Solved

Int and VarChar types in where clause

Posted on 2009-07-13
8
947 Views
Last Modified: 2012-06-27
hi,

I have the below Stored proc which passes in the field name and values to filter on. It works great. However, some of the columns are of type int and others are varchar. The varchar columns need the values in quotes, but the int columns do not. Therefore the below only works for varchars.

Is there any easy fix? Thanks
CREATE PROC test
@columName  varchar(30),
@value  varchar(30)
AS
BEGIN
    EXECUTE(
    'SELECT     D.id_desk,
                D.id_region           
    FROM        DESK D,
                INSTRUMENT I
    WHERE '      + @columName + ' LIKE ''' + @value +'''
    AND         I.id_desk = D.id_desk' )
END
go

Open in new window

0
Comment
Question by:bowemc
  • 4
  • 2
8 Comments
 
LVL 6

Accepted Solution

by:
IncisiveOne earned 250 total points
ID: 24844729
Hang on, that does not "work great".  This sort of thing is completely incorrect.  First an explanation.  Actually, two explanations.

1  SQL is sometimes called a loosely-typed language, because there are few enforcements of the Datatypes in the language itself.  That is incorrect.  The whole idea is that SQL is a DATABASE manipulation language, and the DATABASE is not loosely-typed, it is fixed (the Datatypes are set once, and they do not change.  The correct understanding is, SQL is actually a tightly-typed language, the Typing is in the database.  Therefore it is incumbent upon you, all coders, to always be aware of the Datatype of the column, and to treat it accordingly; using the correct Datatype wherever the column is referenced.

Note that Datatype mismatches are probably the most common mistake, and they always lead to poor performance (eg. Sybase cannot use the index on an indexe column, when the wrong Datatype is used, and thus has to table scan).  This is easily confirmed in the showplan, which every coder should produce and examine for every code segment.  Datatypes mismatches are also the easiest mistakes to avoid; by having good simple standards:

Always use the correct Datatype for the column.
1.1  Therefore you cannot do what you are trying to do (write a generic SQL statement [forget the proc for now] that can perform a LIKE on any column).

1.2  Like is for char and varchar only, you cannot perform like on int, smallint, etc.

2  I appreciate that you are learning SQL, stored procs, and how to go about creating the various objects you need; that this is test proc.  However, in order for you to learn the correct methods (and to identify the incorrect methods), I will treat this proc as real (not test), and identify the issues.

2.1  The use of execute here is superfluous, and can be removed.  The code will  perform better, and it would lead you to a better understanding of the problem/solution.  Stated another way: take the execute out, get the code working without it, and if you need to, after you have working code, then put it back in.

2.2  Thing about this.  Regardless of what you write, immediate code, ordinary code, dynamic SQL, stored procs, the Optimiser has to (a) parse it (b) compile it and then (c) execute it.  Therefore the simple straight SQL is the best, to write and test.  Once you have that working correctly, then place it in dynamic or immediate code.  That means you will have specific code segments for each table or table combination; generic SQL in an application is not a reasonable goal.  Generic SQL is qiuite reasonable for utilities, but that is a different story, not addressed here; by definition, your application code is not an utility.

2.3  You do not have any error checking or column Datatype checking, which you must have

2.4  Remember the Datatype of the column in the database is fixed, and that Datatype is the final truth about the column, so that is what our code should be based on.  It should not be based on "what we want to do", it should be based on "what the column is", and therefore what is possible on the column.

Cheers



CREATE PROC
    DeskInstrument_search
        @columnName  varchar(30) = NULL,
        @searchStr   varchar(30) = NULL
AS
    IF @columnName = NULL
        BEGIN
        PRINT "You must provide a @columnName"
        -- cannot search a column without knowing which col to search
        GOTO EXIT_ERR
        END
 
    -- check if column is known var/char column
    -- exclude int, numeric, date, etc
    IF  @columnName != "deskName" AND 
        @columnName != "deskDescription" AND
        @columnName != "instrName" AND
        @columnName != "instrDescription" AND
        @columnName != "instrAddress1" AND
        @columnName != "instrAddress2"
        BEGIN
        PRINT "@columnName must be a var/char column in DESK or INSTRUMENT"
        GOTO EXIT_ERR
        END
 
    IF CHARINDEX( "%", @searchStr ) = 0  -- et cetera
        BEGIN
        PRINT "@searchStr must be a valid LIKE operand"
        -- otherwise we cannot perform LIKE with it
        GOTO EXIT_ERR
        END
 
    IF @searchStr = NULL
        SELECT  D.id_desk,
                D.id_region           
            FROM  DESK D,
                  INSTRUMENT I
            WHERE I.id_desk = D.id_desk
    ELSE
        SELECT  D.id_desk,
                D.id_region           
            FROM  DESK D,
                  INSTRUMENT I
            WHERE I.id_desk = D.id_desk
            AND   @columnName LIKE @searchStr
 
    IF @@rowcount = 0
        BEGIN
        PRINT "Search string %1! not found in column %1!", @searchStr, @columnName
        END
 
EXIT_OK:
    RETURN 0
 
EXIT_ERR:
    RETURN -1

Open in new window

0
 
LVL 6

Expert Comment

by:IncisiveOne
ID: 24844887
Er, that's for discussion/progress, obviously the code will not work without the execute.
0
 
LVL 13

Assisted Solution

by:alpmoon
alpmoon earned 250 total points
ID: 24856221
What about this? It would convert numeric columns into char and then search the value:

CREATE PROC test
@columName  varchar(30),
@value  varchar(30)
AS
BEGIN
  IF exists(select * from syscolumns
                  where id in (object_id('DESK), object_id(' INSTRUMENT'))
                       and type in (39, 47) -- char or varchar
    EXECUTE(
    'SELECT     D.id_desk,
                D.id_region          
    FROM        DESK D,
                INSTRUMENT I
    WHERE '      + @columName + ' LIKE ''' + @value +'''
    AND         I.id_desk = D.id_desk' )

  ELSE

    EXECUTE(
    'SELECT     D.id_desk,
                D.id_region          
    FROM        DESK D,
                INSTRUMENT I
    WHERE convert(char,'      + @columName + ') LIKE ''' + @value +'''
    AND         I.id_desk = D.id_desk' )

END
go
0
Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

 
LVL 13

Expert Comment

by:alpmoon
ID: 24957813
Have you tried it? Is it useful for your end?
0
 
LVL 13

Expert Comment

by:alpmoon
ID: 25156430
I think my solution is more flexible and efficient. If table structure is changed, the procedure doesn't need to be modified.

I suggest split between me and IncisiveOne
0
 
LVL 13

Expert Comment

by:alpmoon
ID: 25164789
I think my solution is more flexible and efficient. If table structure is changed, the procedure doesn't need to be modified.

I suggest split between me and IncisiveOne
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

With User Account Control (UAC) enabled in Windows 7, one needs to open an elevated Command Prompt in order to run scripts under administrative privileges. Although the elevated Command Prompt accomplishes the task, the question How to run as script…
When it comes to protecting Oracle Database servers and systems, there are a ton of myths out there. Here are the most common.
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question