Solved

Passing options to Stored procedure

Posted on 2011-09-14
3
200 Views
Last Modified: 2012-05-12
Hi There,

My stored procedure takes two parameters from the application, options and amount.
@option can be = or > or <.

How can I take the @option value and replace in the where condition?


USE [Test]
GO

SET ANSI_NULLS ON
GO
SET QUOTED_IDENTIFIER ON
GO


ALTER PROCEDURE [dbo].[search]


      @option varchar,
      @Amount Decimal

      
AS

      

SELECT
      [Search].[Id],
      [Search].[Amount],

FROM
      [dbo].[Search]
      WHERE
      (
      
            [Search].[Amount] @Option @Amount
      
            --i.e  [Search].[Amount] > @Amount


      )
0
Comment
Question by:theartha
  • 2
3 Comments
 
LVL 18

Expert Comment

by:lludden
ID: 36536723
You can use dynamic SQL

ALTER PROCEDURE [dbo].[search]
      @option varchar,
      @Amount Decimal
AS
DECLARE @SQL varchar(max) =
'SELECT
      [Search].[Id],
      [Search].[Amount],

FROM
      [dbo].[Search]
      WHERE  [Search].[Amount] ' +  @Option  + CAST(@Amount as varchar(20))
     
EXECUTE (@SQL)
0
 
LVL 18

Accepted Solution

by:
lludden earned 250 total points
ID: 36536752
If you are not comfortable with dynamic SQL (I am not without very well washed inputs), you can do this:
ALTER PROCEDURE [dbo].[search]
      @option varchar,
      @Amount Decimal
AS
SELECT
      [Search].[Id],
      [Search].[Amount],
FROM
      [dbo].[Search]
      WHERE (@Option = '=' AND Search.Amount = @Amount)
OR
      (@Option = '<' AND Search.Amount < @Amount)
OR
      (@Option = '>' AND Search.Amount > @Amount)

     
     
            [Search].[Amount] @Option @Amount
     
            --i.e  [Search].[Amount] > @Amount


      )
0
 
LVL 15

Assisted Solution

by:tim_cs
tim_cs earned 250 total points
ID: 36536776
You don't want to use dynamic SQL as that opens up security issues.  You could do something like this...
SELECT
   ID
   Amount
FROM
   Search
WHERE
   (Amount = @amount AND @option = 'Equal)
   OR (Amount > @amount AND @option = 'Greater')
   OR (Amount < @amount AND @option = 'Less')

Open in new window

0

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

If you have heard of RFC822 date formats, they can be quite a challenge in SQL Server. RFC822 is an Internet standard format for email message headers, including all dates within those headers. The RFC822 protocols are available in detail at:   ht…
Ever needed a SQL 2008 Database replicated/mirrored/log shipped on another server but you can't take the downtime inflicted by initial snapshot or disconnect while T-logs are restored or mirror applied? You can use SQL Server Initialize from Backup…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now