<?php
session_start();
/*
asaancart - easy shopping cart solution
---------------------------------------
Copyright 2009 Nasir Ahmad Khan
Email: hide@address.com
This file is part of asaancart - open source easy shopping cart solution.
asaancart is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
asaancart is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with asaancart. If not, see <http://www.gnu.org/licenses/>.
*/
include("../config/config.php");
include("includes/chk_login_status_inc.php");
$smarty->assign('title','Add New Brand');
$brand_name = $_POST['brand_name'];
$brand_intro = $_POST['brand_intro'];
$brand_logo = $_POST['brand_logo'];
$uploaddir = $_SERVER['DOCUMENT_ROOT'].'/'.APP_ROOT_DIR.'/brand_images/';
if($_POST['btn_create']=="Create")
{
if($brand_name!=""){
//upload logo
if(basename($_FILES['brand_logo']['name'])!=''){
$uploadfile = $uploaddir ."$brand_name"."_".basename($_FILES['brand_logo']['name']);
$image_filename = "$brand_name"."_".basename($_FILES['brand_logo']['name']);
if (move_uploaded_file($_FILES['brand_logo']['tmp_name'], $uploadfile)) {
//echo "File is valid, and was successfully uploaded.\n";
} else {
$smarty->assign('msg_brand','Possible file upload attack!');
}
$uploadfile = "";
} //end if
//inser into product table
$sql = "INSERT INTO brands (brand_name, brand_intro, brand_logo) VALUES ('".$brand_name."', '".str_replace("'","\'",$brand_intro)."','".$image_filename."')";
$results = mysql_query($sql);
$smarty->assign('msg_brand','Done: Added Successfully');
}
else{
$smarty->assign('msg_brand',"<span style='color:red'>Error: Please enter brand name</span>");
}
}
//show brand
$sql = "SELECT * FROM brands ORDER BY brand_name";
$results = mysql_query($sql);
while($row = mysql_fetch_assoc($results) )
{
$all_brands[] = $row;
}
$smarty->assign('all_brands', $all_brands);
$smarty->display('add_brand.tpl');
?>