I am trying to convert the below working COSMOS DB SQL statement to a parametrized statement in SQL for COSMOS DB.
The part that I am struggling with is creating the parameters for the parameterized query in the for each loop.
As an example I have a Dictionary<string,string> object with key value pairs that contain the values that I need to search for.
I have built the query by adding the Key value pairs form the Dictionary<string,string> object to the SQL statement in a foreach loop but I would like to convert it to a parameterized statement for safety.
So I need to convert the below query to be a parameterized query for the index Key and values that I am searching on but I am not sure how to go about it.
var searchDictionary = new Dictionary<string, string>();
searchDictionary.Add("Name", "Bob");
searchDictionary.Add("Surname", "Builder");
var Institiute = "test";
StringBuilder sb = new StringBuilder();
sb.Append($"SELECT top 100 * FROM c WHERE c.college =@'{Institiute}'");
foreach (var item in request.IndexData)
{
sb.Append($" and c.indexData['{item.Key}'] = '{item.Value}'");
}
var sqlQueryText = sb.ToString();