<?php
include_once("include/db_connection.php");
header("Expires: Thu, 17 May 2001 10:17:17 GMT"); // Date in the past
header ("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT"); // always modified
header ("Cache-Control: no-cache, must-revalidate"); // HTTP/1.1
header ("Pragma: no-cache"); // HTTP/1.0
session_start();
if($_SESSION["loggedIn"] == FALSE){
header("Location:user_login.php");
exit;
}
include_once("config.php");
$EventName=$_POST['EventName'];
$UserName=$_SESSION['UserName'];
include('header1.php');
$query1=mysql_fetch_array(mysql_query("select UserName FROM users WHERE Type='1' AND UserName='$UserName'" ));
if($UserName==$query1['UserName'] ){
echo $UserName;
include('left_user.php');}
else{
include('left_coord.php');
}
function checkRights($UserName, $module, $EventName)
{
$query1 = "SELECT $module FROM rights where UserName='$UserName' AND EventName='$EventName' ";
$result1=mysql_query($query1);
$row=mysql_fetch_array($result1);
if($row[0]==1)
{
return true;
}
else
return false;
}
if(checkRights($UserName, "Sponsorships", $EventName))
{
?>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>Premium Series by Free CSS Templates</title>
<meta name="keywords" content="" />
<meta name="Premium Series" content="" />
<link href="default.css" rel="stylesheet" type="text/css" media="screen" />
<script language="JavaScript" src="gen_validatorv31.js" type="text/javascript"></script>
<title>Untitled Document</title>
</head>
<body>
<div id="wrapper">
<!-- start page -->
<div id="page">
<!-- start content -->
<div id="prtCnt" align="center">
<div id="content" align="center">
<div class="post">
<h2 class="title"> </h2>
<div class="entry">
<?php $UserName = $_SESSION['UserName'];
$CompanyName=$_POST[CompanyName];
$CompanyAddress=$_POST[CompanyAddress];
$CompanyPhoneNo=$_POST[CompanyPhoneNo];
$Name=$_POST[Name];
$CompanyPost=$_POST[CompanyPost];
$Method=$_POST[Method];
$Date=$_POST[Date];
$Time=$_POST[Time];
//$Date=date("d/m/y h:i:s");
$sql2="INSERT INTO sponsorships(UserName, CompanyName, CompanyAddress, CompanyPhoneNo, Name, CompanyPost,Method,Date,Time, EventName )VALUES('$UserName', '$CompanyName', '$CompanyAddress', '$CompanyPhoneNo', '$Name', '$CompanyPost','$Method','$Date','$Time','$EventName')";
$result2 = mysql_query($sql2) or die("Invalid query: " . mysql_error() . "<br><br>". $sqlQuery);
?>
<script type="text/javascript">
<!--
window.location = "associate_viewSponsorItem.php"
//-->
</script>
</p>
</div>
</div>
</div>
</div>
<!-- end content -->
<!-- start sidebars -->
<!-- end sidebars -->
<div style="clear: both;"> </div>
</div>
<!-- end page -->
</div>
</html>
<?php
include('footer.php');}
else {
$error="Sorry ! You are not authorised to do Accounting in $EventName ";
?>
<script type="text/javascript">
<!--
window.location = "error.php";
//-->
</script>
<?php }
?>