Ejemplo n.º 1
0
 public function delete($categoryId)
 {
     $conn = DB::connect();
     $deleteCategorySql = 'UPDATE categories SET isDeleted = 1 WHERE id="' . $categoryId . '"';
     if ($conn->query($deleteCategorySql)) {
         View::$viewBag['successMessage'] = "Category successfully deleted";
     } else {
         View::$viewBag['errors'][] = "Database error";
     }
 }
Ejemplo n.º 2
0
 public function checkout()
 {
     $db = DB::connect();
     $products = $_SESSION['cart']['products'];
     $productsId = [];
     $productsPrice = 0;
     foreach ($products as $id => $product) {
         $productsId[] = $id;
         $getProductPriceSql = 'SELECT price FROM products WHERE id="' . $id . '"';
         $productsPrice += $db->query($getProductPriceSql)->fetch()["price"] * $product["quantity"];
     }
     $userInfoSql = 'SELECT id, cash FROM users WHERE username="******"';
     $userInfo = $db->query($userInfoSql)->fetch();
     if ($productsPrice > $userInfo["cash"]) {
         View::$viewBag['errors'][] = "You don't have enough money";
     } else {
         $removeUserCashSql = 'UPDATE users SET cash = cash - "' . $productsPrice . '" WHERE id="' . $userInfo['id'] . '"';
         $db->query($removeUserCashSql);
         foreach ($products as $id => $product) {
             $productExistsSql = 'SELECT product_id FROM product_user WHERE product_id = "' . $id . '"
                                 AND user_id = "' . $userInfo['id'] . '"';
             if ($db->query($productExistsSql)->rowCount() == 0) {
                 $buyProductSql = 'INSERT INTO product_user(product_id, user_id, quantity)
                           VALUES("' . $id . '", "' . $userInfo['id'] . '", "' . $product["quantity"] . '")';
             } else {
                 $buyProductSql = 'UPDATE product_user SET quantity = quantity + "' . $product["quantity"] . '"
                                   WHERE  product_id = "' . $id . '" AND user_id = "' . $userInfo['id'] . '"';
             }
             $db->query($buyProductSql);
             $removeQuantitySql = 'UPDATE products SET quantity = quantity - "' . $product["quantity"] . '" WHERE id="' . $id . '"';
             $db->query($removeQuantitySql);
             unset($_SESSION['cart']['products'][$id]);
         }
         header("Location: " . __MAIN_URL__ . "Users/Products");
         exit;
     }
 }
Ejemplo n.º 3
0
 public function addProductToUser($username, $productId, $quantity)
 {
     $errors = [];
     if ($quantity <= 0) {
         $errors[] = "Invalid quantity";
     }
     $db = DB::connect();
     $getUserId = 'SELECT id FROM users WHERE username =  "******"';
     $userId = $db->query($getUserId);
     if ($userId->rowCount() > 0) {
         $userId = $userId->fetch()["id"];
     } else {
         $errors[] = "Invalid username";
     }
     $checkProductSql = 'SELECT id FROM products WHERE id = "' . $productId . '"';
     if ($db->query($checkProductSql)->rowCount() == 0) {
         $errors[] = "Invalid product";
     }
     if (count($errors) == 0) {
         $productExistsSql = 'SELECT product_id FROM product_user WHERE product_id = "' . $productId . '"
                                 AND user_id = "' . $userId . '"';
         if ($db->query($productExistsSql)->rowCount() == 0) {
             $addProductSql = 'INSERT INTO product_user(product_id, user_id, quantity)
                           VALUES("' . $productId . '", "' . $userId . '", "' . $quantity . '")';
         } else {
             $addProductSql = 'UPDATE product_user SET quantity = quantity + "' . $quantity . '"
                                   WHERE  product_id = "' . $productId . '" AND user_id = "' . $userId . '"';
         }
         $db->query($addProductSql);
         View::$viewBag['successMessage'] = "Product added";
     } else {
         View::$viewBag['errors'] = $errors;
     }
 }
Ejemplo n.º 4
0
 public function editUser($username, $email, $role, $cash, $userId)
 {
     $errors = [];
     if (strlen($username) == 0) {
         $errors[] = "Invalid username";
     }
     if (strlen($email) == 0) {
         $errors[] = "Invalid email";
     }
     if ($cash < 0) {
         $errors[] = "Invalid cash";
     }
     if (count($errors) == 0) {
         $db = DB::connect();
         $editUserSql = 'UPDATE users SET
                           username = "******",
                           email = "' . $email . '",
                           role = "' . $role . '",
                           cash = "' . $cash . '"
                           WHERE id = "' . $userId . '"';
         $db->query($editUserSql);
         View::$viewBag['successMessage'] = "User edited";
     } else {
         View::$viewBag['errors'] = $errors;
     }
 }