如何在.net web apps中使用参数进行长查询

use*_*753 0 c# web-applications .net-4.0 sql-server-2008-r2

假设您有一个冗长,复杂的查询来获取需要一些参数的结果.任何人都会这样做,但为了一个例子:

SELECT
    q.PROD_ID, q.NAME, q.STANDARD_PROD, q.DESCRIPTION, q.PART_NUMBER,
    q.COMMENTS, q.DESCRIPTION_URL,
    PROD_CATEGORY.DESCRIPTION AS CATEGORY_DESCRIPTION,
    PROD_TYPES.DESCRIPTION AS PROD_TYPE
FROM
    (SELECT
        PROD.PROD_ID,
        PROD.PROD_TYPE_ID,
        PROD.NAME,
        PROD.STANDARD_PROD,
        PROD.PROD_CATEGORY_ID,
        PROD.DESCRIPTION,
        PROD.PART_NUMBER,
        PROD.COMMENTS,
        PROD.DESCRIPTION_URL
     FROM
        (SELECT
            PROD_ID,
            PROD_TYPE_ID
         FROM
            XREF_PRODSYS
         WHERE
            (PROD_TYPE_ID = (SELECT
                                PROD_TYPE_ID
                             FROM
                                PROD_TYPES
                             WHERE
                                (NAME LIKE @prod_type_name)))) AS p
     LEFT OUTER JOIN PROD ON p.PROD_ID = PROD.PROD_ID
     WHERE
        (PROD.NAME LIKE @prod_name)
        AND (PROD.HIDDEN = 0)) AS q
LEFT OUTER JOIN PROD_CATEGORY ON q.PROD_CATEGORY_ID = PROD_CATEGORY.PROD_CATEGORY_ID
LEFT OUTER JOIN PROD_TYPES ON q.PROD_TYPE_ID = PROD_TYPES.PROD_TYPE_ID
Run Code Online (Sandbox Code Playgroud)

此特定查询需要两个参数,可能通过GET/POST传递给.NET Web应用程序.

有没有更简洁的方法来存储这么长的查询,而不是把它放在webapp页面的C#源代码中?我知道下面的"快速和脏"方法工作正常,但它确实使代码扩展了很多,并且变得有点难以管理.例如:

    //inside Page_Load...
    SqlCommand cmd = new SqlCommand();
    cmd.Connection = con;
    cmd.Parameters.Add("@prod_type_name", SqlDbType.VarChar).Value = _type_name;
    cmd.Parameters.Add("@prod_name", SqlDbType.VarChar).Value = _prod_name;
    cmd.CommandText = @"
    SELECT     q.PROD_ID, q.NAME, q.STANDARD_PROD, q.DESCRIPTION, q.PART_NUMBER, q.COMMENTS, q.DESCRIPTION_URL, 
              PROD_CATEGORY.DESCRIPTION AS CATEGORY_DESCRIPTION, PROD_TYPES.DESCRIPTION AS PROD_TYPE
    FROM         (SELECT     PROD.PROD_ID, PROD.PROD_TYPE_ID, PROD.NAME, PROD.STANDARD_PROD, PROD.PROD_CATEGORY_ID, PROD.DESCRIPTION, 
                                      PROD.PART_NUMBER, PROD.COMMENTS, PROD.DESCRIPTION_URL
               FROM          (SELECT     PROD_ID, PROD_TYPE_ID
                                       FROM          XREF_PRODSYS
                                       WHERE      (PROD_TYPE_ID =
                                                                  (SELECT     PROD_TYPE_ID
                                                                    FROM          PROD_TYPES
                                                                    WHERE      (NAME LIKE @prod_type_name)))) AS p LEFT OUTER JOIN
                                      PROD ON p.PROD_ID = PROD.PROD_ID
               WHERE      (PROD.NAME LIKE @prod_name) AND (PROD.HIDDEN = 0)) AS q LEFT OUTER JOIN
              PROD_CATEGORY ON q.PROD_CATEGORY_ID = PROD_CATEGORY.PROD_CATEGORY_ID LEFT OUTER JOIN
              PROD_TYPES ON q.PROD_TYPE_ID = PROD_TYPES.PROD_TYPE_ID
              ";
              //... do stuff with cmd
Run Code Online (Sandbox Code Playgroud)

Jus*_*ony 6

为什么不把这一切都放入存储过程并调用存储过程,适当地传入参数?

如何创建存储过程

...
cmd.CommandText = "sprocname";
cmd.CommandType = CommandType.StoredProcedure
...
Run Code Online (Sandbox Code Playgroud)