public string SaveTreatment(Treatment treatment) { if (treatment.MedicineQuantity.ToString() == "") { return "Medicine Quantity is missing"; } else if (treatment.Note == "") { return "Treatment Note is missing"; } else if (treatment.Observation=="") { return "Observation is missing"; } else { int value = centerGateway.InsertTreatment(treatment); if (value > 0) { return "Saved Successfully"; } else { return "Operation Failed"; } } }
public int InsertTreatment(Treatment treatment) { SqlConnection connection = new SqlConnection(connectionstring); string query = "INSERT INTO Table_Treatment VALUES ('"+treatment.VoterId+"','"+treatment.Observation+"','"+treatment.Date+"','"+treatment.DoctorId+"','"+treatment.DiseaseName+"','"+treatment.MedicineName+"','"+treatment.Dose+"','"+treatment.Schedule+"','"+treatment.MedicineQuantity+"','"+treatment.Note+"','"+treatment.CenterId+"')"; SqlCommand command = new SqlCommand(query, connection); connection.Open(); int rowsAffected = command.ExecuteNonQuery(); connection.Close(); return rowsAffected; }