Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
Update doesn't work without thisform
Message
General information
Forum:
Visual FoxPro
Category:
Coding, syntax & commands
Environment versions
Visual FoxPro:
VFP 9 SP2
OS:
Windows 7
Miscellaneous
Thread ID:
01525200
Message ID:
01525258
Views:
40
>>Try this
TEXT to mSqlcommand noshow pretext 15 TEXTMERGE
>>UPDATE MyView
>>	SET
>>		Field1 = nValue1, 
>>		Field2 = <<.nSomeValueIHave>> 
>>	WHERE code = nValue3
>>ENDTEXT
>>&mSqlCommand
>>
>>Be sure to remove all semicolons in your code. The TEXTMERGE comment will replace
<<.nSomeValueIHave>>
with the value of your form property.
>>HTH
>
>
>Bad idea. SQL injection risk
>
>Relevant:
>http://xkcd.com/327/

I just realized you are using this in a view. I only use this in PRGs working on local cursors and the code is compiled into an EXE. In that case there can be no risk.
Beer is proof that God loves man, and wants him to be happy. - Benjamin Franklin
John J. Henn
Previous
Reply
Map
View

Click here to load this message in the networking platform