

ASP万用分页程序

这只是个asp小技巧类的东西,它虽然适合在每个不同文件名里调用这个函数,但是也是有前提的,下面让我们来仔细看看其中的原委
收藏 0 赞 0 分享

ASP项目中的公共翻页模块

ASP项目中的公共翻页模块
收藏 0 赞 0 分享

asp实现批量录入数据的实现

asp实现批量录入数据的实现
收藏 0 赞 0 分享

从文本文件中读取信息并存储入数据库

从文本文件中读取信息并存储入数据库
收藏 0 赞 0 分享

在ASP中使用均速分页法提高分页速度

在ASP中使用均速分页法提高分页速度
收藏 0 赞 0 分享

一些值得一看的代码asp

这篇文章主要介绍了一些值得一看的代码asp
收藏 0 赞 0 分享

3种不同的方法生成文件

3种不同的方法生成文件
收藏 0 赞 0 分享

校验算法与ASP程序

这篇文章主要介绍了校验算法与ASP程序
收藏 0 赞 0 分享

ASP抽取数据的执行效率

ASP抽取数据的执行效率
收藏 0 赞 0 分享
查看更多