X-Git-Url: https://git.mxchange.org/?p=mailer.git;a=blobdiff_plain;f=inc%2Fmodules%2Fadmin%2Fwhat-payments.php;h=d3a8c4f4b8261bfd1ff2382881f58b2ee8c7192c;hp=f744849d10830b516952b668564b6188b870918c;hb=95b85ceebca7c97bdd966b1cc94234adfd1abd52;hpb=56156f6c4392510cdbe0eb4f2ccefc23b43e2672 diff --git a/inc/modules/admin/what-payments.php b/inc/modules/admin/what-payments.php index f744849d10..d3a8c4f4b8 100644 --- a/inc/modules/admin/what-payments.php +++ b/inc/modules/admin/what-payments.php @@ -40,56 +40,55 @@ if ((!defined('__SECURITY')) || (!IS_ADMIN())) { // Add description as navigation point ADD_DESCR("admin", __FILE__); -if (empty($_GET['do'])) unset($_GET['do']); - -if (((empty($_POST['t_wait'])) || (empty($_POST['payment']))) && (!empty($_GET['do'])) && ($_GET['do'] == "add")) { - unset($_POST['ok']); +if (((!REQUEST_ISSET_POST(('t_wait'))) || (!REQUEST_ISSET_POST(('payment')))) && (REQUEST_ISSET_GET(('do'))) && (REQUEST_GET('do') == "add")) { + REQUEST_UNSET_POST('ok'); } -if (isset($_POST['ok'])) { - $SQL = array(); - switch ($_GET['do']) { +if (IS_FORM_SENT()) { + switch (REQUEST_GET('do')) { case "add": - $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_payments (time, payment, mail_title, price) VALUES ('".$_POST['t_wait']."','".$_POST['payment']."','".$_POST['title']."','".$_POST['price']."')"; - $result = SQL_QUERY_ESC("SELECT id FROM "._MYSQL_PREFIX."_payments WHERE time='%s' LIMIT 1", - array($_POST['t_wait']), __FILE__, __LINE__); + ADD_SQL("INSERT INTO `{!_MYSQL_PREFIX!}_payments` (time, payment, mail_title, price) VALUES ('".REQUEST_POST('t_wait')."','".REQUEST_POST('payment')."','".REQUEST_POST('title')."','".REQUEST_POST('price')."')"); + $result = SQL_QUERY_ESC("SELECT id FROM `{!_MYSQL_PREFIX!}_payments` WHERE time='%s' LIMIT 1", + array(REQUEST_POST('t_wait')), __FILE__, __LINE__); if (SQL_NUMROWS($result) == 1) { + // Re-init the array here + INIT_SQLS(); + // Free memory - $SQLs[0] = ""; SQL_FREERESULT($result); } break; case "edit": - foreach ($_POST['time'] as $id => $value) { - $SQLs[] = "UPDATE "._MYSQL_PREFIX."_payments SET time='".$value."', payment='".$_POST['pay'][$id]."', price='".$_POST['price'][$id]."', mail_title='".$_POST['title'][$id]."' WHERE id='".$id."' LIMIT 1"; + foreach (REQUEST_POST('time') as $id => $value) { + ADD_SQL("UPDATE `{!_MYSQL_PREFIX!}_payments` SET time='".$value."', payment='".REQUEST_POST('pay', $id)."', price='".REQUEST_POST('price', $id)."', mail_title='".REQUEST_POST('title', $id)."' WHERE id='".$id."' LIMIT 1"); } break; case "del": - foreach ($_POST['id'] as $id => $value) { - $SQLs[] = "DELETE LOW_PRIORITY FROM "._MYSQL_PREFIX."_payments WHERE id='".$id."' LIMIT 1"; + foreach (REQUEST_POST('id') as $id => $value) { + ADD_SQL("DELETE LOW_PRIORITY FROM `{!_MYSQL_PREFIX!}_payments` WHERE id='".$id."' LIMIT 1"); } break; } // Save settings - if (count($SQLs) > 0) { + if (COUNT_SQLS() > 0) { // Run all queries - RUN_FILTER('run_sqls', array('dry_run' => false, 'sqls' => $SQLs)); + RUN_FILTER('run_sqls', array('dry_run' => false)); $content = "".SETTINGS_SAVED.""; } else { // Nothing has changed! - $content = "".SETTINGS_NOT_SAVED.""; + $content = "{--SETTINGS_NOT_SAVED--}"; } // Output template LOAD_TEMPLATE("admin_settings_saved", false, $content); -} elseif ((isset($_POST['del'])) && (SELECTION_COUNT($_POST['sel']) > 0)) { +} elseif ((REQUEST_ISSET_POST(('del'))) && (SELECTION_COUNT(REQUEST_POST('sel')) > 0)) { // Delete entries here $SW = 2; $OUT = ""; - foreach ($_POST['sel'] as $id => $value) { - $result = SQL_QUERY_ESC("SELECT time, mail_title FROM "._MYSQL_PREFIX."_payments WHERE id=%s LIMIT 1", + foreach (REQUEST_POST('sel') as $id => $value) { + $result = SQL_QUERY_ESC("SELECT time, mail_title FROM `{!_MYSQL_PREFIX!}_payments` WHERE id=%s LIMIT 1", array(bigintval($id)), __FILE__, __LINE__); list($time, $title) = SQL_FETCHROW($result); SQL_FREERESULT($result); @@ -110,11 +109,11 @@ if (isset($_POST['ok'])) { // Load main template LOAD_TEMPLATE("admin_del_payments"); -} elseif ((isset($_POST['edit'])) && (SELECTION_COUNT($_POST['sel']) > 0)) { +} elseif ((REQUEST_ISSET_POST(('edit'))) && (SELECTION_COUNT(REQUEST_POST('sel')) > 0)) { // Edit entries $SW = 2; $OUT = ""; - foreach ($_POST['sel'] as $id => $value) { - $result = SQL_QUERY_ESC("SELECT time, payment, mail_title, price FROM "._MYSQL_PREFIX."_payments WHERE id=%s LIMIT 1", + foreach (REQUEST_POST('sel') as $id => $value) { + $result = SQL_QUERY_ESC("SELECT time, payment, mail_title, price FROM `{!_MYSQL_PREFIX!}_payments` WHERE id=%s LIMIT 1", array(bigintval($id)), __FILE__, __LINE__); list($time, $pay, $title, $price) = SQL_FETCHROW($result); SQL_FREERESULT($result); @@ -139,7 +138,7 @@ if (isset($_POST['ok'])) { LOAD_TEMPLATE("admin_edit_payments"); } else { // Referal levels - $result = SQL_QUERY("SELECT id, time, payment, mail_title, price FROM "._MYSQL_PREFIX."_payments ORDER BY time", __FILE__, __LINE__); + $result = SQL_QUERY("SELECT id, time, payment, mail_title, price FROM `{!_MYSQL_PREFIX!}_payments` ORDER BY time", __FILE__, __LINE__); if (SQL_NUMROWS($result) > 0) { // Make referal levels editable and deletable $SW = 2; $OUT = "";