public OutputInvoiceNoteResponse Create(OutputInvoiceNoteViewModel OutputInvoiceNote) { OutputInvoiceNoteResponse response = new OutputInvoiceNoteResponse(); using (SqliteConnection db = new SqliteConnection("Filename=SirmiumERPGFC.db")) { db.Open(); SqliteCommand insertCommand = db.CreateCommand(); insertCommand.CommandText = SqlCommandInsertPart; try { insertCommand = AddCreateParameters(insertCommand, OutputInvoiceNote); insertCommand.ExecuteNonQuery(); } catch (SqliteException error) { MainWindow.ErrorMessage = error.Message; response.Success = false; response.Message = error.Message; return(response); } db.Close(); response.Success = true; return(response); } }
public OutputInvoiceNoteResponse SetStatusDeleted(Guid identifier) { OutputInvoiceNoteResponse response = new OutputInvoiceNoteResponse(); using (SqliteConnection db = new SqliteConnection("Filename=SirmiumERPGFC.db")) { db.Open(); SqliteCommand insertCommand = new SqliteCommand(); insertCommand.Connection = db; //Use parameterized query to prevent SQL injection attacks insertCommand.CommandText = "UPDATE OutputInvoiceNotes SET ItemStatus = @ItemStatus WHERE Identifier = @Identifier"; insertCommand.Parameters.AddWithValue("@ItemStatus", ItemStatus.Deleted); insertCommand.Parameters.AddWithValue("@Identifier", identifier); try { insertCommand.ExecuteNonQuery(); } catch (SqliteException error) { MainWindow.ErrorMessage = error.Message; response.Success = false; response.Message = error.Message; return(response); } db.Close(); response.Success = true; return(response); } }
public OutputInvoiceNoteResponse GetOutputInvoiceNote(Guid identifier) { OutputInvoiceNoteResponse response = new OutputInvoiceNoteResponse(); OutputInvoiceNoteViewModel OutputInvoiceNote = new OutputInvoiceNoteViewModel(); using (SqliteConnection db = new SqliteConnection("Filename=SirmiumERPGFC.db")) { db.Open(); try { SqliteCommand selectCommand = new SqliteCommand( SqlCommandSelectPart + "FROM OutputInvoiceNotes " + "WHERE Identifier = @Identifier;", db); selectCommand.Parameters.AddWithValue("@Identifier", identifier); SqliteDataReader query = selectCommand.ExecuteReader(); if (query.Read()) { OutputInvoiceNoteViewModel dbEntry = Read(query); OutputInvoiceNote = dbEntry; } } catch (SqliteException error) { MainWindow.ErrorMessage = error.Message; response.Success = false; response.Message = error.Message; response.OutputInvoiceNote = new OutputInvoiceNoteViewModel(); return(response); } db.Close(); } response.Success = true; response.OutputInvoiceNote = OutputInvoiceNote; return(response); }