public ActionResult UpdateBuilding(M_Building data) { try { data.CreateID = user.EmployeeNo; data.CreateDate = DateTime.Now; data.UpdateID = user.EmployeeNo; data.UpdateDate = DateTime.Now; string Query = ""; Query += "UPDATE [dbo].[M_Building] SET " + " [BuildingName] = '" + data.BuildingName + "'" + " ,[UpdateID]= '" + data.UpdateID + "'" + " ,[UpdateDate]= '" + data.UpdateDate + "'" + " WHERE [ID] = '" + data.ID + "'"; SqlCommand cmdSql = new SqlCommand(); cmdSql.Connection = conn; cmdSql.CommandTimeout = 0; cmdSql.CommandText = Query; conn.Open(); cmdSql.ExecuteNonQuery(); conn.Close(); return(Json(new { msg = "Success" }, JsonRequestBehavior.AllowGet)); } catch (Exception err) { return(Json(new { msg = err.Message }, JsonRequestBehavior.AllowGet)); } }
public ActionResult CreateBuilding(M_Building data) { try { data.CreateID = user.EmployeeNo; data.CreateDate = DateTime.Now; data.UpdateID = user.EmployeeNo; data.UpdateDate = DateTime.Now; string Query = ""; Query += "INSERT INTO [dbo].[M_Building]" + " ([BuildingName]" + " ,[DivisionID]" + " ,[IsDeleted]" + " ,[CreateID]" + " ,[CreateDate]" + " ,[UpdateID]" + " ,[UpdateDate])" + "VALUES" + " ('" + data.BuildingName + "'," + " '" + user.DivisionID + "'," + " '" + 0 + "'," + " '" + data.CreateID + "'," + " '" + data.CreateDate + "'," + " '" + data.UpdateID + "'," + " '" + data.UpdateDate + "')"; SqlCommand cmdSql = new SqlCommand(); cmdSql.Connection = conn; cmdSql.CommandTimeout = 0; cmdSql.CommandText = Query; conn.Open(); cmdSql.ExecuteNonQuery(); conn.Close(); return(Json(new { msg = "Success" }, JsonRequestBehavior.AllowGet)); } catch (Exception err) { return(Json(new { msg = err.Message }, JsonRequestBehavior.AllowGet)); } }