protected void Submit_Click2(object sender, EventArgs e) { String teaName = TextBox1.Text.ToString().Trim(); String teaInfo1 = TextBox2.Text.ToString().Trim(); String teaInfo2 = TextBox4.Text.ToString().Trim(); String picUrl = Common.getUrl("/images/upload_files/teachers/", teacherPic); int teaOrder = Convert.ToInt32(TextBox3.Text.ToString().Trim()); String detail_bottom = FCKeditor_bottom.Value.ToString().Trim(); String detail_right = FCKeditor_right.Value.ToString().Trim(); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("INSERT INTO teachers ([name],[info1],[info2],[picpath],[t_order],[detail_bottom],[detail_right])" + "VALUES(@name,@info1,@info2,@picpath,@t_order,@detail_bottom,@detail_right)"); cmd.Parameters.AddWithValue("@name", teaName); cmd.Parameters.AddWithValue("@info1", teaInfo1); cmd.Parameters.AddWithValue("@info2", teaInfo2); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@t_order", teaOrder); cmd.Parameters.AddWithValue("@detail_bottom", detail_bottom); cmd.Parameters.AddWithValue("@detail_right", detail_right); if (picUrl != "") { lastteacherPic.ImageUrl = picUrl; lastteacherPic.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("teachers_edit.aspx"); }
private void showDetail() { stu_id = int.Parse(Request.QueryString["id"]); if (!IsPostBack) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select * from students where id=" + stu_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { StringBuilder sb_bottom = new StringBuilder(""); StringBuilder sb_right = new StringBuilder(""); sb_bottom.Append(reader["detail_bottom"].ToString().Trim()); sb_right.Append(reader["detail_right"].ToString().Trim()); ltlbottom.Text = sb_bottom.ToString(); ltlright.Text = sb_right.ToString(); String picUrl = reader["picpath"].ToString().Trim(); if (picUrl != "") { laststudentPic.ImageUrl = picUrl; laststudentPic.Visible = true; } } reader.Close(); cmd.Connection.Close(); cmd.Connection.Dispose(); dbmanager.closeDB(); } }
//ÐÞ¸ÄÃÜÂë public bool modifyPasswordByeid(string newPassword, int eid) { newPassword = Common.getMD5Code(newPassword); sqlManager dbmanager = sqlManager.createInstance(); try { dbmanager.connectDB(); //SqlCommand cmd = dbmanager.getcmd("UPDATE projects SET [newsTitle]=@newstitle,[newsContent]=@NewsContent,[typeid]=@typeid,[version]=@version,[author]=@author,[addtime]= #" + dtNow + "# WHERE [newsid]=" + newsid); string sql = "UPDATE admin SET [password]=@password where id= " + eid; SqlCommand cmd = dbmanager.getcmd(sql); cmd.Parameters.AddWithValue("@password", newPassword); //cmd.ExecuteNonQuery(); cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); return(true); } catch { dbmanager.closeDB(); return(false); } }
protected void Submit_Click2(object sender, EventArgs e) { String courseName = TextBox1.Text.ToString().Trim(); String courseFit = TextBox2.Text.ToString().Trim(); String courseIntro = TextBox3.Text.ToString().Trim(); String courseContent = TextBox4.Text.ToString().Trim(); String courseCtime = TextBox5.Text.ToString().Trim(); String picUrl = Common.getUrl("/images/upload_files/coursegroup/", coursegroupPic); int type = Convert.ToInt32(DropDownList1.SelectedValue); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("INSERT INTO course_group ([name],[fit],[intro],[content],[ctime],[picpath],[type])" + "VALUES(@name,@fit,@intro,@content,@ctime,@picpath,@type)"); cmd.Parameters.AddWithValue("@name", courseName); cmd.Parameters.AddWithValue("@fit", courseFit); cmd.Parameters.AddWithValue("@intro", courseIntro); cmd.Parameters.AddWithValue("@content", courseContent); cmd.Parameters.AddWithValue("@ctime", courseCtime); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@type", type); if (picUrl != "") { lastcoursegroupPic.ImageUrl = picUrl; lastcoursegroupPic.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("students_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { String picUrl = Common.getUrl("/images/upload_files/news/", courseitemPic); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select [picpath] from course_item where [id]=" + course_item_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { string _picpath = reader["picpath"].ToString().Trim(); if (picUrl == "") { picUrl = _picpath; } else { deletePic(reader["picpath"].ToString().Trim()); } } reader.Close(); String courseName = TextBox1.Text.ToString().Trim(); String cTime = TextBox2.Text.ToString().Trim(); String eTime = TextBox3.Text.ToString().Trim(); String duration = TextBox4.Text.ToString().Trim(); int locationID = int.Parse(DropDownList1.SelectedValue); String circum = TextBox5.Text.ToString().Trim(); bool isFull = CheckBox1.Checked; int type = Convert.ToInt32(DropDownList2.SelectedValue); string filter = DDL_a.SelectedValue + DDL_b.SelectedValue + DDL_c.SelectedValue + DDL_d.SelectedValue + DDL_e.SelectedValue + DDL_f.SelectedValue; cmd = dbmanager.getcmd("UPDATE course_item SET [name]=@name,[ctime]=@ctime,[etime]=@etime,[duration]=@duration,[location]=@location,[circum]=@circum,[isfull]=@isfull,[picpath]=@picpath,[type]=@type,[filter]=@filter WHERE [id]=" + course_item_id); cmd.Parameters.AddWithValue("@name", courseName); cmd.Parameters.AddWithValue("@ctime", cTime); cmd.Parameters.AddWithValue("@etime", eTime); cmd.Parameters.AddWithValue("@duration", duration); cmd.Parameters.AddWithValue("@location", locationID); cmd.Parameters.AddWithValue("@circum", circum); cmd.Parameters.AddWithValue("@isfull", isFull); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@type", type); cmd.Parameters.AddWithValue("@filter", filter); if (picUrl != "") { lastcourseitemPic.ImageUrl = picUrl; lastcourseitemPic.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("course_item_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { String teaName = TextBox1.Text.ToString().Trim(); String teaInfo1 = TextBox2.Text.ToString().Trim(); String teaInfo2 = TextBox4.Text.ToString().Trim(); String picUrl = Common.getUrl("/images/upload_files/teachers/", teacherPic); int teaOrder = Convert.ToInt32(TextBox3.Text.ToString().Trim()); String detail_bottom = FCKeditor_bottom.Value.ToString().Trim(); String detail_right = FCKeditor_right.Value.ToString().Trim(); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select [picpath] from teachers where [id]=" + tea_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { string _picpath = reader["picpath"].ToString().Trim(); if (picUrl == "") { picUrl = _picpath; } else { deletePic(reader["picpath"].ToString().Trim()); } } reader.Close(); cmd = dbmanager.getcmd("UPDATE teachers SET [name]=@name,[info1]=@info1,[info2]=@info2,[picpath]=@picpath,[t_order]=@t_order,[detail_bottom]=@detail_bottom,[detail_right]=@detail_right WHERE [id]=" + tea_id); cmd.Parameters.AddWithValue("@name", teaName); cmd.Parameters.AddWithValue("@info1", teaInfo1); cmd.Parameters.AddWithValue("@info2", teaInfo2); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@t_order", teaOrder); cmd.Parameters.AddWithValue("@detail_bottom", detail_bottom); cmd.Parameters.AddWithValue("@detail_right", detail_right); if (picUrl != "") { lastteacherPic.ImageUrl = picUrl; lastteacherPic.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("teachers_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { String picUrl = Common.getUrl("/images/upload_files/coursegroup/", coursegroupPic); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select [picpath] from course_group where [id]=" + course_group_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { string _picpath = reader["picpath"].ToString().Trim(); if (picUrl == "") { picUrl = _picpath; } else { deletePic(reader["picpath"].ToString().Trim()); } } reader.Close(); String courseName = TextBox1.Text.ToString().Trim(); String courseFit = TextBox2.Text.ToString().Trim(); String courseIntro = TextBox3.Text.ToString().Trim(); String courseContent = TextBox4.Text.ToString().Trim(); String courseCtime = TextBox5.Text.ToString().Trim(); int type = Convert.ToInt32(DropDownList1.SelectedValue); cmd = dbmanager.getcmd("UPDATE course_group SET [name]=@name,[fit]=@fit,[intro]=@intro,[content]=@content,[ctime]=@ctime,[picpath]=@picpath,[type]=@type WHERE [id]=" + course_group_id); cmd.Parameters.AddWithValue("@name", courseName); cmd.Parameters.AddWithValue("@fit", courseFit); cmd.Parameters.AddWithValue("@intro", courseIntro); cmd.Parameters.AddWithValue("@content", courseContent); cmd.Parameters.AddWithValue("@ctime", courseCtime); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@type", type); if (picUrl != "") { lastcoursegroupPic.ImageUrl = picUrl; lastcoursegroupPic.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("course_group_edit.aspx"); }
public bool IsExistUser(string strUsername) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("SELECT userid FROM webuser WHERE username='******'"); SqlDataReader reader = cmd.ExecuteReader(); if (reader.HasRows) { cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); return(true); } else { dbmanager.closeDB(); return(false); } }
private void updateHit() { if (!IsPostBack) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("UPDATE news SET [hittime]=[hittime]+1 WHERE [id]=" + news_id); cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); } }
protected void Submit_Click2(object sender, EventArgs e) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("UPDATE keywords SET [name]=@name,[url]=@url WHERE [id]=" + keywords_id); cmd.Parameters.AddWithValue("@name", TextBox1.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@url", TextBox2.Text.ToString().Trim()); cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("keywords_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("INSERT INTO keywords ([name],[url])" + "VALUES(@name,@url)"); cmd.Parameters.AddWithValue("@name", TextBox1.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@url", TextBox2.Text.ToString().Trim()); cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("keywords_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { String strStarttime = ""; if (strStarttime == "") { strStarttime = DateTime.Now.ToString("G"); } DateTime dt = Convert.ToDateTime(strStarttime); String picUrl = Common.getUrl("/images/upload_files/news/", newsPic); String picUrl_w = Common.getUrl("/images/upload_files/news_w/", newsPic_w); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("INSERT INTO news ([title],[intro],[picpath],[picpath_w],[date],[detail],[type],[sub_type],[tags],[source],[hittime])" + "VALUES(@title,@intro,@picpath,@picpath_w,@date,@detail,@type,@sub_type,@tags,@source,@hittime)"); cmd.Parameters.AddWithValue("@title", TextBox1.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@intro", TextBox2.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@picpath_w", picUrl_w); cmd.Parameters.AddWithValue("@date", strStarttime); cmd.Parameters.AddWithValue("@detail", FCKeditor1.Value.ToString().Trim()); cmd.Parameters.AddWithValue("@type", Convert.ToInt32(DropDownList1.SelectedValue)); cmd.Parameters.AddWithValue("@sub_type", Convert.ToInt32(DropDownList2.SelectedValue)); cmd.Parameters.AddWithValue("@tags", TextBox3.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@source", TextBox4.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@hittime", 0); if (picUrl != "") { lastnewsPic.ImageUrl = picUrl; lastnewsPic.Visible = true; } if (picUrl_w != "") { lastnewsPic_w.ImageUrl = picUrl_w; lastnewsPic_w.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("news_edit.aspx"); }
protected void Submit_Click(object sender, EventArgs e) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("UPDATE q_and_a SET [q_order]=@q_order,[question]=@question,[answer]=@answer WHERE [id]=" + qanda_id); cmd.Parameters.AddWithValue("@q_order", TextBox2.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@question", TextBox1.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@answer", FCKeditor1.Value.ToString().Trim()); cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("qanda_edit.aspx"); }
protected void Page_Load(object sender, EventArgs e) { try { if (!Session["security"].Equals("safe")) { Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>"); } } catch (Exception ex) { Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>"); } tea_id = int.Parse(Request.QueryString["id"]); //SqlDataSource1.SelectCommand = "SELECT * FROM q_and_a"; if (!IsPostBack) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select * from teachers where id=" + tea_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { TextBox1.Text = reader["name"].ToString().Trim(); TextBox2.Text = reader["info1"].ToString().Trim(); TextBox4.Text = reader["info2"].ToString().Trim(); TextBox3.Text = reader["t_order"].ToString().Trim(); FCKeditor_bottom.Value = reader["detail_bottom"].ToString().Trim(); FCKeditor_right.Value = reader["detail_right"].ToString().Trim(); String picUrl = reader["picpath"].ToString().Trim(); if (picUrl != "") { lastteacherPic.ImageUrl = picUrl; lastteacherPic.Visible = true; } } reader.Close(); cmd.Connection.Close(); cmd.Connection.Dispose(); dbmanager.closeDB(); } }
protected void Submit_Click2(object sender, EventArgs e) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("INSERT INTO q_and_a ([q_order],[question],[answer])" + "VALUES(@q_order,@question,@answer)"); cmd.Parameters.AddWithValue("@q_order", TextBox2.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@question", TextBox1.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@answer", FCKeditor1.Value.ToString().Trim()); cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("qanda_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { String courseName = TextBox1.Text.ToString().Trim(); String cTime = TextBox2.Text.ToString().Trim(); String eTime = TextBox3.Text.ToString().Trim(); String duration = TextBox4.Text.ToString().Trim(); int locationID = int.Parse(DropDownList1.SelectedValue); String circum = TextBox5.Text.ToString().Trim(); bool isFull = CheckBox1.Checked; String picUrl = Common.getUrl("/images/upload_files/courseitem/", courseitemPic); int type = Convert.ToInt32(DropDownList2.SelectedValue); string filter = DDL_a.SelectedValue + DDL_b.SelectedValue + DDL_c.SelectedValue + DDL_d.SelectedValue + DDL_e.SelectedValue + DDL_f.SelectedValue; sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("INSERT INTO course_item ([name],[ctime],[etime],[duration],[location],[circum],[isfull],[picpath],[type],[filter])" + "VALUES(@name,@ctime,@etime,@duration,@location,@circum,@isfull,@picpath,@type,@filter)"); cmd.Parameters.AddWithValue("@name", courseName); cmd.Parameters.AddWithValue("@ctime", cTime); cmd.Parameters.AddWithValue("@etime", eTime); cmd.Parameters.AddWithValue("@duration", duration); cmd.Parameters.AddWithValue("@location", locationID); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@circum", circum); cmd.Parameters.AddWithValue("@isfull", isFull); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@type", type); cmd.Parameters.AddWithValue("@filter", filter); if (picUrl != "") { lastcourseitemPic.ImageUrl = picUrl; lastcourseitemPic.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("course_item_edit.aspx"); }
public bool CheckPassword(string newPassword, int eid) { string strOldPassword = ""; newPassword = Common.getMD5Code(newPassword); sqlManager dbmanager = sqlManager.createInstance(); try { dbmanager.connectDB(); //SqlCommand cmd = dbmanager.getcmd("UPDATE projects SET [newsTitle]=@newstitle,[newsContent]=@NewsContent,[typeid]=@typeid,[version]=@version,[author]=@author,[addtime]= #" + dtNow + "# WHERE [newsid]=" + newsid); string sql = "select * from admin where id= " + eid; SqlCommand cmd = dbmanager.getcmd(sql); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { strOldPassword = reader["password"].ToString(); } reader.Close(); if (newPassword.ToLower() == strOldPassword.ToLower()) { cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); return(true); } else { cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); return(false); } } catch { dbmanager.closeDB(); return(false); } }
protected void Page_Load(object sender, EventArgs e) { try { if (!Session["security"].Equals("safe")) { Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>"); } } catch (Exception ex) { Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>"); } qanda_id = int.Parse(Request.QueryString["id"]); //SqlDataSource1.SelectCommand = "SELECT * FROM q_and_a"; if (!IsPostBack) { sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select * from q_and_a where id=" + qanda_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { TextBox1.Text = reader["question"].ToString().Trim(); TextBox2.Text = reader["q_order"].ToString().Trim(); FCKeditor1.Value = reader["answer"].ToString().Trim(); } reader.Close(); cmd.Connection.Close(); cmd.Connection.Dispose(); dbmanager.closeDB(); } //hpkreturn.NavigateUrl = "EditNews.aspx?vid=" + strVersion + "&cid=" + ncid; }
protected void Submit_Click2(object sender, EventArgs e) { String picUrl = Common.getUrl("/images/upload_files/news/", newsPic); String picUrl_w = Common.getUrl("/images/upload_files/news_w/", newsPic_w); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select [picpath],[picpath_w] from news where [id]=" + news_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { string _picpath = reader["picpath"].ToString().Trim(); if (picUrl == "") { picUrl = _picpath; } else { deletePic(reader["picpath"].ToString().Trim()); } string _picpath_w = reader["picpath_w"].ToString().Trim(); if (picUrl_w == "") { picUrl_w = _picpath_w; } else { deletePic(reader["picpath_w"].ToString().Trim()); } } reader.Close(); String strStarttime = ""; if (strStarttime == "") { strStarttime = DateTime.Now.ToString("G"); } DateTime dt = Convert.ToDateTime(strStarttime); cmd = dbmanager.getcmd("UPDATE news SET [title]=@title,[intro]=@intro,[picpath]=@picpath,[picpath_w]=@picpath_w,[detail]=@detail,[type]=@type,[sub_type]=@sub_type,[tags]=@tags,[source]=@source WHERE [id]=" + news_id); cmd.Parameters.AddWithValue("@title", TextBox1.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@intro", TextBox2.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@picpath", picUrl); cmd.Parameters.AddWithValue("@picpath_w", picUrl_w); cmd.Parameters.AddWithValue("@detail", FCKeditor1.Value.ToString().Trim()); cmd.Parameters.AddWithValue("@type", Convert.ToInt32(DropDownList1.SelectedValue)); cmd.Parameters.AddWithValue("@sub_type", Convert.ToInt32(DropDownList2.SelectedValue)); cmd.Parameters.AddWithValue("@tags", TextBox3.Text.ToString().Trim()); cmd.Parameters.AddWithValue("@source", TextBox4.Text.ToString().Trim()); if (picUrl != "") { lastnewsPic.ImageUrl = picUrl; lastnewsPic.Visible = true; } if (picUrl_w != "") { lastnewsPic_w.ImageUrl = picUrl_w; lastnewsPic_w.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("news_edit.aspx"); }
protected void Submit_Click2(object sender, EventArgs e) { String picUrl_top = Common.getUrl("/images/upload_files/courseimage_top/", coursePic_top); String picUrl_right = Common.getUrl("/images/upload_files/courseimage_right/", coursePic_right); sqlManager dbmanager = sqlManager.createInstance(); dbmanager.connectDB(); SqlCommand cmd = dbmanager.getcmd("select * from course_image where [id]=" + course_image_id); SqlDataReader reader = cmd.ExecuteReader(); while (reader.Read()) { string _picpath_top = reader["picpath_top"].ToString().Trim(); if (picUrl_top == "") { picUrl_top = _picpath_top; } else { deletePic(reader["picpath_top"].ToString().Trim()); } string _picpath_right = reader["picpath_right"].ToString().Trim(); if (picUrl_right == "") { picUrl_right = _picpath_right; } else { deletePic(reader["picpath_right"].ToString().Trim()); } } reader.Close(); cmd = dbmanager.getcmd("UPDATE course_image SET [name]=@name,[picpath_top]=@picpath_top,[picpath_right]=@picpath_right WHERE [id]=" + course_image_id); cmd.Parameters.AddWithValue("@name", TextBox1.Text.Trim()); cmd.Parameters.AddWithValue("@picpath_top", picUrl_top); cmd.Parameters.AddWithValue("@picpath_right", picUrl_right); if (picUrl_top != "") { lastcoursePic_top.ImageUrl = picUrl_top; lastcoursePic_top.Visible = true; } if (picUrl_right != "") { lastcoursePic_right.ImageUrl = picUrl_right; lastcoursePic_right.Visible = true; } cmd.ExecuteNonQuery(); cmd.Connection.Close(); cmd.Connection.Dispose(); cmd.Dispose(); dbmanager.closeDB(); Response.Redirect("course_image_edit.aspx"); }