narsil/Tanshu.Accounts.SqlDAO/UserDAO.cs

114 lines
4.4 KiB
C#

using System;
using System.Collections.Generic;
using System.Data.SqlClient;
using Tanshu.Accounts.Contracts;
using Tanshu.Data.DAO;
namespace Tanshu.Accounts.SqlDAO
{
public class UserDAO : BaseDAO
{
public UserDAO(IConnectionDAO connection)
: base(connection)
{ }
public UserBO GetUser(Guid userID)
{
var cmd = new SqlCommand("SELECT * FROM Users WHERE UserID = @UserID");
cmd.Parameters.AddWithValue("@UserID", userID);
return BusinessObjectDAO<UserBO>.GetBusinessObject(connection.ExecuteReader(cmd));
}
public List<UserBO> GetUsers()
{
return BusinessObjectDAO<UserBO>.GetBusinessObjects(connection.ExecuteReader("SELECT * FROM Users"));
}
public List<UserBO> GetFilteredUsers(Dictionary<string, string> filter)
{
var name = string.Format("%{0}%", filter["Name"]);
using (var cmd = new SqlCommand("SELECT * FROM Users WHERE Name LIKE @Name ORDER BY Name"))
{
cmd.Parameters.AddWithValue("@Name", name);
return BusinessObjectDAO<UserBO>.GetBusinessObjects(connection.ExecuteReader(cmd));
}
}
public bool UserExists(string userName)
{
using (var cmd = new SqlCommand("SELECT Count(*) FROM Users WHERE Name = @Name"))
{
cmd.Parameters.AddWithValue("@Name", userName);
return (int)connection.ExecuteScalar(cmd) == 1;
}
}
public bool Insert(UserBO user)
{
using (var cmd = new SqlCommand(@"
SELECT @UserID = NEWID()
INSERT INTO Users (UserID, Name, Password, LockedOut)
VALUES (@UserID, @Name, @Password, @LockedOut)
"))
{
cmd.Parameters.Add("@UserID", System.Data.SqlDbType.UniqueIdentifier);
cmd.Parameters["@UserID"].Direction = System.Data.ParameterDirection.Output;
cmd.Parameters.AddWithValue("@Name", user.Name);
cmd.Parameters.AddWithValue("@Password", user.Password);
cmd.Parameters.AddWithValue("@LockedOut", user.LockedOut);
connection.ExecuteNonQuery(cmd);
user.UserID = (Guid)cmd.Parameters["@UserID"].Value;
return true;
}
}
//public bool CheckPassword(string userName, string password)
//{
// using (SqlCommand cmd = new SqlCommand("SELECT Count(*) FROM Users WHERE Name = @Name AND Password = @Password"))
// {
// cmd.Parameters.AddWithValue("@Name", userName);
// cmd.Parameters.AddWithValue("@Password", password);
// return (int)connection.ExecuteScalar(cmd) == 1;
// }
//}
public bool ChangePassword(UserBO userData, string newPassword)
{
using (SqlCommand cmd = new SqlCommand("UPDATE Users SET Password = @NewPassword WHERE Name = @Name AND Password = @Password; SELECT @@rowcount"))
{
cmd.Parameters.AddWithValue("@Name", userData.Name);
cmd.Parameters.AddWithValue("@Password", userData.Password);
cmd.Parameters.AddWithValue("@NewPassword", newPassword);
return (int)connection.ExecuteScalar(cmd) == 1;
}
}
public bool Update(UserBO user)
{
using (SqlCommand cmd = new SqlCommand(@"
UPDATE Users SET
Name = @Name,
Password = @Password,
LockedOut = @LockedOut
WHERE UserID = @UserID;
"))
{
cmd.Parameters.AddWithValue("@UserID", user.UserID);
cmd.Parameters.AddWithValue("@Name", user.Name);
cmd.Parameters.AddWithValue("@Password", user.Password);
cmd.Parameters.AddWithValue("@LockedOut", user.LockedOut);
connection.ExecuteNonQuery(cmd);
return true;
}
}
public bool Delete(Guid userID)
{
using (SqlCommand cmd = new SqlCommand("DELETE FROM Users WHERE UserID = @UserID"))
{
cmd.Parameters.AddWithValue("@UserID", userID);
connection.ExecuteNonQuery(cmd);
return true;
}
}
}
}
//private static log4net.ILog log
//= log4net.LogManager.GetLogger(
// System.Reflection.MethodBase.GetCurrentMethod().DeclaringType);