I saw in many tutorial that compose sql statement by using variable and Parameters.Add likt this
public void updateStudent(String @studentID, String @firstNa
Four reasons:
Also note:
You don't need to use @
as a prefix to your variables unless they're keywords. So it would be more idiomatic to write:
command.Parameters.Add(new SQLiteParameter("@lastName", lastName));
(Ditto for the method parameter declarations to start with... but not the parameters inside the SQL statement.)