SqlServer特殊字符转换&查询

  

Codesnip, currently in used in my project:

 

    /// <summary>

/// Encode the user-input (with special character) into SQL query statement

/// special character like : ',[,/,_,%...etc

/// </summary>

/// <param name="strValue"> user-input </param>

/// <param name="isLikeStatement">if it is encode for like statement</param>

/// <returns>SQL query statement</returns>
public static string sqlEncode(string strValue, bool isLikeStatement)

    {

        string rtStr = strValue;

        if (isLikeStatement)

        {

            rtStr = strValue.Replace("[", "[[]"); //此句一定要在最前

            rtStr = rtStr.Replace("_", "[_]");

            rtStr = rtStr.Replace("%", "[%]");

            rtStr = rtStr.Replace(@"/", "");

        }

        rtStr = rtStr.Replace("'", "''");

 

        return rtStr;

    }

 

 

 

===============================ppll的分割线==================================

 

查询SqlServer特殊字符 原文:Here

 

 

我们都知道SQL查询过程中,单引号“'”是特殊字符,所以在查询的时候要转换成双单引号“''”。

但这只是特殊字符的一个,在实际项目中,发现对于like操作还有以下特殊字符:下划线“_”,百分号“%”,方括号“[]”以及尖号“^”。

其用途如下:

下划线:用于代替一个任意字符(相当于正则表达式中的 ?

百分号:用于代替任意数目的任意字符(相当于正则表达式中的 *

方括号:用于转义(事实上只有左方括号用于转义,右方括号使用最近优先原则匹配最近的左方括号)

尖号:用于排除一些字符进行匹配(这个与正则表达式中的一样)

 

以下是一些匹配的举例,需要说明的是,只有like操作才有这些特殊字符,=操作是没有的。

a_b...

a[_]b%

a%b...

a[%]b%

a[b...

a[[]b%

a]b...

a]b%

a[]b...

a[[]]b%

a[^]b...

a[[][^]]b%

a[^^]b...

a[[][^][^]]b%

 

 

对于like操作,需要进行以下替换(注意顺序也很重要)

[ -> [[]     (这个必须是第一个替换的!!)

% -> [%]    (这里%是指希望匹配的字符本身包括的%而不是专门用于匹配的通配符)

_ -> [_]

^ -> [^]

 

 

===============================ppll的分割线==================================

引用:Here

SQL encode and decode Function
2007-07-05 14:31

Function SQL_encode(strContent)
If isnull(strContent) = False Then
   strContent = replace(strContent, """", "&#34;")
   strContent = replace(strContent, "'", "&#39;")
   strContent = replace(strContent, "+", "&#43;")
   strContent = replace(strContent, "*", "&#42;")
   strContent = replace(strContent, "-", "&#45;")
   strContent = replace(strContent, "=", "&#61;")
   strContent = replace(strContent, "<", "&lt;")
   strContent = replace(strContent, ">", "&gt;")
   strContent = replace(strContent, "%", "&#37;")
   strContent = replace(strContent, "_", "&#95;")
   SQL_encode = strContent
End If
End Function

Function SQL_decode(strContent)
If isnull(strContent) = False Then
   strContent = replace(strContent, "&#34;", """")
   strContent = replace(strContent, "&#39;", "'")
   strContent = replace(strContent, "&#43;", "+")
   strContent = replace(strContent, "&#42;", "*")
   strContent = replace(strContent, "&#45;", "-")
   strContent = replace(strContent, "&#61;", "=")
   strContent = replace(strContent, "&lt;", "<")
   strContent = replace(strContent, "&gt;", ">")
   strContent = replace(strContent, "&#37;", "%")
   strContent = replace(strContent, "&#95;", "_")
   SQL_Decode = strContent
End If
End Function

edition 2006

-------------------------------------------------------------------

'transform any SQL operators to their ascii equivalent
function SQL_encode(strContent)

if isnull(strContent) = false then

   'transform sql operators to ascii equivalents
   strContent = replace(strContent, "'", "|Q|")
   strContent = replace(strContent, """", "|QQ|")
   strContent = replace(strContent, "+", "|PLUS|")
   strContent = replace(strContent, "*", "|STAR|")
   strContent = replace(strContent, "-", "|MINUS|")
   strContent = replace(strContent, "=", "|EQUALS|")
   strContent = replace(strContent, "<", "|LEFT|")
   strContent = replace(strContent, ">", "|RIGHT|")
   strContent = replace(strContent, "%", "|PERCENT|")
   strContent = replace(strContent, "_", "|UNDER|")
   strContent = replace(strContent, "/", "|BACKS|")
   strContent = replace(strContent, "/", "|FRONTS|")

   SQL_encode = strContent

end if

end function

'tranform ascii characters to their SQL equivalent
function SQL_decode(strContent)

if isnull(strContent) = false then

   'transform sql operators
   strContent = replace(strContent, "|Q|", "'")
   strContent = replace(strContent, "|QQ|", """")
   strContent = replace(strContent, "|PLUS|", "+")
   strContent = replace(strContent, "|STAR|", "*")
   strContent = replace(strContent, "|MINUS|", "-")
   strContent = replace(strContent, "|EQUALS|", "=")
   strContent = replace(strContent, "|LEFT|", "<")
   strContent = replace(strContent, "|RIGHT|", ">")
   strContent = replace(strContent, "|PERCENT|", "%")
   strContent = replace(strContent, "|UNDER|", "_")
   strContent = replace(strContent, "|BACKS|", "/")
   strContent = replace(strContent, "|FRONTS|", "/")

   SQL_Decode = strContent

end if

end function

 

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值