@Override public void updateUser(User user) throws Exception { StringBuffer sqlStmt = new StringBuffer().append("UPDATE ").append(usersTable).append(" SET"); sqlStmt.append(" firstname='").append(user.getFirstname()); sqlStmt.append("', lastname='").append(user.getLastname()); sqlStmt.append("', email='").append(user.getEmail()); sqlStmt.append("' WHERE username='******'"); /*String sqlStmt = "UPDATE "+usersTable+" SET" + " firstname='" + user.getFirstname() + "', lastname='" + user.getLastname() + "', email='" + user.getEmail() + "' WHERE username='******'";*/ doUpdate(sqlStmt.toString()); }
@Override public void addUser(User user) throws Exception { StringBuffer sqlStmt = new StringBuffer(); sqlStmt.append("INSERT INTO ").append(usersTable); sqlStmt.append(" (username, firstname, lastname, email) VALUES ('"); sqlStmt.append(user.getUsername()).append("','"); sqlStmt.append(user.getFirstname()).append("','"); sqlStmt.append(user.getLastname()).append("','"); sqlStmt.append(user.getEmail()); sqlStmt.append("')"); /*String sqlStmt = "INSERT INTO "+usersTable+" (username, firstname, lastname, email) VALUES ('" + user.getUsername() + "','" + user.getFirstname() + "','" + user.getLastname() + "','" + user.getEmail() + "')";*/ doUpdate(sqlStmt.toString()); }