LosOjos Posted June 19, 2013 Posted June 19, 2013 I wonder if anybody uses WebMatrix here? If so, perhaps you have some ideas about the following... I’ve been working for the past few days in WebMatrix 2, trying to learn the ropes as regards to ASP.NET and Razor (I’m using C# as the base language as I’m already familiar with it). I have to say I’m impressed with how easy and quick it is to code and everything was going so smoothly until I came across one irritating problem I was unable to find a solution for despite my best Googling. It seems that when using parametrized database queries, WebMatrix doesn’t like strings. For instance, the following SQL query will fail: SELECT * FROM aTable WHERE ID='@0' Whereas dropping the string-denoting single quotes does work: SELECT * FROM aTable WHERE ID=@0 As yet, the only way I’ve found around this is to build the query at run time and drop in the string values I need, but of course this doesn’t provide the SQL injection safety net that parametrized queries do. My thoughts are that WebMatrix/Razor isn’t recognizing the parameter as it’s enclosed in quotes, but I’m yet to find a fix for that.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now