On 07.11.2012, at 17:15, Christian Schmitz <[email protected]> 
wrote:

> 
> Am 07.11.2012 um 17:14 schrieb Massimo Valle <[email protected]>:
> 
>> 
>> dim selectCmd as string = "SELECT * FROM :table"
> 
> 
> Hey, parameters are for parameters. But table name is normally not escaped or 
> quoted.
> 
> Can't you simply put in table name yourself?

The SQLCommandMBS object will be passed to another object which need to know on 
which table operated. Having the table as a parameter would help me on easy 
later retrieval. That's the only reason for non putting the table name into the 
string.
Anyway, is not the table a parameter?

Do the original library provide a method to fill string parameters without 
quotes?

Thanks,

Massimo Valle

SACO Software and Consulting GmbH, Mühlgasse 5, D-97840 Hafenlohr
Tel.: ++49 9391 90890-0, Fax: ++49 9391 90890-99, E-Mail: [email protected]
Amtsgericht Würzburg HRB 5410, Geschäftsführer: Peter Schubert, 
Dipl.-Wirt.ing.(FH) Thorsten Beck

_______________________________________________
Mbsplugins_monkeybreadsoftware.info mailing list
[email protected]
https://ml01.ispgateway.de/mailman/listinfo/mbsplugins_monkeybreadsoftware.info

Reply via email to