public void GetProductID() { Product product = new Product("P1", "BOX", 100, "this is a plastic box"); // THIS exists in DB by SQL injection Product prod = handler.GetProductID("P1"); Assert.AreEqual(product, prod); }