<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<?
//Copyright David Byrne 2007
//This file is part of eCanteen.
// eCanteen is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
// eCanteen is distributed in the hope that it will be useful
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
// You should have received a copy of the GNU General Public License
// along with eCanteen. If not, see <http://www.gnu.org/licenses/>.
include("../include/constants.php");
include("../include/session.php");
mysql_free_result($res);
//$recid=$_SESSION['CustomerID'];
function connect()
{
$conn = mysql_connect(DB_SERVER, DB_USER, DB_PASS);
mysql_select_db(DB_NAME);
return $conn;
}
//echo count($_POST);
echo "<BR>";
if (count($_POST)>0)
{
$xx=db_update('majorcustomer', 'CustomerID', $_POST["CustomerID"]);
//$recid=$_POST["CustomerID"];
}
////////////////////////////////////////////////////////////
// Function Name: db_update()
// Accepts: varchar table, varchar pk, varchar pkval
// Returns: Success or mysql_error()
//
// Author: Andrew Deering
// Date: 12/10/04
//
// Purpose:
//
// This function takes all of the posted form elements
// and updates $table WHERE $pk = $pkval with new values.
///////////////////////////////////////////////////////////
function db_update($table, $pk, $pkval){
//$query = "UPDATE <table> SET
connect();
$query = "UPDATE ".$table." SET ";
$query =$query."`UserName_L2`='".$_POST["UserName_L2"]."', `FirstName`='".$_POST["FirstName"]."', `LastName`='".$_POST["LastName"]."', `MobileNumber`='".$_POST["MobileNumber"]."',`EmailAddress`='".$_POST["EmailAddress"]."' WHERE `CustomerID`=".$_SESSION['CustomerID'].";";
//$query = "UPDATE <table> SET $fldnm1 = fldnm1, $fldnm2 = fldnm2, ... $fldnmN = fldnmN
//$fldnmN = $fieldnameN //EXPLANATION//
//$trigger = 0;
//foreach($_POST as $field => $value){
//echo $trigger." ".$field." = ".$value."<br><br>";
//if($trigger > 0) $query = $query . ", ";
//$query = $query . $field." = $value";
//$trigger++;
//}
//$query = "UPDATE <table> SET $fldnm1 = fldnm1, $fldnm2 = fldnm2, ... $fldnmN = fldnmN WHERE $pk = $pkval
//$query = $query . " WHERE ".$pk." = ".$pkval;
//IF query runs, return. else, tell me why
//echo $query."<br><br>";
if($result = mysql_query($query)) return(0);
else echo(mysql_error());
//$recid=$_SESSION['CustomerID'];
}
//END db_update
?>
<html>
<head>
<LINK REL="stylesheet" TYPE="text/css" HREF="maintain.css">
<body>
<button id="Return2Cal" onclick="window.location.href='../index.php?site=<?$_SESSION['SiteID']?>>';return true;" style="width: 190px">Return to Main Menu</button><br />
<form action="majorone.php" method="post">
<?
$conn = connect();
$sqlstmt="SELECT m.`CustomerID`, m.`UserName_L2`, m.`FirstName`, m.`LastName`, m.`MobileNumber`,m.`EmailAddress`, m.`Password`, m.`UserLevel_L3`, m.`Credit_L2`, m.`Active_L2`, m.`~SiteID$` FROM majorcustomer m WHERE m.`CustomerID`=".$_SESSION['CustomerID'].";";
$objRecordset1=mysql_query($sqlstmt);
?>
<table class="tbl" border="0" cellspacing="1" cellpadding="5" width="50%">
<tr>
<td class="hr"><? echo htmlspecialchars("Customer ID:")." " ?></td>
<td class="dr"><input type="text" readonly name="CustomerID" value="<? echo mysql_result($objRecordset1,0,"CustomerID") ;?>"></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("UserName")." " ?></td>
<td class="dr"><input type="text" name="UserName_L2" maxlength="20" value="<?echo mysql_result($objRecordset1,0,"UserName_L2") ;?>"></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("First Name")." " ?></td>
<td class="dr"><input type="text" name="FirstName" maxlength="30" value="<? echo str_replace('"', '"', trim(mysql_result($objRecordset1,0,"FirstName"))) ;?>"></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("Last Name")." " ?></td>
<td class="dr"><input type="text" name="LastName" maxlength="30" value="<?echo mysql_result($objRecordset1,0,"LastName");?>"></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("Mobile Number")." " ?></td>
<td class="dr"><input type="text" name="MobileNumber" maxlength="10" value="<? echo str_replace('"', '"', trim(mysql_result($objRecordset1,0,"MobileNumber")));?>"></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("Email Address")." " ?></td>
<td class="dr"><input type="text" name="EmailAddress" maxlength="50" value="<? echo str_replace('"', '"', trim(mysql_result($objRecordset1,0,"EmailAddress"))) ;?>"></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("UserLevel")." " ?></td>
<td class="dr"><? echo mysql_result($objRecordset1,0,"UserLevel_L3");?></td>
</tr>
<tr>
<td class="hr"><? echo htmlspecialchars("Credit")." " ?></td>
<td class="dr"><? echo str_replace('"', '"', trim(mysql_result($objRecordset1,0,"Credit_L2"))) ;?></td>
</tr>
</table>
<p><input type="submit" name="action" value="Post"></p>
</form>
</body>
</html>