public void update(DTO.DuAn c, int id) { string sql = "update tbl_DuAn set TenDuAn = N'" + c.TenDuAn + "', Anh = N'" + c.Anh + "',DanhMucDuAn_Id=N'" + c.DanhMucDuAn_Id + "',MoTa=N'" + c.MoTa + "',DiaChi=N'" + c.DiaChi + "',Gia=N'" + c.Gia + "',ChuDauTu=N'" + c.ChuDauTu + "',DienTich=N'" + c.DienTich + "',TienDo=N'" + c.TienDo + "', status = '" + c.status + "' where id = '" + id + "'"; obj.ExecuteNonQuery(sql); }
public void create(DTO.DuAn c) { string sql = "insert tbl_DuAn values(N'" + c.TenDuAn + "' ,N'" + c.Anh + "' ,N'" + c.DanhMucDuAn_Id + "' , N'" + c.MoTa + "',N'" + c.DiaChi + "' ,N'" + c.Gia + "' ,N'" + c.ChuDauTu + "' ,N'" + c.DienTich + "' ,N'" + c.TienDo + "' , '" + c.status + "', '" + c.created_at + "' )"; obj.ExecuteNonQuery(sql); }