You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET MVC图片上传至SQL Server Express时模型图片属性为空问题

问题分析与解决

你遇到的objProductModel.ProductImage为空的问题,由以下几个关键错误导致,逐一修正即可解决:

1. 视图中的表单嵌套与属性缺失

你的视图里嵌套了两层<form>标签,不符合HTML规范;同时外层表单未设置enctype="multipart/form-data"——这个属性是文件上传的必要条件,缺失会导致文件无法正确提交到控制器。

修正后的视图代码:

@model Nettbutikk.Models.ProductsModel

@{
}

@Html.Raw(ViewBag.msg)

@using (Html.BeginForm("NewProduct", "YourControllerName", FormMethod.Post, new { enctype = "multipart/form-data" }))
{
    @Html.AntiForgeryToken()

    <h1>Add New Product</h1>
    <p>
        <span>Product price<label>*</label></span>
        <br />
        @Html.EditorFor(model => model.ProductPrice, new { htmlattributes = new { @class = "control-form" } })
    </p>

    <p>
        <span>Image<label>*</label></span>
        <br />
        @Html.TextBoxFor(model => model.ProductImage, new { type = "file" })
    </p>

    <p>
        <input type="submit" value="Add New Product" />
    </p>
}

注意:将YourControllerName替换为你实际使用的控制器名称

2. 模型属性类型错误

模型中ProductImage使用了Image类型,ASP.NET Core无法直接将前端上传的文件绑定到该类型。正确的做法是使用IFormFile(属于Microsoft.AspNetCore.Http命名空间)来接收上传的文件流。

修正后的模型代码:

using Microsoft.AspNetCore.Http;

public class ProductsModel
{
    public IFormFile ProductImage { get; set; }
    public int ProductPrice { get; set; }
    public int ProductId { get; set; }
}

3. 控制器逻辑的错误与风险

  • 原代码直接拼接SQL语句,存在严重的SQL注入风险,必须改用参数化查询;
  • 原代码用Openrowset读取服务器本地文件,这不是处理前端上传文件的正确方式,应该读取上传文件的字节数组后直接存入数据库。

修正后的控制器代码:

using Microsoft.AspNetCore.Http;
using System.Data.SqlClient;
using System.IO;

[HttpPost]
public async Task<IActionResult> NewProduct(ProductsModel objProductModel)
{
    if (objProductModel.ProductImage == null || objProductModel.ProductImage.Length == 0)
    {
        ViewBag.msg = "请选择要上传的图片";
        return View();
    }

    string conStr = @"Data Source=.\SQLEXPRESS; Initial Catalog=Nettbutikk; Integrated Security=True";
    
    using (SqlConnection con = new SqlConnection(conStr))
    {
        await con.OpenAsync();
        
        // 读取上传文件的字节数组
        byte[] imageBytes;
        using (var ms = new MemoryStream())
        {
            await objProductModel.ProductImage.CopyToAsync(ms);
            imageBytes = ms.ToArray();
        }

        // 参数化查询,避免SQL注入
        string query = "INSERT INTO products(price, picture) VALUES (@Price, @Image)";
        using (SqlCommand cmd = new SqlCommand(query, con))
        {
            cmd.Parameters.AddWithValue("@Price", objProductModel.ProductPrice);
            cmd.Parameters.AddWithValue("@Image", imageBytes);
            await cmd.ExecuteNonQueryAsync();
        }
    }

    ViewBag.msg = "产品添加成功";
    return View();
}

额外注意事项

  • 确保SQL Server表中picture字段的类型为VARBINARY(MAX),用于存储字节数组形式的图片;
  • 使用using语句自动释放数据库连接和资源,避免资源泄漏。

内容的提问来源于stack exchange,提问作者javed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 12:40:12