版权声明:本文为博主原创文章,转载请在显著位置标明本文出处以及作者网名,未经作者允许不得用于商业目的。
关于《Visual Basic.Net 循序渐进》请到百度网盘下载,具体下载地址:
链接:https://pan.baidu.com/s/1IfaLvlklx-nT4KK4VKZuIw
提取码:ip5n
在登录界面输入正确的账号和密码才能登录。
为了防止sql注入,采用的方法是,先检查账号是否存在,如果存在就返回对应的操作员姓名和密码。具体Sql语句如下:
select 姓名,密码 from 操作员 where (id=账号ID) and (是否停用='否')
其中账号ID是输入的账号。
通过返回的密码与用户输入的密码比较,再判断是否可以进入系统。
关于数据库操作,请参看教程第19章《数据库操作》。全部代码如下:
Imports System.Data.OleDb
Public Class FormLogin
Dim connection As OleDbConnection
Private Sub FormLogin_Load(sender As Object, e As EventArgs) Handles MyBase.Load
databasePath = Application.StartupPath & "\kfgl.accdb"
databaseConnString = "Provider=Microsoft.ACE.OLEDB.12.0;data source=" & databasePath & ";"
connection = New OleDbConnection(databaseConnString)
'打开数据连接
connection.Open()
End Sub
Private Sub btnLogin_Click(sender As Object, e As EventArgs) Handles btnLogin.Click
Dim errMsg As String
errMsg = checkData()
If errMsg <> "" Then
MessageBox.Show(errMsg)
Exit Sub
End If
Dim inputId As Integer = Integer.Parse(txtID.Text)
Dim inputPass As String = txtPass.Text
Dim inputPassMd5 As String = ClassMd5.toMD5(inputPass)
'新建OleDbCommand对象实例
Dim command As New OleDbCommand()
'=========查询用户列表==================
'要执行的SQL查询
command.CommandText = "select 姓名,密码 from 操作员 where (id=" & inputId & ") and (是否停用='否')"
'设置OleDbCommand的数据连接为OleDbConnection
command.Connection = connection
Dim odReader As OleDbDataReader
Dim userPass As String
Dim userName As String
odReader = command.ExecuteReader(CommandBehavior.SingleRow)
If odReader.HasRows = False Then
odReader.Close()
MessageBox.Show("账号或密码错误!")
Exit Sub
End If
odReader.Read()
userName = odReader.GetValue(0)
userPass = odReader.GetValue(1)
odReader.Close()
If userPass <> inputPassMd5 Then
MessageBox.Show("账号或密码错误!")
Exit Sub
End If
If inputId = 0 Then
permissions = 0
loginId = inputId
loginName = "管理员"
Else
permissions = 1
loginId = inputId
loginName = userName
End If
FormMain.Show()
Me.Hide()
End Sub
Private Function checkData() As String
Dim id As Integer
If txtID.Text.Trim = "" Then
Return "账号不能为空"
End If
If Integer.TryParse(txtID.Text, id) = False Then
Return "账号不是有效的数字"
End If
If txtPass.Text.Trim = "" Then
Return "密码不能为空"
End If
Return ""
End Function
End Class
由于.net平台下C#和vb.NET很相似,本文也可以为C#爱好者提供的参考。
学习更多vb.net知识,请参看 vb.net 教程 目录