| Server IP : 210.245.233.93 / Your IP : 216.73.216.226 Web Server : Apache/2.2.15 (CentOS) System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64 User : apache ( 48) PHP Version : 5.3.3 Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /var/www/onesupportsys.onesolution.hk/profile/ |
Upload File : |
<?php
global $dbh;
require_once('../inc/configure.php');
//Ajax Function
if(!empty($_POST["actionCode"])){
//Get a saved record from customerProfileOtherInfo
if ( $_POST["actionCode"] == "R" ) {
$sql = "select * from customerProfileOtherInfo where profile_id = ?";
$result = tableInfo::recordData($sql, $_POST["profileId"]);
echo json_encode($result);
exit;
}
//Save new record
if ( $_POST["actionCode"] == "S" ) {
$result = tableInfo::getColumns("customerProfileOtherInfo");
foreach ($result as $column) {
$column = $column['column_name'];
if (isset($_POST[$column])) {
$temp[$column] = $_POST[$column];
}
}
$columns = array();
$values = array();
$parameters = array();
if ( $_POST["id"] == '0' ) {
foreach ($temp as $column => $value) {
$columns[] = $column;
$parameters[] = !strlen($value) ? null : $value;
$values[] = '?';
}
$sql = "INSERT customerProfileOtherInfo (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";
} else {
if ($_POST['profile_delete'] == "Y") {
$sql = "delete from customerProfileOtherInfo WHERE id = ?";
} else {
foreach ($temp as $column => $value) {
if ($column != 'id' && $column != 'profile_id') {
switch ($column) {
case 'loginpw': {
if (!empty($value)) {
$parameters[] = md5($value);
$values[] = "`$column` = ?";
}
break;
}
default: {
$parameters[] = !strlen($value) ? null : $value;
$values[] = "`$column` = ?";
break;
}
}
}
}
$sql = "UPDATE customerProfileOtherInfo SET " . implode(', ', $values) . " WHERE id = ?";
}
$parameters[] = $_POST["id"];
}
$result = tableInfo::updateRecord($sql, $parameters);
$outValue = $result;
echo $outValue;
exit;
}
}
//-----------------------------------------------------------------------------
// Check permission
//-----------------------------------------------------------------------------
if (!Util::isAdmin()) {
redirectAndExit('index.php?message=No permission!');
}
//-----------------------------------------------------------------------------
// Find job by id
//-----------------------------------------------------------------------------
$sql = "SELECT * FROM customerProfile WHERE customer_id = ?";
$parameters = array($id);
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$customer = $sth->fetch(PDO::FETCH_ASSOC);
//Profile not yet created
if ( is_null($customer['customer_id']) ) {
$customer['id'] = "0";
$customer['customer_id'] = $_GET["id"];
}
//return array(
// 'customer' => $customer,
//);
//-----------------------------------------------------------------------------
// Save if POST method
//-----------------------------------------------------------------------------
if (isPost()) {
$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
$parameters = array('customerProfile');
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$columns = $sth->fetchAll();
foreach ($columns as $column) {
$column = $column['column_name'];
if (isset($_POST[$column])) {
$customer[$column] = $_POST[$column];
}
}
// Append record time
$now = date("Y-m-d H:i:s");
if ( $customer['id'] <> '0' ) {
$customer = array_merge($customer, array(
'updated_at' => $now,
'updated_by' => $_SESSION['webadmin']['id'],
));
// Update customer Profile
$values = array();
$parameters = array();
foreach ($customer as $column => $value) {
if ($column != 'id') {
switch ($column) {
case 'loginpw': {
if (!empty($value)) {
$parameters[] = md5($value);
$values[] = "`$column` = ?";
}
break;
}
default: {
$parameters[] = !strlen($value) ? null : $value;
$values[] = "`$column` = ?";
break;
}
}
}
}
$sql = "UPDATE customerProfile SET " . implode(', ', $values) . " WHERE id = ?";
$parameters[] = $customer['id'];
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
} else {
$customer = array_merge($customer, array(
'created_at' => $now,
'created_by' => $_SESSION['webadmin']['id'],
));
// Create customer
$columns = array();
$values = array();
$parameters = array();
foreach ($customer as $column => $value) {
$columns[] = $column;
$parameters[] = !strlen($value) ? null : $value;
$values[] = '?';
}
$sql = "INSERT customerProfile (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";
//throw new Exception($sql . " S " . implode(', ', $parameters));
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$customer['id'] = $dbh->lastInsertId();
}
redirectAndExit('index.php?message=Saved.');
}
//-----------------------------------------------------------------------------
// Return array parameters
//-----------------------------------------------------------------------------
return array(
'customer' => $customer,
'message' => $_GET['message'],
);