繁体   English   中英

如何将图像存储到数据库C#中/如何将Byte []转换为varbinary(max)C#

[英]How to store image to database C# / how to convert Byte[] to varbinary(max) C#

我正在尝试将数据插入数据库,但是无法插入变量Byte[] bytes 当我将数据库中的数据类型更改为image时,可以插入,但是当我将其更改为varbinary(max)时,将显示以下错误:

对象或列名称丢失或为空。 对于SELECT INTO语句,请验证每个列都有一个名称。 对于其他语句,请查找空别名。 不允许将别名定义为“”或[]。 将别名更改为有效名称。 ”附近的语法不正确。

我该如何解决这个问题?

protected void btnUpload_Click(object sender, EventArgs e)
    {
        HttpPostedFile postedFile = FileUpload1.PostedFile;
        string filename = Path.GetFileName(postedFile.FileName);
        string fileExtension = Path.GetExtension(filename);
        int fileSize = postedFile.ContentLength;
        int FkAlbum = Int32.Parse(ddlSubjects.SelectedValue);
        String PicDetail = DropDownList1.SelectedValue;

        String Artists = System.Configuration.ConfigurationManager.ConnectionStrings["FleetManagementConnectionString"].ConnectionString;
        System.Data.SqlClient.SqlConnection con = new System.Data.SqlClient.SqlConnection(Artists);

        //An object or column name is missing or empty. For SELECT INTO statements, verify each column has a name. For other statements, look for empty alias names. Aliases defined as "" or [] are not allowed. Change the alias to a valid name.
        //Incorrect syntax near ''.An object or column name is missing or empty. For SELECT INTO statements, verify each column has a name. For other statements, look for empty alias names. Aliases defined as "" or [] are not allowed. Change the alias to a valid name.
        //Incorrect syntax near ''.

        if (fileExtension.ToLower() == ".jpg" || fileExtension.ToLower() == ".gif"
            || fileExtension.ToLower() == ".png" || fileExtension.ToLower() == ".bmp")
        {
            Stream stream = postedFile.InputStream;
            BinaryReader binaryReader = new BinaryReader(stream);
            Byte[] bytes = binaryReader.ReadBytes((int)stream.Length);


            System.Data.SqlClient.SqlCommand cmd = new System.Data.SqlClient.SqlCommand("Insert into Images (ImageName,ImageData,PicDetail,ImageSize,AlbumID) values('" + filename + "','" + bytes + "','" + PicDetail + "'," + fileSize + "," + FkAlbum + ")", con);
            //System.Data.SqlClient.SqlCommand cmd = new System.Data.SqlClient.SqlCommand("Insert into Images (ImageName,PicDetail,ImageSize,AlbumID) values('" + filename + "','" + PicDetail + "'," + fileSize + "," + FkAlbum + ")", con);


            con.Open();
            cmd.ExecuteNonQuery();
            con.Close();
            lblMessage.Visible = true;
            lblMessage.Text = "ThaNK YOU";



        }
        else
        {
            lblMessage.Visible = true;
            lblMessage.ForeColor = System.Drawing.Color.Red;
            lblMessage.Text = "Only images (.jpg, .png, .gif and .bmp) can be uploaded";
            hyperlink.Visible = false;
        }
    }
}

使用SqlCommand参数可以避免SQL注入。 不要通过插入值来构建SQL语句字符串。 这实际上也可以解决您的问题。

SqlCommand command = new SqlCommand(@"INSERT INTO Images (ImageName, ImageData, PicDetail, ImageSize, AlbumID)
    VALUES (@ImageName, @ImageData, @PicDetail, @ImageSize, @AlbumId)", con);

command.Parameters.AddWithValue("@ImageName", filename);
command.Parameters.AddWithValue("@ImageData", bytes);
command.Parameters.AddWithValue("@PicDetail", PicDetail);
command.Parameters.AddWithValue("@ImageSize", fileSize);
command.Parameters.AddWithValue("@AlbumId", FkAlbum);

https://msdn.microsoft.com/zh-CN/library/system.data.sqlclient.sqlcommand.parameters(v=vs.110).aspx

暂无
暂无

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM