| Server IP : 210.245.233.93 / Your IP : 216.73.216.226 Web Server : Apache/2.2.15 (CentOS) System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64 User : apache ( 48) PHP Version : 5.3.3 Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /var/www/onesupportsys.onesolution.hk/project/ |
Upload File : |
<?php
require_once(__DIR__ . '/../checkuser.php');
session_start();
//-----------------------------------------------------------------------------
// Check permission
//-----------------------------------------------------------------------------
//if (!Util::isAdmin()) {
// redirectAndExit('index.php?message=No permission!');
//}
//-----------------------------------------------------------------------------
// Save if POST method
//-----------------------------------------------------------------------------
if (isPost()) {
$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
$parameters = array('sup_project');
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$columns = $sth->fetchAll();
foreach ($columns as $column) {
$column = $column['column_name'];
if (isset($_POST[$column])) {
$project[$column] = $_POST[$column];
}
}
$now = date("Y-m-d H:i:s");
$project = array_merge($project, array(
'status' => 1,
'deleted' => 0,
'createdate' => $now,
'createby' => $_SESSION['webadmin']['id'],
'lastupdate' => $now,
'lastupby' => $_SESSION['webadmin']['id'],
));
// Create project
$columns = array();
$values = array();
$parameters = array();
foreach ($project as $column => $value) {
$columns[] = $column;
$parameters[] = !strlen($value) ? null : $value;
$values[] = '?';
}
$sql = "INSERT sup_project (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$lastinsertid = $dbh->lastInsertId();
$_SESSION["remark_project_id"] = $lastinsertid;
if (!empty($lastinsertid)) {
//header("Location: modifyform.php?id=$lastinsertid&message=New Project Created.");
header("Location: index.php?message=New Project Created.");
}
}