Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

using variables in whereclause

Posted on 2012-03-29
7
Medium Priority
?
260 Views
Last Modified: 2012-03-29
Hi,
  I have something like below in my stored procedure

IF @physicianID = 0 OR @physicianID IS NULL
BEGIN
SET @whereClause = 'requestedby=@physicianID
            and examdate>=@startDate
            and examdate<=@endDate'
END
ELSE
BEGIN
SET @whereClause ='examdate>=@startDate
            and examdate<=@endDate'
END

and I used the variable @whereCluase like below

select
            examdate,
            patient_no
      from exams
      where @whereClause
      group by examdate,patient_no
Can I do like this? or please let me know how can I do that .

Thank you
0
Comment
Question by:Sthokala
  • 3
  • 3
7 Comments
 
LVL 61

Expert Comment

by:HainKurt
ID: 37783272
after your code do his

declare @sql varchar(max) = 'select ... from ...' + @whereClause
exec @sql
0
 
LVL 61

Expert Comment

by:HainKurt
ID: 37783288
oops, you need to work on this part too

SET @whereClause = 'requestedby=@physicianID
            and examdate>=@startDate
            and examdate<=@endDate'
>>>>
SET @whereClause = 'requestedby=' + @physicianID +
          ' and examdate>= ''' + @startDate + ''''
          ' and examdate<= ''' + @endDate + ''''
0
 
LVL 61

Expert Comment

by:HainKurt
ID: 37783311
and I guess there is logical error in your code "if... then ... else..." logic should be reversed...

so, final structure should be something like this

declare @whereClause varchar(max)
declare @startDate varchar(12)
declare @endDate varchar(12)
declare @physicianID int

IF isNull(@physicianID,0) = 0
BEGIN 
  SET @whereClause ='examdate >= ''' + @startDate + ''' and examdate <= ''' + @endDate + ''''
END
ELSE
BEGIN
  SET @whereClause = 'requestedby=' + @physicianID + ' and examdate>= ''' + @startDate + ''' and examdate<= ''' + @endDate + ''''
END

declare @sql varchar(max) = 'select ... from ...' + @whereClause
exec @sql

Open in new window

0
Fill in the form and get your FREE NFR key NOW!

Veeam is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

 
LVL 70

Expert Comment

by:Scott Pletcher
ID: 37783340
You have two choices:
    1.  Use one query, which tests the variable and column as needed.  
         This may not produce an optimal query plan every time it run.
    2.  Use dynamic SQL, which will produce an optimal query plan, but is more work
         to set up **and requires specific authorities being granted *directly* to the id
         used to run the SQL code**.


--1.
SELECT
            examdate,
            patient_no
      FROM dbo.exams
      WHERE
          (@physicianID = 0 OR @physicianID IS NULL OR requestedby = @physicianID) AND
          examdate>=@startDate and
          examdate<=@endDate'
      GROUP BY
          examdate, patient_no
0
 
LVL 70

Accepted Solution

by:
Scott Pletcher earned 2000 total points
ID: 37783367
--2.

DECLARE @sql nvarchar(max)

SET @sql = '
SELECT
            examdate,
            patient_no
      FROM dbo.exams
      WHERE
          examdate>=@startDate AND
          examdate<=@endDate
'

IF @physicianID > 0
    SET @sql = @sql + ' AND
           requestedby = ' + CAST(physicianID AS varchar(10))

SET @sql = @sql + '
       GROUP BY
          examdate, patient_no'

EXEC sp_executesql @sql, N'@startDate datetime, @endDate datetime', @startDate, @endDate
0
 

Author Comment

by:Sthokala
ID: 37783530
Hi,
  Thank you for your comments.  I tried below way

DECLARE @sql nvarchar(max)

SET @sql = ' INSERT INTO #TmpMUStatus
   SELECT count(*), (SELECT name from users where user_no='+CAST(@physicianID AS varchar(10))+') as physicianName,null,null,null,null,null,null,null,null,null,null,NULL,NULL from(
      SELECT
            examdate,
            patient_no
      FROM exams WHERE
          examdate>='+LEFT(CONVERT(VARCHAR, @startDate, 120), 10)
+' AND
          examdate<='+LEFT(CONVERT(VARCHAR, @endDate, 120), 10)

IF @physicianID > 0
    SET @sql = @sql + ' AND
           requestedby = ' + CAST(@physicianID AS varchar(10))

SET @sql = @sql + '
        GROUP BY examdate,patient_no) AS SourceQuery'
EXEC @sql


I am getting below error

Msg 203, Level 16, State 2, Procedure GenerateMUStats, Line 54
The name ' INSERT INTO #TmpMUStatus
   SELECT count(*), (SELECT name from users where user_no=73408) as physicianName,null,null,null,null,null,null,null,null,null,null,NULL,NULL from(
      SELECT
            examdate,
            patient_no
      FROM exams WHERE
          examdate>=2012-01-01 AND
          examdate<=2012-05-05 AND
           requestedby = 73408
        GROUP BY examdate,patient_no) AS SourceQuery' is not a valid identifier.
0
 
LVL 70

Expert Comment

by:Scott Pletcher
ID: 37783579
EXEC (@sql) -- the parens are required


Since you want pass to the date values in, you also need additional quotes:

...
FROM exams WHERE
          examdate>='''+LEFT(CONVERT(VARCHAR, @startDate, 112), 8)
+''' AND
          examdate<='''+LEFT(CONVERT(VARCHAR, @endDate, 112), 8) + ''''
...
0

Featured Post

Configuration Guide and Best Practices

Read the guide to learn how to orchestrate Data ONTAP, create application-consistent backups and enable fast recovery from NetApp storage snapshots. Version 9.5 also contains performance and scalability enhancements to meet the needs of the largest enterprise environments.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you have heard of RFC822 date formats, they can be quite a challenge in SQL Server. RFC822 is an Internet standard format for email message headers, including all dates within those headers. The RFC822 protocols are available in detail at:   ht…
Use this article to create a batch file to backup a Microsoft SQL Server database to a Windows folder.  The folder can be on the local hard drive or on a network share.  This batch file will query the SQL server to get the current date & time and wi…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
With just a little bit of  SQL and VBA, many doors open to cool things like synchronize a list box to display data relevant to other information on a form.  If you have never written code or looked at an SQL statement before, no problem! ...  give i…

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question