Windows Forms C#实现登录后从数据库加载用户信息至文本框
在Windows Forms C#中实现登录后显示用户资料的方案
一、修复登录代码的安全问题并获取用户信息
你的原代码存在SQL注入风险,同时未保存登录用户的详细信息,先修改这部分代码,使用参数化查询并读取用户数据:
// 定义变量存储用户信息,根据你的tblUser表字段调整 string userId = ""; string userFullName = ""; string userEmail = ""; OleDbConnection connection = new OleDbConnection(); connection.ConnectionString = @"Provider=Microsoft.ACE.OLEDB.12.0;Data Source=C:\Users\RAV21001310\OneDrive\Database1.accdb;"; try { connection.Open(); // 使用参数化查询避免SQL注入 OleDbCommand command = new OleDbCommand("select * from tblUser where Username = ? and Password = ?", connection); command.Parameters.AddWithValue("@Username", username.Text); command.Parameters.AddWithValue("@Password", password.Text); OleDbDataReader reader = command.ExecuteReader(); if (reader.HasRows) { // 读取当前登录用户的信息 reader.Read(); userId = reader["UserId"].ToString(); // 替换为你表中的用户ID字段名 userFullName = reader["FullName"].ToString(); // 替换为你表中的姓名字段名 userEmail = reader["Email"].ToString(); // 替换为你表中的邮箱字段名 // 继续读取其他需要展示的字段 MessageBox.Show("登录成功"); // 打开资料页并传递用户信息 Profile profileForm = new Profile(userId, userFullName, userEmail); profileForm.Show(); this.Hide(); // 隐藏登录窗口 } else { MessageBox.Show("用户名或密码错误"); } } catch (Exception ex) { MessageBox.Show("登录出错:" + ex.Message); } finally { connection.Close(); }
二、修改资料页(Profile)的构造函数
在你的Profile窗体中,添加带参数的构造函数,用于接收并展示用户信息:
// 假设Profile窗体有这些文本框:txtUserId、txtFullName、txtEmail public partial class Profile : Form { public Profile(string userId, string fullName, string email) { InitializeComponent(); // 将传递的信息赋值给对应文本框 txtUserId.Text = userId; txtFullName.Text = fullName; txtEmail.Text = email; // 其他字段同理赋值 } }
三、进阶方案:用类封装用户信息(字段较多时更易用)
如果用户资料字段较多,可定义一个User类来统一管理数据:
- 定义User类:
public class User { public string Id { get; set; } public string Username { get; set; } public string FullName { get; set; } public string Email { get; set; } // 添加你需要的其他属性,如手机号、地址等 }
- 登录时读取并传递User对象:
// 登录代码中读取用户信息部分改为: User currentUser = new User(); reader.Read(); currentUser.Id = reader["UserId"].ToString(); currentUser.Username = reader["Username"].ToString(); currentUser.FullName = reader["FullName"].ToString(); currentUser.Email = reader["Email"].ToString(); // 打开资料页 Profile profileForm = new Profile(currentUser); profileForm.Show();
- Profile窗体的构造函数:
public Profile(User user) { InitializeComponent(); txtUserId.Text = user.Id; txtUsername.Text = user.Username; txtFullName.Text = user.FullName; txtEmail.Text = user.Email; }
注意事项
- 确保代码中读取的字段名与
tblUser表的实际字段名完全一致(注意大小写匹配) - 禁止用字符串拼接SQL语句,参数化查询是防范SQL注入的必要手段
- 可将数据库连接字符串移至项目配置文件,方便后续修改
内容的提问来源于stack exchange,提问作者Muhammad Ravat
相关产品推荐
相关产品推荐

