location.href='http://www.take-away.com.au/index.html';"); } else { $sock = msqlConnect(); if ($sock < 0) { fatal("Error : $ERRMSG\n"); } if (msqlSelectDB($sock,"take-away") < 0) { fatal("Error : $ERRMSG\n"); } $query = sub($QUERY_STRING, "%20"," "); $query = sub($query, "%22","\""); $query = sub($query, "_"," "); $query = sub($query, "=",";"); $query_array = split($query, "&"); $no_of_fields = #$query_array; $action = $query_array[0]; if($action == "create" || $action == "update" || $action == "delete") { /* echo("0= $query_array[0]
"); echo("1= $query_array[1]
"); echo("2= $query_array[2]
"); echo("3= $query_array[3]
"); echo("4= $query_array[4]
"); echo("5= $query_array[5]
"); echo("6= $query_array[6]
"); echo("7= $query_array[7]
"); echo("8= $query_array[8]
"); echo("9= $query_array[9]
"); echo("10= $query_array[10]
"); echo("11= $query_array[11]
"); echo("12= $query_array[12]
");*/ if($action == "update") { $password = $query_array[2]; $record_no = $query_array[3]; $account_no = $query_array[5]; $category_name = $query_array[7]; $item_name = $query_array[8]; $item_description = $query_array[9]; $item_price = (money)$query_array[10]; $date_created = $query_array[11]; $date_changed = $query_array[12]; $db_query = "update take_away_inventory set category_name = '$category_name', item_name = '$item_name', item_description = '$item_description', item_price = $item_price, date_created = '$date_created', date_changed = '$date_changed' where account_no = $account_no and record_no = $record_no"; } if($action == "create") { $query = "select _seq from take_away_inventory"; if (msqlQuery($sock, $query) < 0) { fatal("Error : $ERRMSG\n"); } $res = msqlStoreResult(); $row = msqlFetchRow($res); $record_no = (int)$row[0]; msqlFreeResult($res); $password = $query_array[2]; $item_no = $query_array[4]; $account_no = $query_array[1]; $business_name = $query_array[6]; if($business_name == "") { /* echo("BUSINESS NAME EMPTY $account_no $password"); */ $query = "select business_name from take_away_account where account_no = $account_no and password clike '$password'"; /* $query = "select business_name from take_away_inventory where account_no = $account_no";*/ if (msqlQuery($sock, $query) < 0) { fatal("Error : $ERRMSG\n"); } $res = msqlStoreResult(); $row = msqlFetchRow($res); $business_name = $row[0]; msqlFreeResult($res); } $category_name = $query_array[7]; $item_name = $query_array[8]; $item_description = $query_array[9]; $item_price = (money)$query_array[10]; $date_created = $query_array[11]; $date_changed = $query_array[12]; $db_query = "insert into take_away_inventory values ($record_no, $item_no, $account_no, '$business_name', '$category_name', '$item_name', '$item_description', $item_price, '$date_created', '$date_changed')"; } if($action == "delete") { $account_no = $query_array[1]; $record_no = $query_array[2]; $item_no = $query_array[3]; $password = $query_array[4]; $db_query = "delete from take_away_inventory where account_no = $account_no and record_no = $record_no and item_no = $item_no"; } /* echo("

$db_query

"); exit(0);*/ if(msqlQuery($sock, $db_query ) < 0) { fatal("Error: $ERRMSG\n"); } echo(""); } else { $account_no = $query_array[1]; $password = $query_array[2]; $query="select account_no, password from take_away_account where account_no = $account_no and password clike '$password'"; if(msqlQuery($sock, $query ) < 0) { fatal("Error: $ERRMSG\n"); } $res = msqlStoreResult(); if (msqlNumRows($res) <> 1) { echo("

You do not have access to this page

"); sleep(12); echo(""); } else { if ($action == "entry") { $row = msqlFetchRow($res); $account_no = $row[0]; $password = $row[1]; msqlFreeResult($res); $query="select * from take_away_inventory where account_no = $account_no order by category_name, item_no"; if(msqlQuery($sock, $query ) < 0) { fatal("Error: $ERRMSG\n"); } $res = msqlStoreResult(); $counter = 0; $row = msqlFetchRow($res); echo("$row[3]"); echo(" Change an item or add an item (on the bottom line) and click the button next to it to submit. Separate ingredients in the description with a semicolon ';' only.
Illegal characters cannot by typed and will not show. To delete an entry hold the 'Ctrl' key down when you click the button next to the item.
Category Name, Item Name and Price are always required. Description is optional. You can only modify or add only the one line at a time.
"); echo(""); echo(""); while (#$row > 0) { $record_no = $row[0]; $item_no = $row[1]; $account_no = $row[2]; $business_name = $row[3]; $category_name = $row[4]; $item_name = $row[5]; $item_description = $row[6]; $item_price = $row[7]; $date_created = $row[8]; $date_changed = $row[9]; echo(""); $row = msqlFetchRow($res); $counter++; } $line_no = $counter + 1; echo(""); echo(""); echo("
RIABCategory NameItem NameDescriptionPriceDD*
"); } } msqlFreeResult($res); msqlClose($sock); } } >