-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathAddVolunteerC.aspx.cs
112 lines (85 loc) · 4.46 KB
/
AddVolunteerC.aspx.cs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Data;
using System.Data.SqlClient;
using System.Web.Configuration;
namespace CapstoneFinal
{
public partial class AddVolunteerC : System.Web.UI.Page
{
protected void Page_Load(object sender, EventArgs e)
{
}
protected void butClear_Click(object sender, EventArgs e)
{
txtFirstName.Text = String.Empty;
Response.Redirect("AddVolunteer.aspx");
}
protected void butCreate_Click(object sender, EventArgs e)
{
String sqlQuery = "SELECT * FROM EventPersonnel";
SqlConnection sqlConnect = new SqlConnection(WebConfigurationManager.ConnectionStrings["lab4"].ToString());
SqlCommand sqlCommand = new SqlCommand();
sqlCommand.Connection = sqlConnect;
sqlCommand.CommandType = CommandType.Text;
sqlCommand.CommandText = sqlQuery;
sqlConnect.Open();
SqlDataReader queryResults = sqlCommand.ExecuteReader();
int counter = 0;
while (queryResults.Read())
{
counter++;
}
queryResults.Close();
sqlCommand = new SqlCommand();
sqlQuery = "INSERT INTO EventPersonnel VALUES ( '" + counter.ToString() + "' , @FirstName , @LastName , @Email , @Phone , 'Volunteer' , @ShirtInfoID) ";
sqlCommand.Parameters.AddWithValue("@FirstName", HttpUtility.HtmlEncode(txtFirstName.Text));
sqlCommand.Parameters.AddWithValue("@LastName", HttpUtility.HtmlEncode(txtLastName.Text));
sqlCommand.Parameters.AddWithValue("@Email", HttpUtility.HtmlEncode(txtEmail.Text));
sqlCommand.Parameters.AddWithValue("@Phone", HttpUtility.HtmlEncode(txtPhone.Text));
sqlCommand.Parameters.AddWithValue("@ShirtInfoID", HttpUtility.HtmlEncode(ListBox1.SelectedValue));
sqlCommand.Connection = sqlConnect;
sqlCommand.CommandType = CommandType.Text;
sqlCommand.CommandText = sqlQuery;
queryResults = sqlCommand.ExecuteReader();
queryResults.Close();
sqlConnect.Close();
if (txtFirstName.Text != "" && txtLastName.Text != "" && txtPassword.Text != "" && txtEmail.Text != "")
{
try
{
System.Data.SqlClient.SqlConnection sc = new System.Data.SqlClient.SqlConnection();
sc.ConnectionString = @"Server=LOCALHOST;Database=AUTH;Trusted_Connection=Yes;"; // connect to PBKDF2 Auth database
sc.Open();
System.Data.SqlClient.SqlCommand createUser = new System.Data.SqlClient.SqlCommand();
createUser.Connection = sc;
// INSERT USER RECORD
createUser.CommandText = "insert into[dbo].[Person] values(@FName, @LName, @Username)";
createUser.Parameters.Add(new SqlParameter("@FName", HttpUtility.HtmlEncode(txtFirstName.Text)));
createUser.Parameters.Add(new SqlParameter("@LName", HttpUtility.HtmlEncode(txtLastName.Text)));
createUser.Parameters.Add(new SqlParameter("@Username", HttpUtility.HtmlEncode(txtEmail.Text)));
createUser.ExecuteNonQuery();
System.Data.SqlClient.SqlCommand setPass = new System.Data.SqlClient.SqlCommand();
setPass.Connection = sc;
setPass.CommandText = "insert into[dbo].[Pass] values((select max(userid) from person), @Username, @Password)";
setPass.Parameters.Add(new SqlParameter("@Username", HttpUtility.HtmlEncode(txtEmail.Text)));
setPass.Parameters.Add(new SqlParameter("@Password", PasswordHash.HashPassword(HttpUtility.HtmlEncode(txtPassword.Text)))); // hash entered password
setPass.ExecuteNonQuery();
sc.Close();
txtFirstName.Enabled = false;
txtLastName.Enabled = false;
txtEmail.Enabled = false;
txtPassword.Enabled = false;
Response.Redirect("login.aspx");
}
catch
{
}
}
}
}
}