public void UpdateSalesman(SalesmanDTO salesmanDTO) { sqlConnection.Open(); string sqlQuery = "Update Salesman SET SalesmanID='" + salesmanDTO.SalesmanID + "' where SalesmanID='" + salesmanDTO.SalesmanID + "'"; sqlCommand = new SqlCommand(sqlQuery, sqlConnection); sqlCommand.ExecuteNonQuery(); string sqlQuery1 = "Update Salesman SET SalesmanName='" + salesmanDTO.SalesmanNAME + "' where SalesmanID='" + salesmanDTO.SalesmanID + "'"; sqlCommand1 = new SqlCommand(sqlQuery1, sqlConnection); sqlCommand1.ExecuteNonQuery(); string sqlQuery2 = "Update Salesman SET Password='******' where SalesmanID='" + salesmanDTO.SalesmanID + "'"; sqlCommand2 = new SqlCommand(sqlQuery2, sqlConnection); sqlCommand2.ExecuteNonQuery(); string sqlQuery3 = "Update Salesman SET Address='" + salesmanDTO.SalesmanADDRESS + "' where SalesmanID='" + salesmanDTO.SalesmanID + "'"; sqlCommand3 = new SqlCommand(sqlQuery3, sqlConnection); sqlCommand3.ExecuteNonQuery(); sqlConnection.Close(); }
public void CreateSalesman(SalesmanDTO salesmanDTO) { try { sqlConnection.Open(); string sqlQuery = " insert into Salesman values('" + salesmanDTO.SalesmanID + "','" + salesmanDTO.SalesmanNAME + "','" + salesmanDTO.SalesmanPASSWORD + "','" + salesmanDTO.SalesmanADDRESS + "')"; sqlCommand = new SqlCommand(sqlQuery, sqlConnection); sqlCommand.ExecuteNonQuery(); sqlConnection.Close(); } catch (Exception ex) { MessageBox.Show("Invalid Input!", "alert", MessageBoxButtons.OK, MessageBoxIcon.Error); } }