ASP.NET - Coding Err - Asked By Jahir on 11-Feb-12 02:52 AM

This is y coding when i am execute this it shows err like this:
My Err;
Error:System.FormatException: Input string was not in a correct format. at System.Number.StringToNumber(String str, NumberStyles options, NumberBuffer& number, NumberFormatInfo info, Boolean parseDecimal) at System.Number.ParseSingle(String value, NumberStyles options, NumberFormatInfo numfmt) at System.Single.Parse(String s, NumberStyles style, NumberFormatInfo info) at System.Single.Parse(String s) at creditadd.GridView1_RowCommand(Object sender, GridViewCommandEventArgs e) in d:\tour\creditadd.aspx.cs:line 232

My codings:

cmd = new SqlCommand("select sum(credit) AS total from creditadd where cid<=cid and credit='" + txcredit.Text + "' and total='" + txtotal.Text + "'", con);

dr = cmd.ExecuteReader();

dr.Read();

if(dr.HasRows)

{

total=float.Parse(dr[0].ToString());

float f=total+float.Parse(txcredit.Text);

dr.Close();


cmd = new SqlCommand("update creditadd set credit='" + txcredit.Text + "' where cid ='" + lbid.Text + "'", con);

cmd.ExecuteNonQuery();

GridView1.EditIndex = -1;

Response.Write(

"<script>alert('Updated Successfully');</script>");

}

else

{

dr.Close();

}

cmd = new SqlCommand("select cid from creditadd where userid='" + txusrid.Text + "' and username='" + txusrname.Text + "'", con);

adap =

new SqlDataAdapter(cmd);

ds = new DataSet();

adap.Fill(ds);



for (int k = 0; k < ds.Tables[0].Rows.Count; k++)

{

int c = int.Parse(ds.Tables[0].Rows[k]["cid"].ToString());

// cmd = new SqlCommand("select total from creditadd where cid<=cid and userid='" + txusrid.Text + "' and username='" + txusrname.Text + "'", con);

cmd = new SqlCommand("select total from creditadd where cid='"+c.ToString()+"'",con);

dr = cmd.ExecuteReader();

dr.Read();


if (dr.HasRows)

{

total = float.Parse(dr[0].ToString());

float f = total + float.Parse(txcredit.Text);

dr.Close();

cmd = new SqlCommand("update creditadd set credit='" + txcredit.Text + "' where cid ='" + lbid.Text + "'", con);

cmd.ExecuteNonQuery();


}


else

{

dr.Close();

}

}

kalpana aparnathi replied to Jahir on 11-Feb-12 03:15 AM
hi,

I suggest you that TryParse to ensure your code will not throw an exception if it fails converting to a number and you can define a default value.

Thanks,
Danasegarane Arunachalam replied to Jahir on 12-Feb-12 01:24 AM
The Error Producing Lines will be

total=float.Parse(dr[0].ToString());

float f=total+float.Parse(txcredit.Text);



And you are trying to convert what the user enters in the text box. What happens when the user does not type anything in the textbox.
Then you will get the exception .

And the front end make sure that user entered some valid values. It the user does not enter anything then try to pass a 0 as default value.

And don't contact values for query use the Parameter collection instead


And here is the example for the parameter collection

static void Main()
    {
    //
    // The name we are trying to match.
    //
    string dogName = "Fido";
    //
    // Use preset string for connection and open it.
    //
    string connectionString = ConsoleApplication1.Properties.Settings.Default.ConnectionString;
    using (SqlConnection connection = new SqlConnection(connectionString))
    {
      connection.Open();
      //
      // Description of SQL command:
      // 1. It selects all cells from rows matching the name.
      // 2. It uses LIKE operator because Name is a Text field.
      // 3. @Name must be added as a new SqlParameter.
      //
      using (SqlCommand command = new SqlCommand("SELECT * FROM Tabble WHERE Name LIKE @Name", connection))
      {
        //
        // Add new SqlParameter to the command.
        //
        command.Parameters.Add(new SqlParameter("Name", dogName));
        //
        // Read in the SELECT results.
        //
        SqlDataReader reader = command.ExecuteReader();
        while (reader.Read())
        {
          int weight = reader.GetInt32(0);
          string name = reader.GetString(1);
          string breed = reader.GetString(2);
          Console.WriteLine("ITem1 = {0}, Item2 = {1}, Item3 = {2}", weight, name, breed);
        }
      }
    }
    }


Parameter collection saves from SQL injection and data type conversion errors