Take a look at "Converting DataSourceRequest filters to SqlServer parameterized query in controller Read method" that I posted in Telerik forums.
There are three pieces that go deeper and deeper.
Reader
public ActionResult MyData_Read(DataSourceRequest request)
{
SqlCommand command = new SqlCommand();
string whereClause = FiltersToParameterizedQuery(request.Filters, command: command);
...
... compute order clause
... compute paging clause
string pageQuery = "select * from MY_UNMODELED_DATABASE_OBJECT" + " " + whereClause + orderClause + pageClause;
string countQuery = "select count(1) from MY_UNMODELED_DATABASE_OBJECT" + " " + whereClause;
...
FiltersToParameterizedQuery
private string FiltersToParameterizedQuery(IList<IFilterDescriptor> filters, FilterCompositionLogicalOperator compositionOperator = FilterCompositionLogicalOperator.And, SqlCommand command = null)
{
// See https://www.telerik.com/forums/how-to-access-datasourcerequest-filters-in-controller-
if (!filters.Any()) return "";
string result = "(";
string combineWith = "";
foreach (var filter in filters)
{
if (filter is FilterDescriptor fd)
{
result +=
combineWith + "("
+ DescriptorToSqlServerQuery(fd, command)
+ ")"
;
}
else if (filter is CompositeFilterDescriptor cfd)
{
result +=
combineWith + "("
+ FiltersToParameterizedQuery(cfd.FilterDescriptors, cfd.LogicalOperator, command)
+ ")"
;
}
combineWith =
(compositionOperator == FilterCompositionLogicalOperator.And)
? " and "
: " or "
;
}
result += ")";
return result;
}
and lastly
DescriptorToSqlServerQuery
private string DescriptorToSqlServerQuery (FilterDescriptor fd, SqlCommand command)
{
string parameterName = "@PARAMETER" + command.Parameters.Count;
string result;
// Some string filter values are modified for use as parameters in a SQL LIKE clause, thus work with a copy.
// The original value must remain unchanged for when ToDataSourceResult(request) is used later.
Object filterValue = fd.Value;
switch (fd.Operator)
{
case FilterOperator.IsLessThan: result = "[" + fd.Member + "]" + " < " + parameterName; break;
case FilterOperator.IsLessThanOrEqualTo: result = "[" + fd.Member + "]" + " <= " + parameterName; break;
case FilterOperator.IsEqualTo: result = "[" + fd.Member + "]" + " = " + parameterName; break;
case FilterOperator.IsNotEqualTo: result = "[" + fd.Member + "]" + " <> " + parameterName; break;
case FilterOperator.IsGreaterThanOrEqualTo: result = "[" + fd.Member + "]" + " >= " + parameterName; break;
case FilterOperator.IsGreaterThan: result = "[" + fd.Member + "]" + " > " + parameterName; break;
case FilterOperator.StartsWith:
filterValue = fd.Value.ToString().ToSqlSafeLikeData() + "%";
result = "[" + fd.Member + "]" + " like " + parameterName; break;
case FilterOperator.EndsWith:
filterValue = "%" + fd.Value.ToString().ToSqlSafeLikeData();
result = "[" + fd.Member + "]" + " like " + parameterName; break;
case FilterOperator.Contains:
filterValue = "%" + fd.Value.ToString().ToSqlSafeLikeData() + "%";
result= "[" + fd.Member + "]" + " like " + parameterName; break;
case FilterOperator.IsContainedIn:
throw new Exception("There is no translator for [" + fd.Member + "]" + " " + fd.Operator + " " + fd.Value);
case FilterOperator.DoesNotContain:
filterValue = "%" + fd.Value.ToString().ToSqlSafeLikeData();
result = "[" + fd.Member + "]" + " not like " + parameterName; break;
case FilterOperator.IsNull: result = "[" + fd.Member + "]" + " IS NULL"; break;
case FilterOperator.IsNotNull: result = "[" + fd.Member + "]" + " IS NOT NULL"; break;
case FilterOperator.IsEmpty: result = "[" + fd.Member + "]" + " = ''"; break;
case FilterOperator.IsNotEmpty: result = "[" + fd.Member + "]" + " <> ''"; break;
default:
throw new Exception("There is no translator for [" + fd.Member + "]" + " " + fd.Operator + " " + fd.Value);
}
command.Parameters.Add(new SqlParameter(parameterName, filterValue));
return result;
}