Solved

Select records from an MS SQL 2K table using value list parameter

Posted on 2004-08-11
8
244 Views
Last Modified: 2008-03-10
I'm contructing a stored proc like the following:

CREATE PROCEDURE Select_Widgets
    @WidgetsList varChar(20)
    AS
    Select * From Table1
    Where WidgetID In(@WidgetsList )

but am getting the following error from sql server 2k when running through the debugger: 'Syntax error converting the varchar value '2,5' to a column of data type int'.  The target field is an int, so I'm passing a comma delimited list of int values without quotes around each value.
0
Comment
Question by:LloydMc
8 Comments
 
LVL 15

Expert Comment

by:jdlambert1
ID: 11776288
Don't know if there's a better way, but this works:

CREATE PROCEDURE Select_Widgets
    @WidgetsList varChar(20)
AS

DECLARE @sql nvarchar(888)

SET @sql = 'Select * From Table1 Where WidgetID In ( ' + @WidgetsList + ') '

EXEC sp_executesql @sql
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 11776453
jdlambert1: I agree, this is 'the' solution, no better choices availlable ...
0
 
LVL 18

Accepted Solution

by:
SjoerdVerweij earned 125 total points
ID: 11777172
Ehm... how about

Create Procedure Select_Widgets
  @WidgetList VarChar(255)
As
Begin

  Declare @TWidget Table(ID Int)

  Declare @P Int

  While (@P > 0)
    Begin
      Set @P = CharIndex(',', @WidgetList)
      If (@P <= 0)
        Insert Into @TWidget(ID) Values(Cast(@WidgetList As Int))
      Else
        Begin
          Insert Into @TWidget(ID) Values(Cast(Left(@WidgetList, @P-1) As Int))
          Set @WidgetList = SubString(@WidgetList, @P + 1, 255)
        End
    End
 
  Select * From Table1 Where WidgetID In (Select ID From @TWidget)

End
Go

No dynamic SQL needed.
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 34

Expert Comment

by:arbert
ID: 11777410
Have to agree with SjoerdVerweij here.  Looks overly complicated, but you don't have the penalty of Dynamic SQL and you don't have to worry about the security implications of dynamic sql...
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 11782187
If security is an issue, last solution is best. If it is not, first solution is more fexible, since you can use a subselect as argument (and this is indeed the security break ...).
0
 
LVL 18

Expert Comment

by:SjoerdVerweij
ID: 11784968
Call the first version like so:

Select_Widgets '0);select user --'

It's called a SQL injection attack.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Nowadays, some of developer are too much worried about data. Who is using data, who is updating it etc. etc. Because, data is more costlier in term of money and information. So security of data is focusing concern in days. Lets' understand the Au…
International Data Corporation (IDC) prognosticates that before the current the year gets over disbursing on IT framework products to be sent in cloud environs will be $37.1B.
Using examples as well as descriptions, and references to Books Online, show the different Recovery Models available in SQL Server and explain, as well as show how full, differential and transaction log backups are performed
Via a live example, show how to backup a database, simulate a failure backup the tail of the database transaction log and perform the restore.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now