basic-php-08-commit-rev02.php / php
<?php // COMMIT ADD AND EDITS link = mysql_connect("localhost", "bp5am", "bp5ampass") or die("Could not connect: " . mysql_error()); mysql_select_db('moviesite', _GET['action']) { case "edit": switch (sql = "UPDATE people SET " . "people_fullname = '" . _GET['id'] . "'"; break; case "movie": _POST['movie_rating']); if (!is_numeric(error .= "Please+enter+a+numeric+rating+%21%0D%0A"; } else { if (movie_rating > 10) { _POST['movie_release'] , error .= "Please+enter+a+date+" . "with+the+dd-mm-yyyy+format%21%0D%0A"; } else { reldatepart['2'], reldatepart['3']); if (error .= "Please+enter+a+real+date+" . "with+the+dd-mm-yyyy+format%21%0D%0A"; } } _POST['movie_name']); if (empty(error .= "Please+enter+a+movie+name%21%0D%0A"; } if (empty(error .= "Please+select+a+movie+type%21%0D%0A"; } if (empty(error .= "Please+select+a+movie+year%21%0D%0A"; } if (empty(sql = "UPDATE movie SET " . "movie_name = '" . _POST['movie_year'] . "'," . "movie_release = '_POST['movie_type'] . "'," . "movie_leadactor = '" . _POST['movie_director'] . "'," . "movie_rating = '_GET['id'] . "'"; } else { header("location:movie.php?action=edit&error=" . _GET['id']); } break; } break; case "add": switch (sql = "INSERT INTO people (people_fullname) " . "VALUES ('" . movie_rating = trim(movie_rating)) { movie_rating < 0 || error .= "Please+enter+a+rating+" . "between+0+and+10%21%0D%0A"; } } _POST['movie_release']); if (!ereg("([0-9]{2})-([0-9]{2})-([0-9]{4})", reldatepart) || empty(error .= "Please+enter+a+date+" . "with+the+dd-mm-yyyy+format%21%0D%0A"; } else { reldatepart['2'], reldatepart['3']); if (error .= "Please+enter+a+real+date+" . "with+the+dd-mm-yyyy+format%21%0D%0A"; } } row['movie_name']); if (empty(error .= "Please+enter+a+movie+name%21%0D%0A"; } if (empty(error .= "Please+select+a+movie+type%21%0D%0A"; } if (empty(error .= "Please+select+a+movie+year%21%0D%0A"; } if (empty(sql = "INSERT INTO movie (movie_name,movie_year," . "movie_release,movie_type,movie_leadactor," . "movie_director,movie_rating) " . "VALUES ('" . _POST['movie_year'] . "'," . "'_POST['movie_type'] . "'," . "'" . _POST['movie_director'] . "'," . "'error); } break; } break; } if (isset(sql)) { echo "<!--".result = mysql_query(<p align="center" style="color:#FF0000"> Done. <a href=<index.php>>Index</a> </p> <?php } ?>
(C) Æliens 20/2/2008
You may not copy or print any of this material without explicit permission of the author or the publisher. In case of other copyright issues, contact the author.