protected void updatebonus(object sender, EventArgs e) { string id = Request["id"]; string pt = txtbonusphoto.ImageUrl; if (bonusphoto.FileName != "") { pt = "~/Image/bonus/" + bonusphoto.FileName; } bn = new DTO_Bonus(); bn.Bonus_id_ = id; bn.Name_bonus_ = txtbonusname.Text; bn.Photo_ = pt; bn.Price_ = Convert.ToInt32(txtbonusprice.Text); bb.updateBonus(bn); saveUpLoadFile(); Response.Redirect("Bonus.aspx"); }
protected void addNewBonus(object sender, EventArgs e) { if (Page.IsValid) { string pt = txtbonusphoto.ImageUrl; if (bonusphoto.FileName != "") { pt = "~/Image/bonus/" + bonusphoto.FileName; } bn = new DTO_Bonus(); bn.Bonus_id_ = txtbonusid.Text; bn.Name_bonus_ = txtbonusname.Text; bn.Photo_ = pt; bn.Price_ = Convert.ToInt32(txtbonusprice.Text); bb.insertBonus(bn); saveUpLoadFile(); Response.Redirect("Bonus.aspx"); } }
public void insertBonus(DTO_Bonus db) { string sql = "insert into Bonus values('" + db.Bonus_id_ + "',N'" + db.Name_bonus_ + "','" + db.Photo_ + "'," + db.Price_ + ")"; da.ExcuteNonQuery(sql); }
public void updateBonus(DTO_Bonus db) { string sql = "update BONUS set name_bonus=N'" + db.Name_bonus_ + "', photo='" + db.Photo_ + "', price=" + db.Price_ + " where bonus_ID='" + db.Bonus_id_ + "'"; da.ExcuteNonQuery(sql); }