語言

SqlDataSource.Insert 方法

定義

使用 InsertCommand SQL 字串及集合中 InsertParameters 的任何參數執行插入操作。

public:
 int Insert();
public int Insert();
member this.Insert : unit -> int
Public Function Insert () As Integer

傳回

一個代表插入底層資料庫的列數值。

例外狀況

他們 SqlDataSource 無法與底層資料來源建立連結。

範例

以下程式碼範例示範如何利用 SqlDataSource 控制項和簡單的網頁表單頁面將資料插入資料庫。 資料表中的當前資料會顯示在控制中 DropDownList 。 你可以在控制項輸入數值 TextBox ,然後點擊 插入 按鈕來新增紀錄。 當按下 插入 按鈕時,指定的數值會入資料庫,然後 DropDownList 再重新整理。

Important

此範例包含一個接受使用者輸入的文字框,這可能構成安全威脅,且參數中插入數值且未經驗證,這同樣是潛在的安全威脅。 在執行查詢前,請利用事件 Inserting 驗證參數值。 欲了解更多資訊,請參閱 腳本漏洞概述。

Note

這個範例展示了如何使用宣告式語法來存取資料。 關於如何用程式碼而非標記存取資料,請參見 「在 Visual Studio 存取資料」。

<%@Page  Language="C#" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<script runat="server">
private void InsertShipper (object source, EventArgs e) {
  SqlDataSource1.Insert();
}
</script>
<html xmlns="http://www.w3.org/1999/xhtml" >
  <head runat="server">
    <title>ASP.NET Example</title>
</head>
<body>
    <form id="form1" runat="server">

      <asp:dropdownlist
        id="DropDownList1"
        runat="server"
        datasourceid="SqlDataSource1"
        datatextfield="CompanyName"
        datavaluefield="ShipperID" />

<!-- Security Note: The SqlDataSource uses a FormParameter,
     Security Note: which does not perform validation of input from the client.
     Security Note: To validate the value of the FormParameter, handle the Inserting event. -->

      <asp:sqldatasource
        id="SqlDataSource1"
        runat="server"
        connectionstring="<%$ ConnectionStrings:MyNorthwind %>"
        selectcommand="SELECT CompanyName,ShipperID FROM Shippers"
        insertcommand="INSERT INTO Shippers (CompanyName,Phone) VALUES (@CoName,@Phone)">
          <insertparameters>
            <asp:formparameter name="CoName" formfield="CompanyNameBox" />
            <asp:formparameter name="Phone"  formfield="PhoneBox" />
          </insertparameters>
      </asp:sqldatasource>

      <br /><asp:textbox
           id="CompanyNameBox"
           runat="server" />

      <asp:RequiredFieldValidator
        id="RequiredFieldValidator1"
        runat="server"
        ControlToValidate="CompanyNameBox"
        Display="Static"
        ErrorMessage="Please enter a company name." />

      <br /><asp:textbox
           id="PhoneBox"
           runat="server" />

      <asp:RequiredFieldValidator
        id="RequiredFieldValidator2"
        runat="server"
        ControlToValidate="PhoneBox"
        Display="Static"
        ErrorMessage="Please enter a phone number." />

      <br /><asp:button
           id="Button1"
           runat="server"
           text="Insert New Shipper"
           onclick="InsertShipper" />

    </form>
  </body>
</html>
<%@Page  Language="VB" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<script runat="server">
Private Sub InsertShipper (ByVal Source As Object, ByVal e As EventArgs)
  SqlDataSource1.Insert()
End Sub ' InsertShipper
</script>
<html xmlns="http://www.w3.org/1999/xhtml" >
  <head runat="server">
    <title>ASP.NET Example</title>
</head>
<body>
    <form id="form1" runat="server">

      <asp:dropdownlist
        id="DropDownList1"
        runat="server"
        datasourceid="SqlDataSource1"
        datatextfield="CompanyName"
        datavaluefield="ShipperID" />

<!-- Security Note: The SqlDataSource uses a FormParameter,
     Security Note: which does not perform validation of input from the client.
     Security Note: To validate the value of the FormParameter, handle the Inserting event. -->

      <asp:sqldatasource
        id="SqlDataSource1"
        runat="server"
        connectionstring="<%$ ConnectionStrings:MyNorthwind %>"
        selectcommand="SELECT CompanyName,ShipperID FROM Shippers"
        insertcommand="INSERT INTO Shippers (CompanyName,Phone) VALUES (@CoName,@Phone)">
          <insertparameters>
            <asp:formparameter name="CoName" formfield="CompanyNameBox" />
            <asp:formparameter name="Phone"  formfield="PhoneBox" />
          </insertparameters>
      </asp:sqldatasource>

      <br /><asp:textbox
           id="CompanyNameBox"
           runat="server" />

      <asp:RequiredFieldValidator
        id="RequiredFieldValidator1"
        runat="server"
        ControlToValidate="CompanyNameBox"
        Display="Static"
        ErrorMessage="Please enter a company name." />

      <br /><asp:textbox
           id="PhoneBox"
           runat="server" />

      <asp:RequiredFieldValidator
        id="RequiredFieldValidator2"
        runat="server"
        ControlToValidate="PhoneBox"
        Display="Static"
        ErrorMessage="Please enter a phone number." />

      <br /><asp:button
           id="Button1"
           runat="server"
           text="Insert New Shipper"
           onclick="InsertShipper" />

    </form>
  </body>
</html>

備註

在執行插入操作前,會呼叫該 OnInserting 方法來啟動 Inserting 事件。 你可以處理此事件來檢查參數值,並在操作前 Insert 執行任何預處理。 執行插入操作時,物件會SqlDataSourceView利用DbCommand文字及相關InsertCommand屬性建立物件InsertParameters,然後對底層資料庫執行該DbCommand物件。

操作完成後,會呼叫該 OnInserted 方法來啟動事件 Inserted 。 你可以處理此事件來檢查任何回傳值和錯誤代碼,並執行後製處理。

Insert此方法提供程式存取Insert權限。 若控制 SqlDataSource 項與資料綁定控制相關聯,資料綁定控制項會自動呼叫該 Insert 方法。

該Insert方法將委派給Insert與SqlDataSourceView控制項相關的物件的方法SqlDataSource。

Important

參數中插入數值時未經驗證,這可能構成安全威脅。 在執行查詢前,請利用事件 Filtering 驗證參數值。 欲了解更多資訊,請參閱 腳本漏洞概述。

適用於

另請參閱