November 8, 2013 at 4:29 pm
November 8, 2013 at 4:35 pm
Be easier to help if you provide some Ddl and how are you calling stored procedure or setting the variables. Initially i would look up dynamic sql perhaps do you have an example execution
***The first step is always the hardest *******
November 8, 2013 at 4:45 pm
SGT_squeequal (11/8/2013)
Be easier to help if you provide some Ddl and how are you calling stored procedure or setting the variables. Initially i would look up dynamic sql perhaps do you have an example execution
DECLARE @sql NVARCHAR(200)
DECLARE @InComeAmountB INT=500
SET @sql='SELECT * FROM [DB1].[dbo].[DailyIncome] WHERE IncomeAmount>@IncomeAmount'
SET @sql=REPLACE(@Sql,'@IncomeAmount','@InComeAmountB')
Exec (@Sql)
The sql (@Sql) is hardcoded and is stored in a table.
This is what i am trying to do.
November 8, 2013 at 5:09 pm
peacesells (11/8/2013)
SGT_squeequal (11/8/2013)
Be easier to help if you provide some Ddl and how are you calling stored procedure or setting the variables. Initially i would look up dynamic sql perhaps do you have an example executionDECLARE @sql NVARCHAR(200)
DECLARE @InComeAmountB INT=500
SET @sql='SELECT * FROM [DB1].[dbo].[DailyIncome] WHERE IncomeAmount>@IncomeAmount'
SET @sql=REPLACE(@Sql,'@IncomeAmount','@InComeAmountB')
Exec (@Sql)
The sql (@Sql) is hardcoded and is stored in a table.
This is what i am trying to do.
Don't use EXEC for this, use sp_executesql but you will need to be able to build/provide a list of parameters with it:
declare @sql nvarchar(200), @params nvarchar(200);
declare @incomeamountb int=500;
set @sql=n'select * from [db1].[dbo].[dailyincome] where incomeamount > @incomeamount'
set @params=n'@incomeamount int';
exec sp_executesql @sql,@params,@incomeamountb
This is also a step in the right direction for protecting against sql injection...
MM
select geometry::STGeomFromWKB(0x
November 8, 2013 at 5:23 pm
mister.magoo (11/8/2013)
peacesells (11/8/2013)
SGT_squeequal (11/8/2013)
Be easier to help if you provide some Ddl and how are you calling stored procedure or setting the variables. Initially i would look up dynamic sql perhaps do you have an example executionDECLARE @sql NVARCHAR(200)
DECLARE @InComeAmountB INT=500
SET @sql='SELECT * FROM [DB1].[dbo].[DailyIncome] WHERE IncomeAmount>@IncomeAmount'
SET @sql=REPLACE(@Sql,'@IncomeAmount','@InComeAmountB')
Exec (@Sql)
The sql (@Sql) is hardcoded and is stored in a table.
This is what i am trying to do.
Don't use EXEC for this, use sp_executesql but you will need to be able to build/provide a list of parameters with it:
declare @sql nvarchar(200), @params nvarchar(200);
declare @incomeamountb int=500;
set @sql=n'select * from [db1].[dbo].[dailyincome] where incomeamount > @incomeamount'
set @params=n'@incomeamount int';
exec sp_executesql @sql,@params,@incomeamountb
This is also a step in the right direction for protecting against sql injection...
I haven't tried out this yet, i wonder if this will because i also i have group by clause which is hardcoded in the query stored in the query . so for instance the query i posted earlier would look smth like this.
SET @sql='SELECT a, b, c , sum(d) FROM [DB1].[dbo].[DailyIncome] WHERE IncomeAmount>@IncomeAmount Group by a, b, c'
November 8, 2013 at 5:24 pm
Not sure what your question is there?
Having group by in your query won't matter one jot.
MM
select geometry::STGeomFromWKB(0x
Viewing 8 posts - 1 through 7 (of 7 total)
You must be logged in to reply to this topic. Login to reply