Esempio n. 1
0
    private void clearGrid()
    {
        dsSearch.SelectCommand = string.Empty;
        dsSearch.SelectParameters.Clear();
        dsSearch.DataBind();
        GRD_Results.DataSource = dsSearch;
        GRD_Results.DataBind();

        tblView.Visible   = false;
        tblInOut.Visible  = false;
        btnSubmit.Enabled = false;
    }
Esempio n. 2
0
    private void setSearch()
    {
        dsSearch.ConnectionString = ConnString;

        if (ddlCategory.SelectedValue != "" && ddlUserType.SelectedValue != "")
        {
            if (ddlUserType.SelectedValue == "Tenants")
            {
                SelectTenant    += " WHERE " + AntiXSSMethods.MakeStringSafeForSQL(ddlCategory.SelectedValue) + " LIKE @SQ";
                SearcQuery       = SelectTenant;
                SelectedUserType = 1;
            }
            else if (ddlUserType.SelectedValue == "Employees")
            {
                SelectEmployee  += " WHERE " + AntiXSSMethods.MakeStringSafeForSQL(ddlCategory.SelectedValue) + " LIKE @SQ";
                SearcQuery       = SelectEmployee;
                SelectedUserType = 2;
            }


            ViewState.Add("UserType", SelectedUserType.ToString());

            dsSearch.SelectParameters.Add(new Parameter("SQ", System.Data.DbType.String, "%" + AntiXSSMethods.CleanString(txtSearchQuery.Text) + "%"));
            dsSearch.SelectCommand = SearcQuery;
            dsSearch.DataBind();

            GRD_Results.DataSource = dsSearch;
            GRD_Results.DataBind();

            lblAlert.Text = "";
        }
        else if (ddlUserType.SelectedValue != "" && ddlCategory.SelectedValue == "")
        {
            //no category selected
            clearGrid();
            lblAlert.Text = "No Category selected.";
        }
        else if (ddlUserType.SelectedValue == "" && ddlCategory.SelectedValue != "")
        {
            //no category selected
            clearGrid();
            lblAlert.Text = "No User Type selected.";
        }
        else
        {
            //no category selected

            lblAlert.Text = "Please complete fields!";
            clearGrid();
        }
    }
Esempio n. 3
0
    protected void btnSearch_Click(object sender, EventArgs e)
    {
        if (ddlCategory.SelectedValue + ddlUserType.SelectedValue != "")
        {
            string         strSelect = "SELECT * FROM DTR WHERE " + ddlCategory.SelectedValue + ddlUserType.SelectedValue + " LIKE @entry AND DTR_ID !='" + SelectedUser.ToString() + "'  ORDER BY Username DESC";
            SqlParameter[] SearchVal = { new SqlParameter("@entry", "%" + AntiXSSMethods.CleanString(txtSearch.Text) + "%") };
            DataSet        ds        = DataAccess.DataProcessReturnData(strSelect, SearchVal, connString);


            GRD_Results.DataSourceID = string.Empty;
            GRD_Results.DataSourceID = string.Empty;
            GRD_Results.DataBind();
        }
        else
        {
        }
    }