public M_Ucenter Select(int ID) { string sqlStr = "select * from " + strTableName + " where ID=" + ID; using (DbDataReader reader = SqlHelper.ExecuteReader(CommandType.Text, sqlStr)) { if (reader.Read()) { return(initMod.GetModelFromReader(reader)); } else { return(new M_Ucenter()); } } }
public M_Ucenter Select(int ID) { string sqlStr = "select * from " + strTableName + " where ID=@ID"; SqlParameter[] cmdParams = new SqlParameter[1]; cmdParams[0] = new SqlParameter("@ID", SqlDbType.Int, 4); cmdParams[0].Value = ID; using (SqlDataReader reader = SqlHelper.ExecuteReader(CommandType.Text, sqlStr, cmdParams)) { if (reader.Read()) { return(initMod.GetModelFromReader(reader)); } else { return(new M_Ucenter()); } } }