Skip to content

Instantly share code, notes, and snippets.

@bertwagner
Created September 1, 2017 21:58
Show Gist options
  • Save bertwagner/48452945d98231d8a22345510abcbf3a to your computer and use it in GitHub Desktop.
Save bertwagner/48452945d98231d8a22345510abcbf3a to your computer and use it in GitHub Desktop.
CREATE PROCEDURE dbo.sp_GetFullNameFromTableSanitized
@ParmTableName varchar(100),
@ParmUserName varchar(100)
AS
BEGIN
DECLARE @FullQuery nvarchar(1000)
SET @FullQuery = N'SELECT FullName FROM dbo.' + QUOTENAME(@ParmTableName) + ' WHERE UserName = @UserName'
DECLARE @ParmDefinition nvarchar(100) = N'@UserName varchar(100)';
EXEC sp_executesql @FullQuery, @ParmDefinition,
@UserName = @ParmUserName
END
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment