protected void Button1_Click(object sender, EventArgs e)
{
SqlConnection myConnection = new SqlConnection();
myConnection.ConnectionString = "integrated security=SSPI;data source=\"(local)\"; persist security info=False; initial catalog= MyDatabase ";
myConnection.Open();
// SQL拼接查询
string sql = "select 员工编号,姓名,性别,出生日期,基本工资 from MyTable2";
if (TextBox1.Text != "")
//sql += " where 姓名 = '"+ TextBox1.Text +" and MyTable1.编码=MyTable2.单位编码'";
sql += " where 姓名 = '" + TextBox1.Text + "'"; //where前面要加空格,同时TextBox1.Text被当做字符串处理,所以要使用+来连接该SQL查询语句。
// else
// Response.Write("<script>alert('2333');</script>");
// 参数化查询
string namevalue = TextBox1.Text;
SqlCommand search = new SqlCommand("select 员工编号,姓名,性别,出生日期,基本工资 from MyTable2 where 姓名=@name");
search.Connection = myConnection;
search.Parameters.AddWithValue("@name",namevalue);
// SqlDataReader reader = search.ExecuteReader();
// reader.Read();
SqlDataAdapter da = new SqlDataAdapter(search);
//创建数据适配器
DataSet ds = new DataSet();
da.Fill(ds);
//使用数据适配器的Fill方法将所需数据填充到数据集
GridView1.DataSource = ds;
GridView1.DataBind();
// myConnection.close();
}