You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

System.ArgumentException报错:数据源不能为空,求SQLite连接问题解决方案

Fixing "Data Source cannot be empty" Error in SQLite Connection

Hey there! I see you're building a productivity tool and ran into a SQLite connection hiccup—let's get this sorted for you right away.

Root Cause of the Error

The core issue here is how you've structured your connection string. You placed the @ symbol inside the double quotes, which turns it into part of the string literal instead of letting it act as a verbatim string prefix. SQLite ends up parsing a connection string that starts with @Data Source instead of the valid Data Source, so it can't recognize the actual database file path—hence the "Data Source cannot be empty" error.

Quick Fix for the Connection String

Move the @ outside the quotes so it properly marks the string as verbatim (this also avoids escape character issues if you later use full file paths):

string dbcon = @"Data Source=KMS.db;Version=3;";

Note: I also removed the extra space after =—while SQLite might tolerate it, keeping the syntax consistent makes your code cleaner and less prone to unexpected issues.

Critical Security & Code Upgrade: Avoid SQL Injection

Your current login query directly concatenates user input into the SQL string, which is a massive security risk (it leaves your app wide open to SQL injection attacks). Always use parameterized queries instead. Here's how to update your logic safely:

try {
    // Using 'using' ensures the connection is auto-disposed, preventing resource leaks
    using (SQLiteConnection sqlcon = new SQLiteConnection(dbcon)) 
    {
        sqlcon.Open();
        // Parameterized query to block SQL injection
        string query = "SELECT * FROM user WHERE Username = @Username AND Password = @Password";
        using (SQLiteCommand com = new SQLiteCommand(query, sqlcon))
        {
            // Bind user input to parameters (never concatenate directly!)
            com.Parameters.AddWithValue("@Username", textusername.Text);
            com.Parameters.AddWithValue("@Password", textpassword.Text);
            
            using (SQLiteDataReader dr = com.ExecuteReader())
            {
                int matchCount = 0;
                while (dr.Read()) {
                    matchCount++;
                }
                if(matchCount == 1) {
                    KMS_MainMenu MainMenu = new KMS_MainMenu();
                    MainMenu.Show();
                    this.Hide();
                } else {
                    EmptyErrorLabel.Visible = true;
                    EmptyErrorLabel.Text = "Invalid Username and / or Password";
                    textpassword.Clear();
                }
            }
        }
    }
} catch (Exception ex) {
    MessageBox.Show("Error while logging: " + ex);
}

Key Improvements Here:

  • using statements for all database objects: This guarantees resources are properly released even if an error occurs, no manual cleanup needed.
  • Parameterized queries: Eliminates SQL injection risks entirely by separating user input from the SQL logic.
  • Simplified the success/failure check: Since matchCount can only be 0 or 1 here, an else clause works perfectly instead of a separate if(i < 1) check.

Quick Additional Check

Double-check that KMS.db is in the right location: If you're running the app from Visual Studio, the database file should live in your project's output folder (usually bin/Debug or bin/Release). If it's missing, set the file's "Copy to Output Directory" property to "Copy if newer" in Visual Studio's Solution Explorer.

内容的提问来源于stack exchange,提问作者Francisco Mendonça

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 09:12:44