<?php
require("sesionchk.php");
if(! isset($_SESSION['sectors'])){
session_start();
// include("conf/conf.php");
// $dbConf = new AAConf();
/* $databaseURL = 'localhost';//$dbConf->get_databaseURL();
$databaseUName = 'root';//$dbConf->get_databaseUName();
$databasePWord = '';//$dbConf->get_databasePWord();
$databaseName = 'addrnew';//$dbConf->get_databaseName();
*/
include 'library/config.php';
// $dbConf = new AAConf();
$databaseURL =$dbhost;// 'localhost';//$dbConf->get_databaseURL();
$databaseUName = $dbuser;//'root';//$dbConf->get_databaseUName();
$databasePWord = $dbpass;//'';//$dbConf->get_databasePWord();
$databaseName = $dbname;// 'addrnew';//$dbConf->get_databaseName();
//Set DB Info. in-session
/* $_SESSION['databaseURL']=$databaseURL;
$_SESSION['databaseUName']=$databaseUName;
$_SESSION['databasePWord']=$databasePWord;
$_SESSION['databaseName']=$databaseName;
*/
$connection = mysql_connect($databaseURL,$databaseUName,$databasePWord);
if (!$connection)
{
die('Could not connect: ' . mysql_error());
}
// or die ("Error while connecting to localhost");
$db = mysql_select_db($databaseName,$connection);
//or die ("Error while connecting to database");
$bday= $_POST[mmonth]."/".$_POST[dday]."/".$_POST[yyear];
if (trim($_POST[fullname])=="")
{
$_POST[fullname]=trim($_POST[company]);
}
if (trim($_POST[webpageaddress])=="" or trim($_POST[webpageaddress])=="http://www.")
{
$wbpage="";
}
else
{
$wbpage=trim($_POST[webpageaddress]);
}
/*$wbpage=mysql_real_escape_string($wbpage);
$_POST[fullname]=mysql_real_escape_string($_POST[fullname]);
$_POST[title]=mysql_real_escape_string($_POST[title]);
$_POST[jobtitle]=mysql_real_escape_string($_POST[jobtitle]);
$_POST[company]=mysql_real_escape_string($_POST[company]);
$_POST[phbusiness]=mysql_real_escape_string($_POST[phbusiness]);
$_POST[phhome]=mysql_real_escape_string($_POST[phhome]);
$_POST[phbusinessfax]=mysql_real_escape_string($_POST[phbusinessfax]);
$_POST[phmobile]=mysql_real_escape_string($_POST[phmobile]);
$_POST[addrbusiness]=mysql_real_escape_string($_POST[addrbusiness]);
$_POST[addrhome]=mysql_real_escape_string($_POST[addrhome]);
$_POST[addrother]=mysql_real_escape_string($_POST[addrother]);
$_POST[txtemail]=mysql_real_escape_string($_POST[txtemail]);
$_POST[notes]=mysql_real_escape_string($_POST[notes]);
$_POST[Categories]=mysql_real_escape_string($_POST[Categories]);
$_POST[dept]=mysql_real_escape_string($_POST[dept]);
$_POST[phbusinessphon2]=mysql_real_escape_string($_POST[phbusinessphon2]);
$_POST[buscntry]=mysql_real_escape_string($_POST[buscntry]);
$_POST[homcntry]=mysql_real_escape_string($_POST[homcntry]);
$_POST[othrcntry]=mysql_real_escape_string($_POST[othrcntry]);
$_POST[CompanyMainPhone]=mysql_real_escape_string($_POST[CompanyMainPhone]);
$_POST[HomePhone2]=mysql_real_escape_string($_POST[HomePhone2]);
$_POST[PrimaryPhone]=mysql_real_escape_string($_POST[PrimaryPhone]);
$_POST[Email3Address]=mysql_real_escape_string($_POST[Email3Address]);
$_POST[Email2Address]=mysql_real_escape_string($_POST[Email2Address]);
$_POST[HomeFax]=mysql_real_escape_string($_POST[HomeFax]);
*/
// $sql="INSERT INTO tblautopsy (`Species`,`Reference Number`,`Stocklist No`,`AutopsyDate`,`Autopsy Report`,`Final Conclusion`) VALUES ('$_POST[stklstno]','$_POST[refno]','$_POST[stklstno]','$_POST[adate]','$_POST[areport]','$_POST[fconclusion]')";
if ($_POST[addrid]==0)
{
//$sql="insert into contacts (`FirstName`,`EmailAddress`,`Notes`) VALUES ('". $_POST[fullname]."','".$_POST[txtemail]."','".$_POST[notes]."')";
/*
$sql="insert into contacts (`FirstName`,`JobTitle`,`Company`,`BusinessPhone`,`HomePhone`, `BusinessFax`,`MobilePhone`,`BusinessStreet`,`HomeStreet`,`OtherStreet`,`EmailAddress`,`WebPage`,`Notes`) VALUES ('". $_POST[fullname]."','".$_POST[txtemail]."','".$_POST[notes]."')";
*/
$sql="insert into contacts (`Title`,`FirstName`,`JobTitle`,`Company`,`BusinessPhone`,`HomePhone`, `BusinessFax`,`MobilePhone`,`BusinessStreet`,`HomeStreet`,`OtherStreet`,`EmailAddress`,`WebPage`,`Notes`,`Department`,`BusinessPhone2`,`BusinessCountry`,`HomeCountry`,`OtherCountry`,`CompanyMainPhone`,`HomePhone2`,`PrimaryPhone`,`Birthday`,`Categories`,`Email3Address`,`Email2Address`,`HomeFax`,`user_id`,`user_id2`,`addedon`,`updatedon`) VALUES ('". $_POST[title]."','". $_POST[fullname]."','".$_POST[jobtitle]."','".$_POST[company]."','".$_POST[phbusiness]."','".$_POST[phhome]."','".$_POST[phbusinessfax]."','".$_POST[phmobile]."','".$_POST[addrbusiness]."','".$_POST[addrhome]."','".$_POST[addrother]."','".$_POST[txtemail]."','".$wbpage."','".$_POST[notes]."','".$_POST[dept]."','".$_POST[phbusinessphon2]."','".$_POST[buscntry]."','".$_POST[homcntry]."','".$_POST[othrcntry]."','".$_POST[CompanyMainPhone]."','".$_POST[HomePhone2]."','".$_POST[PrimaryPhone]."','".$bday."','".$_POST[Categories]."','".$_POST[Email3Address]."','".$_POST[Email2Address]."','".$_POST[HomeFax]."',".$_SESSION['usr_id'].",".$_SESSION['usr_id'].",'".date("j/n/Y")."','".date("j/n/Y")."')";
}
else
{
//$sql="UPDATE contacts SET `FirstName`='". $_POST[fullname]."',`EmailAddress`='". $_POST[txtemail]."',`Notes`='". $_POST[notes]."' WHERE id=".$_POST[addrid];
$sql="UPDATE contacts SET `Title`='". $_POST[title]."',`FirstName`='". $_POST[fullname]."',`JobTitle`='". $_POST[jobtitle]."',`Company`='". $_POST[company]."',`BusinessPhone`='". $_POST[phbusiness]."',`HomePhone`='". $_POST[phhome]."', `BusinessFax`='". $_POST[phbusinessfax]."',`MobilePhone`='". $_POST[phmobile]."',`BusinessStreet`='". $_POST[addrbusiness]."',`HomeStreet`='". $_POST[addrhome]."',`OtherStreet`='". $_POST[addrother]."',`EmailAddress`='". $_POST[txtemail]."',`WebPage`='". $wbpage."',`EmailAddress`='". $_POST[txtemail]."',`Notes`='". $_POST[notes]."',`Department`='". $_POST[dept]."',`BusinessPhone2`='". $_POST[phbusinessphon2]."',`BusinessCountry`='". $_POST[buscntry]."',`HomeCountry`='". $_POST[homcntry]."',`OtherCountry`='". $_POST[othrcntry]."',`CompanyMainPhone`='". $_POST[CompanyMainPhone]."',`HomePhone2`='". $_POST[HomePhone2]."',`PrimaryPhone`='". $_POST[PrimaryPhone]."',`Birthday`='". $bday."',`Categories`='". $_POST[Categories]."',`Email3Address`='". $_POST[Email3Address]."',`Email2Address`='". $_POST[Email2Address]."',`HomeFax`='". $_POST[HomeFax ]."',`user_id2`=".$_SESSION['usr_id'].",`updatedon`='".date("j-n-Y")."' WHERE id=".$_POST[addrid];
}
if ($_POST[addrid]!==0)
{
$imgquery = "SELECT `imagename` FROM `tblimages` WHERE id =" .$_POST[addrid];
mysql_query("SET NAMES 'utf8'");
mysql_query('SET CHARACTER SET utf8');
$imgresult = mysql_query($imgquery);
//$row = mysql_fetch_array($imgresult, MYSQL_ASSOC);
if (mysql_num_rows($imgresult)>0)
{
while($imgrow = mysql_fetch_array($imgresult))
{
if (trim($imgrow)!=="")
{
$imgrowtmp=str_replace('.','',$imgrow['imagename']);
/*
echo $_REQUEST[$imgrow['imagename']];
//$imgrow['imagename']="578_1qwJPG";
echo "<br> >>> ".$_REQUEST[$imgrow['imagename']]."<br>";
*/
$imgrowtmp=str_replace('.','',$imgrow['imagename']);
$imgrecquery =" UPDATE `tblimages` SET `imagedesc` = '".$_REQUEST[$imgrowtmp]."' WHERE id =".$_POST[addrid]." AND imagename = '".$imgrow['imagename']."' ";
/* $imgrecquery = "update `tblimages` set `imagedesc`='".$_REQUEST[$imgrowtmp]."' WHERE id =" .$_POST[addrid]." and imagename='".$imgrow['imagename']."'";*/
mysql_query("SET NAMES 'utf8'");
mysql_query('SET CHARACTER SET utf8');
mysql_query($imgrecquery);
}
}
}
}
mysql_query("SET NAMES 'utf8'");
mysql_query('SET CHARACTER SET utf8');
if (!mysql_query($sql,$connection))
{
die('Error: ' . mysql_error());
}
//echo "1 record added";
//echo "<br>".$_GET['a']."<br>";
if ($_GET['a']=='0')
{
if ($_POST[addrid]==0)
{
$IDD=mysql_insert_id();
}
else
{
$IDD=$_POST[addrid];
}
mysql_close($connection);
/*
echo "<br>IDD = ".$IDD."wen a=".$_GET['a']."<br>";
echo "1 record added don wen get is 0";*/
header('Location: uploader/upload.form.php?ID='.$IDD.'&a='.$_GET['adb']);
}
else if ($_GET['a']=='2')
{
if ($_POST[addrid]==0)
{
$IDD=mysql_insert_id();
}
else
{
$IDD=$_POST[addrid];
}
mysql_close($connection);
/*
echo "<br>IDD = ".$IDD."wen a=".$_GET['a']."<br>";
echo "1 record added don wen get is 0";*/
header('Location: dtaildwabraaddressbook.php?ID='.$IDD);
}
else
{
if ($_POST[addrid]==0)
{
$IDD=mysql_insert_id();
}
else
{
$IDD=$_POST[addrid];
}
mysql_close($connection);
// echo "1 record added don wen get is 1";
//header('Location: alphapaging.php?type=sort&value=A');
header('Location: dtaildwabraaddressbook.php?ID='.$IDD);
}
exit;
}
?>