VB.NET中TextBox数据插入User表遇对象名无效SqlException错误
Hey there! Let's work through the issues causing your SqlException and get your user creation code working properly:
1. Table Name Spelling Mistake
Looking at your SQL query, you wrote insert into Utlisateur (...) — notice the missing 'i'? The correct French spelling for "User" is Utilisateur (with two 'i's). Your error message mentions "Invalid User object name" which suggests either the table name is misspelled in your query, or the actual table in your database is named User instead of Utilisateur. Double-check your database schema to confirm the exact table name, then fix the query accordingly.
2. Wrong Execution Method for Insert Operations
You're using ExecuteReader() to run an INSERT statement — this method is designed for reading result sets from SELECT queries, not for write operations like INSERT/UPDATE/DELETE. For these actions, you should use ExecuteNonQuery(), which returns the number of rows affected by the command.
3. Critical SQL Injection Vulnerability
Directly concatenating TextBox values into your SQL query is extremely dangerous — it leaves your database wide open to SQL injection attacks. Always use parameterized queries to safely pass user input to your database.
Corrected Code
Here's the revised version of your code addressing all three issues:
' Get connection string from settings Dim CnxAppli As String = "Server=" & My.Settings.nomServeur & "; DataBase=" & My.Settings.nomBDD & "; Uid=" & My.Settings.idUser & "; Pwd=" & My.Settings.mdp & "; Integrated Security=SSPI;" ' Use Using statements to automatically dispose connections/commands (best practice) Using sqlConnect As New SqlConnection(CnxAppli) ' Fix the table name here (ensure it matches your actual database table) Dim SqlReq As String = "INSERT INTO Utilisateur (nom, prenom, tel, mail, poste, login, mdp) VALUES (@nom, @prenom, @tel, @mail, @poste, @login, @mdp)" Using SqlCommande As New SqlCommand(SqlReq, sqlConnect) ' Add parameters with user input (prevents SQL injection) SqlCommande.Parameters.AddWithValue("@nom", tbNom.Text) SqlCommande.Parameters.AddWithValue("@prenom", tbPrenom.Text) SqlCommande.Parameters.AddWithValue("@tel", tbTel.Text) SqlCommande.Parameters.AddWithValue("@mail", tbMail.Text) SqlCommande.Parameters.AddWithValue("@poste", tbPoste.Text) SqlCommande.Parameters.AddWithValue("@login", tbLogin.Text) SqlCommande.Parameters.AddWithValue("@mdp", tbMdp.Text) ' Open connection and execute the insert sqlConnect.Open() Dim rowsAffected As Integer = SqlCommande.ExecuteNonQuery() ' Optional: Check if the insert was successful If rowsAffected > 0 Then MessageBox.Show("Utilisateur créé avec succès!") End If End Using End Using GestionUtilisateurs.Show() Me.Close()
Key Improvements in the Corrected Code:
- Using Statements: Automatically handle closing and disposing of database connections and commands, preventing resource leaks.
- Parameterized Query: Eliminates SQL injection risks and handles special characters in user input (like apostrophes) correctly.
- ExecuteNonQuery: Proper method for write operations, returns the number of rows inserted to verify success.
- Fixed Table Name: Corrected the spelling of
Utilisateur(adjust this if your actual table name is different, e.g.,User).
内容的提问来源于stack exchange,提问作者JeMenBeur

