/** * função que autentica o USUÁRIO * * @name login * @param string $usuario * @param string $senha * @param string $destino */ function login($usuario, $senha, $destino) { //verifica se o USUÁRIO e a senha constam na tabela echo "Verificando usuário ... "; $sel = sel("usuarios", "usuario = '{$usuario}' and senha = '{$senha}'", "", ""); echo "<b>ok</b><br>"; if (mysql_num_rows($sel) == 0) { //se não existir, mostra a mensagem abaixo echo "<i>Este usuário não existe!</i><br><br>"; echo "<a href=\"javascript:history.go(-1);\">Voltar</a>"; exit; //encerra a execução do arquivo, não permitindo que o USUÁRIO prossiga } else { echo "Gravando sessão ... "; //guarda usuario e senha $_SESSION["login"] = $usuario; $_SESSION["senha"] = $senha; echo "<b>ok</b><br>"; //guarda um valor de sessão único para gravar que o USUÁRIO está logado $_SESSION["idsession"] = date("H") + date("i") + date("s") + date("d") + date("m") + date("Y"); $idsession = $_SESSION["idsession"]; ins("sessoes", "usuario, senha, sessao", "'{$usuario}', '{$senha}', '{$idsession}'"); echo "Redirecionando ... "; echo "<meta http-equiv=\"refresh\" content=\"0;URL={$destino}\">"; echo "<b>ok</b>"; exit; } }
$fecha = $_POST['fecha']; $hora = $_POST['hora']; $observacion = $_POST['des']; $actividad = $_POST['actividad']; $query; $result; $contador = 0; $dato; function ins() { $us = $_POST['us']; $fecha = $_POST['fecha']; $hora = $_POST['hora']; $observacion = $_POST['des']; $actividad = $_POST['actividad']; $qury = "INSERT INTO reser_gym (id_reser_gym , for_cliented, fecha, hora, observaciones,actividad)\n\t\t\t\tVALUES (''," . busqueda($us) . ",'" . $fecha . "','" . $hora . "','" . $observacion . "','" . $actividad . "')"; $s = mysql_query($qury); return $s; } function busqueda($us) { $query = "SELECT fk_id_cliente FROM user_app WHERE usuario = '" . $us . "'"; $result = mysql_query($query); while ($row = mysql_fetch_object($result)) { $fka = $row->fk_id_cliente; return $fka; } } echo json_encode("<h1>" . busqueda($us) . "</h1>"); echo json_encode(ins());
function newNodeRevisionExecute() { if (fv('nodeDataUploadFlag')) { // echo 'Adding data…'; $tablenamenewdata = "data"; $next_incrementdata = 0; $qShowStatusdata = "SHOW TABLE STATUS LIKE '{$tablenamenewdata}'"; $qShowStatusResultdata = mysql_query($qShowStatusdata) or die("Query failed: " . mysql_error() . "<br/>" . $qShowStatusdata); $rowdata = mysql_fetch_assoc($qShowStatusResultdata); $next_incrementdata = $rowdata['Auto_increment']; mysql_query('INSERT INTO `data` (`data_id`, `data_current_revision`) VALUES (NULL, \'' . $next_incrementdata . '\');'); $addedDataId = mysql_insert_id(); // echo 'data number ' . $addedDataId . 'and data revision number '; $fileTempName = $_FILES['uploadeddata']['tmp_name']; mysql_query('INSERT INTO `data_revision` (`data_revision_id`, `data_revision_name`, `data_revision_length`, `data_revision_type`, `data_revision_node_id`, `data_revision_md5`, `data_revision_data_id`, `data_revision_node_edit_id`) VALUES (NULL, \'' . $HTTP_POST_FILES['uploadeddata']['name'] . '\', \'' . $HTTP_POST_FILES['uploadeddata']['size'] . '\', \'' . fv('dataType') . '\', \'nodeid\', \'' . md5_file($fileTempName) . '\', \'' . $addedDataId . '\', \'not yet known\');'); $targetULDirectory = 'weave/data/' . str_replace(0, '0/', str_replace(1, '1/', str_replace(2, '2/', str_replace(3, '3/', str_replace(4, '4/', str_replace(5, '5/', str_replace(6, '6/', str_replace(7, '7/', str_replace(8, '8/', str_replace(9, '9/', mysql_insert_id())))))))))); mkdir($targetULDirectory, 0700, true); /* $ck = mysql_insert_id(); $subdirs = array(); for ($i = 0;$i < strlen($ck);$i++) $subdirs[] = $ck[$i]; */ $addedDataRevisionId = mysql_insert_id(); // echo $addedDataRevisionId; $targetULDirectory = $targetULDirectory . $addedDataRevisionId . '.wdf'; // echo $targetULDirectory; move_uploaded_file($fileTempName, $targetULDirectory); } else { // echo 'not adding data. '; } $tablenamenewnode = "node_revision"; $next_incrementnode = 0; $qShowStatusnode = "SHOW TABLE STATUS LIKE '{$tablenamenewnode}'"; $qShowStatusResultnode = mysql_query($qShowStatusnode) or die("Query failed: " . mysql_error() . "<br/>" . $qShowStatusnode); $rownode = mysql_fetch_assoc($qShowStatusResultnode); $next_incrementnode_revision = $rownode['Auto_increment']; mysql_query('UPDATE `node` SET `node_current_revision` = \'' . $next_incrementnode_revision . '\' WHERE `node_id` =' . fv('nodeId') . ' LIMIT 1 ;'); //INSERT INTO `node` ( `node_id` , `node_current_revision` ) VALUES (' . fv('nodeId') . ', \'' . $next_incrementnode_revision . '\');'); $nodeEditedId = mysql_insert_id(); newintf($_POST['nodeDisplayTitle']); global $newIntfId; $nodeDisplayTitleIntfId = $newIntfId; newintf($_POST['nodeShortTitle']); global $newIntfId; $nodeShortTitleIntfId = $newIntfId; newintf($_POST['nodeTitle']); global $newIntfId; $nodeTitleIntfId = $newIntfId; newintf($_POST['nodeSource']); global $newIntfId; $nodeSourceIntfId = $newIntfId; newintf($_POST['nodeSortTitle']); global $newIntfId; $nodeSortTitleIntfId = $newIntfId; newintf($_POST['nodeDescription']); global $newIntfId; $nodeDescriptionIntfId = $newIntfId; newintf($_POST['nodeDisambiguationDescription']); global $newIntfId; $nodeDisambiguationDescriptionIntfId = $newIntfId; newintf($_POST['nodeComment']); global $newIntfId; $nodeCommentIntfId = $newIntfId; newintf($_POST['nodeShortDescription']); global $newIntfId; $nodeShortDescriptionIntfId = $newIntfId; $newNodeOwnerId = qry('user', 'user_id', 'user_name', mysql_real_escape_string($_POST['userName'])); $newNodeData = array("node_revision_type" => $_POST['nodeType'], "node_revision_display_title" => $nodeDisplayTitleIntfId, "node_revision_short_title" => $nodeShortTitleIntfId, "node_revision_title" => $nodeTitleIntfId, "node_revision_permissions" => $_POST['nodePermissions'], "node_revision_relationships" => $_POST['nodeRelationships'], "node_revision_source" => $nodeSourceIntfId, "node_revision_sort_title" => $nodeSortTitleIntfId, "node_revision_description" => $nodeDescriptionIntfId, "node_revision_disambiguation_description" => $nodeDisambiguationDescriptionIntfId, "node_revision_metadata" => $_POST['nodeMetadata'], "node_revision_comment" => $nodeCommentIntfId, "node_revision_short_description" => $nodeShortDescriptionIntfId, "node_revision_universe_status" => $_POST['nodeUniverseStatus'], "node_revision_owner" => $newNodeOwnerId, "node_revision_copyright_flag" => $_POST['nodeCopyrightFlag'], "node_revision_morality_flag" => $_POST['nodeMoralityFlag'], "node_revision_personal_flag" => $_POST['nodePersonalFlag'], "node_revision_data_id" => $addedDataId, "node_revision_node_id" => fv('nodeId'), "node_revision_minor_flag" => $_POST['nodeMinorFlag'], "node_revision_time" => getnow()); ins('node_revision', $newNodeData); $nodeRevisionAddedId = mysql_insert_id(); $nodeEditedId = fv('nodeId'); $user = new user(0, '', 0, fv('wvUserName'), 0, '', '', ''); $user->request_content('user_name', fv('wvUserName')); $newnodeeditids = $user->node_edit_ids . itr(1494) . $nodeRevisionAddedId; $user->set_variable('node_edit_ids', $newnodeeditids); return $nodeEditedId; }
$to = 'files/' . $new_name; if ($size > $maxsize) { echo "Файл больше 100 мб. Уменьшите размер вашего файла или загрузите другой. <br><a href='' onClick=window.close();>Закрыть окно</a>"; } elseif (!in_array($type, $extentions)) { echo ' <b>Файл имеет недопустимое расширение <font color="#FF0000">' . $type . '</font></b>. Допустимыми являются форматы изображений. <br>'; } else { if (copy($file, $to)) { $fl = fopen($to, "r"); while (!feof($fl)) { $buffer = fgets($fl, 4096); $explode = explode(";", $buffer); $explode[3] = trim($explode[3]); if (!ins($explode[3], $explode[0], $explode[2], $explode[1])) { $ex = explode("-", $explode[3]); $curs = abs(substr($ya, 2, 2) - substr(trim($ex[1]), 0, 2)); if ($curs == 0) { $curs = 1; } $insert = mysql_query("INSERT INTO `group`(`name`,`curs`)VALUES('{$explode['3']}','{$curs}')"); if ($insert) { ins($explode[3], $explode[0], $explode[2], $explode[1]); } } } redirect($home_url); } else { echo "Файл НЕ был загружен."; } } } }