<?php
require("sesionchk.php");
if(! isset($_SESSION['sectors'])){
session_start();
include 'library/config.php';
// $dbConf = new AAConf();
$databaseURL =$dbhost;// 'localhost';//$dbConf->get_databaseURL();
$databaseUName = $dbuser;//'root';//$dbConf->get_databaseUName();
$databasePWord = $dbpass;//'';//$dbConf->get_databasePWord();
$databaseName = $dbname;// 'addrnew';//$dbConf->get_databaseName();
//Set DB Info. in-session
/* $_SESSION['databaseURL']=$databaseURL;
$_SESSION['databaseUName']=$databaseUName;
$_SESSION['databasePWord']=$databasePWord;
$_SESSION['databaseName']=$databaseName;
*/
if (trim($_POST[fullname])=="" and trim($_POST[company])=="")
{
require("links.php");
echo "<center> Enter Name or Company.. <br>";
echo "<a href='wabraaddressbook.php?ID=-1'>Go Back..</a></center>";
}
else
{
$connection = mysql_connect($databaseURL,$databaseUName,$databasePWord);
if (!$connection)
{
die('Could not connect: ' . mysql_error());
}
// or die ("Error while connecting to localhost");
$db = mysql_select_db($databaseName,$connection);
//or die ("Error while connecting to database");
if (trim($_POST[fullname])=="")
{
$_POST[fullname]=trim($_POST[company]);
}
// $sql="INSERT INTO tblautopsy (`Species`,`Reference Number`,`Stocklist No`,`AutopsyDate`,`Autopsy Report`,`Final Conclusion`) VALUES ('$_POST[stklstno]','$_POST[refno]','$_POST[stklstno]','$_POST[adate]','$_POST[areport]','$_POST[fconclusion]')";
if (trim($_POST[webpageaddress])=="" or trim($_POST[webpageaddress])=="http://www.")
{
$wbpage="";
}
else
{
$wbpage=trim($_POST[webpageaddress]);
}
/*
$wbpage=mysql_real_escape_string($wbpage);
$_POST[fullname]=mysql_real_escape_string($_POST[fullname]);
$_POST[title]=mysql_real_escape_string($_POST[title]);
$_POST[jobtitle]=mysql_real_escape_string($_POST[jobtitle]);
$_POST[company]=mysql_real_escape_string($_POST[company]);
$_POST[phbusiness]=mysql_real_escape_string($_POST[phbusiness]);
$_POST[phhome]=mysql_real_escape_string($_POST[phhome]);
$_POST[phbusinessfax]=mysql_real_escape_string($_POST[phbusinessfax]);
$_POST[phmobile]=mysql_real_escape_string($_POST[phmobile]);
$_POST[addrbusiness]=mysql_real_escape_string($_POST[addrbusiness]);
$_POST[addrhome]=mysql_real_escape_string($_POST[addrhome]);
$_POST[addrother]=mysql_real_escape_string($_POST[addrother]);
$_POST[txtemail]=mysql_real_escape_string($_POST[txtemail]);
$_POST[notes]=mysql_real_escape_string($_POST[notes]);
$_POST[Categories]=mysql_real_escape_string($_POST[Categories]);
*/
if ($_POST[addrid]==0)
{
//$sql="insert into contacts (`FirstName`,`EmailAddress`,`Notes`) VALUES ('". $_POST[fullname]."','".$_POST[txtemail]."','".$_POST[notes]."')";
/*
$sql="insert into contacts (`FirstName`,`JobTitle`,`Company`,`BusinessPhone`,`HomePhone`, `BusinessFax`,`MobilePhone`,`BusinessStreet`,`HomeStreet`,`OtherStreet`,`EmailAddress`,`WebPage`,`Notes`) VALUES ('". $_POST[fullname]."','".$_POST[txtemail]."','".$_POST[notes]."')";
*/
$sql="insert into contacts (`Title`,`FirstName`,`JobTitle`,`Company`,`BusinessPhone`,`HomePhone`, `BusinessFax`,`MobilePhone`,`BusinessStreet`,`HomeStreet`,`OtherStreet`,`EmailAddress`,`WebPage`,`Notes`,`Categories`,`user_id`,`user_id2`,`addedon`,`updatedon`) VALUES ('". $_POST[title]."','". $_POST[fullname]."','".$_POST[jobtitle]."','".$_POST[company]."','".$_POST[phbusiness]."','".$_POST[phhome]."','".$_POST[phbusinessfax]."','".$_POST[phmobile]."','".$_POST[addrbusiness]."','".$_POST[addrhome]."','".$_POST[addrother]."','".$_POST[txtemail]."','".$wbpage."','".$_POST[notes]."','".$_POST[Categories]."',".$_SESSION['usr_id'].",".$_SESSION['usr_id'].",'".date("j/n/Y")."','".date("j/n/Y")."')";
}
else
{
//$sql="UPDATE contacts SET `FirstName`='". $_POST[fullname]."',`EmailAddress`='". $_POST[txtemail]."',`Notes`='". $_POST[notes]."' WHERE id=".$_POST[addrid];
$sql="UPDATE contacts SET `Title`='". $_POST[title]."',`FirstName`='". $_POST[fullname]."',`JobTitle`='". $_POST[jobtitle]."',`Company`='". $_POST[company]."',`BusinessPhone`='". $_POST[phbusiness]."',`HomePhone`='". $_POST[phhome]."', `BusinessFax`='". $_POST[phbusinessfax]."',`MobilePhone`='". $_POST[phmobile]."',`BusinessStreet`='". $_POST[addrbusiness]."',`HomeStreet`='". $_POST[addrhome]."',`OtherStreet`='". $_POST[addrother]."',`EmailAddress`='". $_POST[txtemail]."',`WebPage`='". $wbpage."',`EmailAddress`='". $_POST[txtemail]."',`Notes`='". $_POST[notes]."',`Categories`='". $_POST[Categories]."',`user_id2`=".$_SESSION['usr_id'].",`updatedon`='".date("j-n-Y")."' WHERE id=".$_POST[addrid];
}
if ($_POST[addrid]!==0)
{
$imgquery = "SELECT `imagename` FROM `tblimages` WHERE id =" .$_POST[addrid];
mysql_query("SET NAMES 'utf8'");
mysql_query('SET CHARACTER SET utf8');
$imgresult = mysql_query($imgquery);
//$row = mysql_fetch_array($imgresult, MYSQL_ASSOC);
if (mysql_num_rows($imgresult)>0)
{
while($imgrow = mysql_fetch_array($imgresult))
{
if (trim($imgrow)!=="")
{
$imgrowtmp=str_replace('.','',$imgrow['imagename']);
/*
echo $_REQUEST[$imgrow['imagename']];
//$imgrow['imagename']="578_1qwJPG";
echo "<br> >>> ".$_REQUEST[$imgrow['imagename']]."<br>";
*/
$imgrowtmp=str_replace('.','',$imgrow['imagename']);
$imgrecquery =" UPDATE `tblimages` SET `imagedesc` = '".$_REQUEST[$imgrowtmp]."' WHERE id =".$_POST[addrid]." AND imagename = '".$imgrow['imagename']."' ";
/* $imgrecquery = "update `tblimages` set `imagedesc`='".$_REQUEST[$imgrowtmp]."' WHERE id =" .$_POST[addrid]." and imagename='".$imgrow['imagename']."'";*/
mysql_query("SET NAMES 'utf8'");
mysql_query('SET CHARACTER SET utf8');
mysql_query($imgrecquery);
}
}
}
}
mysql_query("SET NAMES 'utf8'");
mysql_query('SET CHARACTER SET utf8');
if (!mysql_query($sql,$connection))
{
die('Error: ' . mysql_error());
}
//echo "1 record added";
//echo "<br>".$_GET['a']."<br>";
if ($_GET['a']=='0')
{
if ($_POST[addrid]==0)
{
$IDD=mysql_insert_id();
}
else
{
$IDD=$_POST[addrid];
}
mysql_close($connection);
/*
echo "<br>IDD = ".$IDD."wen a=".$_GET['a']."<br>";
echo "1 record added don wen get is 0";*/
header('Location: ./uploader/upload.form.php?ID='.$IDD.'&a='.$_GET['adb']);
}
else if ($_GET['a']=='2')
{
if ($_POST[addrid]==0)
{
$IDD=mysql_insert_id();
}
else
{
$IDD=$_POST[addrid];
}
mysql_close($connection);
/*
echo "<br>IDD = ".$IDD."wen a=".$_GET['a']."<br>";
echo "1 record added don wen get is 0";*/
header('Location: ./dtaildwabraaddressbook.php?ID='.$IDD);
}
else
{
if ($_POST[addrid]==0)
{
$IDD=mysql_insert_id();
}
else
{
$IDD=$_POST[addrid];
}
mysql_close($connection);
// echo "1 record added don wen get is 1";
//echo "b4location";
header('Location: ./wabraaddressbook.php?ID='.$IDD);
//echo "aftrlocation";
// header('Location: alphapaging.php?type=sort&value=A');
}
//exit;
}
}
?>