public void updateSalesPerson(SalesPerson sp) { string query = "UPDATE salesperson SET name='" + sp.getName() + "',commission='" + sp.getCommission() + "',address='" + sp.getAddress() + "' WHERE sid='" + sp.getSId() + "'"; if (this.connect()) { MySqlCommand cmd = new MySqlCommand(query, connection); cmd.ExecuteNonQuery(); query = "UPDATE employees SET id='" + sp.getEmpId() + "',sid='" + sp.getSId() + "',password='******' WHERE sid='" + sp.getSId() + "'"; cmd.CommandText = query; cmd.ExecuteNonQuery(); } this.stopConnection(); }
public void addSalesPerson(SalesPerson sp) { if (this.connect()) { string query = "INSERT INTO salesperson (name,commission,address) VALUES ('" + sp.getName() + "','" + sp.getCommission() + "','" + sp.getAddress() + "')"; MySqlCommand cmd = new MySqlCommand(query, connection); cmd.ExecuteNonQuery(); query = "SELECT sid FROM salesperson WHERE name = " + sp.getName() + ";"; cmd = new MySqlCommand(query, connection); MySqlDataReader reader = cmd.ExecuteReader(); sp.setSId(reader.GetInt32(0)); query = "INSERT INTO employees (id,password,sid) VALUES ('" + sp.getEmpId() + "','" + sp.getPassword() + "','" + sp.getSId() + "')"; cmd = new MySqlCommand(query, connection); cmd.ExecuteNonQuery(); reader.Close(); } this.stopConnection(); }