Hello Edhy
What do you think about this ! i want to build a dynamic query !
and do you think it's secure ?
declare @cName varchar(30);
declare @cPrice varchar(12);
declare @cCondition varchar(max);
declare @MyQuery varchar(max)
set @cName = 'm.dupont';
set @cPrice = '120000';
IF @cName <>''
set @cCondition = 'name like '+@cName+'%';
IF @cPrice <>''
set @cCondition = 'price>='+@cPrice;
SET @MyQuery = 'select * from product where ' + @cCondition
EXEC (@MyQuery)
Do you see the way what i need ?
thanks
Olivier
==============================================
Asp.net C# - Strataframe - telerik
==============================================