Solved

exec sp_executesql syntax error

Posted on 2009-05-06
4
522 Views
Last Modified: 2012-05-06
I am attempting to retrieve records based on security I have set in a SQL table.
I have a field named ufilter that contains the filter to be applied to the data set.
In this case, the filter is: schoolnum = '032'
I keep receiving the error 'Incorrect syntax near 'schoolnum'.
I tested the SQL that is generated to the @cmd variable and the correct records are returned.

Any guidance would be most appreciated.


ALTER proc spPrincipalTest
(
@uid varchar(30)
)
as
 
DECLARE @ufilter nvarchar(200)
DECLARE @uexpdate datetime
DECLARE @CMD nvarchar(200)
 
select @ufilter=ufilter, @uexpdate=uexpdate from UFILTERS where uid=@uid
 
Print @ufilter
 
IF ISNULL(@ufilter, 'ZZTOP') = 'ZZTOP'
	BEGIN
		select * from dvASTUCurrentShort where 1 = 2
	END
 
IF @ufilter = 'NONE'
	BEGIN
		select * from dvASTUCurrentShort order by Lastname, Firstname
	END
ELSE
	BEGIN
		set @cmd = 'select * from dvASTUCurrentShort where ' + @ufilter
		print @cmd
		exec sp_executesql @cmd, @ufilter 
	END
 
Output:
schoolnum='032'
select * from dvASTUCurrentShort where schoolnum='032'
Incorrect syntax near 'schoolnum'.
No rows affected.
(0 row(s) returned)
@RETURN_VALUE = 0
Finished running [dbo].[spPrincipalTest].

Open in new window

0
Comment
Question by:JEClark
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 75

Accepted Solution

by:
Aneesh Retnakaran earned 250 total points
ID: 24318456

replace exec sp_executesql @cmd, @ufilter with EXEC(@cmd)
0
 

Author Comment

by:JEClark
ID: 24318537
Thanks for the quick response!
0
 
LVL 39

Expert Comment

by:BrandonGalderisi
ID: 24318545
You don't need to pass @ufilter into the sp_executesql command.

changed:
            exec sp_executesql @cmd, @ufilter

to

            exec sp_executesql @cmd

ALTER proc spPrincipalTest
(
@uid varchar(30)
)
as
 
DECLARE @ufilter nvarchar(200)
DECLARE @uexpdate datetime
DECLARE @CMD nvarchar(200)
 
select @ufilter=ufilter, @uexpdate=uexpdate from UFILTERS where uid=@uid
 
Print @ufilter
 
IF ISNULL(@ufilter, 'ZZTOP') = 'ZZTOP'
	BEGIN
		select * from dvASTUCurrentShort where 1 = 2
	END
 
IF @ufilter = 'NONE'
	BEGIN
		select * from dvASTUCurrentShort order by Lastname, Firstname
	END
ELSE
	BEGIN
		set @cmd = 'select * from dvASTUCurrentShort where '   @ufilter
		print @cmd
		exec sp_executesql @cmd
	END

Open in new window

0
 
LVL 39

Expert Comment

by:BrandonGalderisi
ID: 24318557
That WILL work, but you should be using sp_executeSQL.  The problem was that you were passing @ufilter in and didn't need to.
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Creating and Managing Databases with phpMyAdmin in cPanel.
In this article we will get to know that how can we recover deleted data if it happens accidently. We really can recover deleted rows if we know the time when data is deleted by using the transaction log.
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question