asp.net core sqlsugar timestamp 防sql注入方法
string sql= "insert into ts (title,dx,zt,tsnr,tpe,jhsj,bz,guid) values (@title,@dx,@zt,@tsnr,@tpe,@jhsj::timestamp,@bz,@guid)";
var par = new List<SqlSugar.SugarParameter>();
par.Add(new SqlSugar.SugarParameter("@tsnr", result));
par.Add(new SugarParameter("@jhsj",string.IsNullOrWhiteSpace(jhsj?.ToString()) ? DBNull.Value : jhsj));
_db.Ado.ExecuteCommand(sql, par);