未提供的参数化查询

sar*_*nan 10 vb.net sql-server asp.net visual-studio-2008

我一直收到这个错误:

参数化查询'(@AdminEmail nvarchar(4000),@ AdminPassword nvarchar(4000))SELECT'需要参数'@AdminEmail',这是未提供的.

码:

Public Function AuthenticateAdmin() As Boolean
    Dim Success As Boolean

    Dim strConn As String
    strConn = ConfigurationManager.ConnectionStrings("HMVDb").ToString
    Dim conn As New SqlConnection(strConn.ToString())

    Dim cmd As New SqlCommand("SELECT * FROM Admin WHERE AdminEmail=@AdminEmail AND Adminpassword=@Adminpassword", conn)
    cmd.Parameters.AddWithValue("@AdminEmail", EMail)
    cmd.Parameters.AddWithValue("@AdminPassword", Password)

    Dim da As New SqlDataAdapter(cmd)

    Dim ds As New DataSet

    conn.Open()
    da.Fill(ds, "Admin")
    conn.Close()

    If ds.Tables("Admin").Rows.Count > 0 Then

        Dim aemail As String = ds.Tables("Admin").Rows(0).Item("AdminEmail")
        Dim apass As String = ds.Tables("Admin").Rows(0).Item("AdminPassword")
        Dim aid As Integer = ds.Tables("Admin").Rows(0).Item("AdminID")
        Dim aname As String = ds.Tables("Admin").Rows(0).Item("AdminName")

        If EMail = aemail And Password = apass Then
            ID = aid ' Shopper ID that identify Ecader
            Name = aname
            Success = True 'Shopper is authenticated
        Else
            Success = False 'Authentication fail
        End If
    End If


    'Return the authentication result to calling program
    Return Success
End Function
Run Code Online (Sandbox Code Playgroud)

Pie*_*ant 42

您的@AdminEmail变量EMail为null.您无法传递null必需的参数.使用DBNull.Value.

使用时null,您通知Sql Server您正在省略该参数.这对于具有默认值的可选参数很有用,但会导致所需参数出错.

我建议您在将值传递给命令参数时始终使用实用程序函数.

例如:

public static object GetDataValue(object value)
{
   if(value == null)
   {
       return DBNull.Value;
   }

   return value;
}
Run Code Online (Sandbox Code Playgroud)

然后使用

cmd.Parameters.AddWithValue("@AdminEmail", GetDataValue(EMail))
Run Code Online (Sandbox Code Playgroud)