"ASP.NET MVC与Sql Server交互, 插入数据"中,在Controller中拼接sql语句。比如:

_db.InsertData("insert into Product(Name,quantity,Price) values('"+productVm.Name+"','"+productVm.Quantity+"','"+productVm.Price+"')");


_db.InsertDataByDic("表名", 字典集合);



     public class SqlDB
        protected SqlConnection conn;

        public bool OpenConnection()
            conn = new SqlConnection(ConfigurationManager.ConnectionStrings["DefaultConnection"].ConnectionString);
                bool result = true;
                if (conn.State.ToString() != "Open")
                return result;
            catch (SqlException ex)
                return false;

        public bool CloseConnection()
                return true;
            catch (Exception ex)

                return false;

        public int InsertData(string sql)
            int lastId = 0;
            //string query = sql + ";SELECT @@Identity;";
                    SqlCommand cmd = new SqlCommand(sql, conn);
                    lastId = ToInt(cmd.ExecuteScalar());//返回第一行的第一列
                return ToInt(lastId);
            catch (Exception ex)

                return 0;

        private int ToInt(object o)
                return int.Parse(o.ToString());
            catch (Exception ex)

                return 0;

        public int InsertDataByDic(string tableName, Dictionary<string,string> dics)
            int lastId = 0;
            string keyStr = string.Empty;//拼接键
            string valStr = string.Empty;//拼接变量
            int index = 0;//索引
                foreach (KeyValuePair<string, string> item in dics)
                    keyStr += (index != 1 ? "," : "") + "[" + item.Key + "]";
                    valStr += (index != 1 ? "," : "") + "@" + item.Key;

                string query = "insert into " + tableName + "(" + keyStr + ") values (" + valStr + ");SELECT @@Identity;";
                if (conn.State.ToString() == "Open")
                    SqlCommand cmd = new SqlCommand(query, conn);
                    foreach (KeyValuePair<string, string> item in dics)
                        cmd.Parameters.AddWithValue("@" + item.Key, item.Value);
                    lastId = ToInt(cmd.ExecuteScalar());
                return ToInt(lastId);
            catch (Exception ex)
                return 0;


  public class TestController : Controller

        private SqlDB _db = new SqlDB();
        // GET: /Test/
        public ActionResult Index()
            bool r = _db.OpenConnection();
            if (r)
                return Content("连接成功");
                return Content("连接失败");

        public ActionResult AddProduct()
            return View();

        public ActionResult AddProduct(ProductVm productVm)
                int result = _db.InsertData("insert into Product(Name,quantity,Price) values('"+productVm.Name+"','"+productVm.Quantity+"','"+productVm.Price+"')");
                if(result > 0)
                    ModelState.AddModelError("success", "创建成功");
                    ModelState.AddModelError("error", "创建失败");
                return RedirectToAction("Index");
                return View(productVm);

        public ActionResult AddProductByDic()
            return View();

        public ActionResult AddProductByDic(ProductVm productVm)
            int i = 0;
            if (ModelState.IsValid)
                Dictionary<string, string> data = new Dictionary<string, string>();
                data["Name"] = productVm.Name;
                data["quantity"] = productVm.Quantity;
                data["Price"] = productVm.Price;
                i = _db.InsertDataByDic("Product", data);

                    return RedirectToAction("Index");
                    return View(productVm);
                return View(productVm);


@model Portal.Models.ProductVm

    ViewBag.Title = "AddProductByDic";
    Layout = "~/Views/Shared/_Layout.cshtml";


@using (Html.BeginForm("AddProductByDic", "Test", new { @id = "addForm" }, FormMethod.Post))

    <div class="form-horizontal">
        <hr />

        <div class="form-group">
            @Html.LabelFor(model => model.Name, new { @class = "control-label col-md-2" })
            <div class="col-md-10">
                @Html.EditorFor(model => model.Name)
                @Html.ValidationMessageFor(model => model.Name)

        <div class="form-group">
            @Html.LabelFor(model => model.Quantity, new { @class = "control-label col-md-2" })
            <div class="col-md-10">
                @Html.EditorFor(model => model.Quantity)
                @Html.ValidationMessageFor(model => model.Quantity)

        <div class="form-group">
            @Html.LabelFor(model => model.Price, new { @class = "control-label col-md-2" })
            <div class="col-md-10">
                @Html.EditorFor(model => model.Price)
                @Html.ValidationMessageFor(model => model.Price)

        <div class="form-group">
            <div class="col-md-offset-2 col-md-10">
                <input type="submit" value="创建" class="btn btn-default" />

    @Html.ActionLink("Back to List", "Index")

