Example #1
0
     }
     break;
 case "edit_lend":
     if (mosGetParam($_POST, 'save') == 1) {
         if (count($bid) > 1) {
             echo "<script> alert('You must select only one item for edit'); window.history.go(-1); </script>\n";
             exit;
         }
         saveLend($option, $bid, "edit_lend");
     } else {
         edit_lend($option, $bid);
     }
     break;
 case "delete_review":
     $ids = explode(',', $bid[0]);
     delete_review($option, $ids[1]);
     editBook($option, $ids[0]);
     break;
 case "edit_review":
     $ids = explode(',', $bid[0]);
     edit_review($option, $ids[1], $ids[0]);
     break;
 case "update_review":
     $title = mosGetParam($_POST, 'title');
     $comment = mosGetParam($_POST, 'comment');
     $rating = mosGetParam($_POST, 'rating');
     $book_id = mosGetParam($_POST, 'book_id');
     $review_id = mosGetParam($_POST, 'review_id');
     update_review($title, $comment, $rating, $review_id);
     editBook($option, $book_id);
     break;
Example #2
0
             } else {
                 echo format_error_block($errors);
                 echo get_edit_form('update', array(), $HTTP_VARS);
             }
         } else {
             echo "<p class=\"error\">" . get_opendb_lang_var('operation_not_available') . "</p>";
         }
     } else {
         echo "<p class=\"error\">" . get_opendb_lang_var('operation_not_available') . "</p>";
     }
 } else {
     if ($HTTP_VARS['op'] == 'delete') {
         if (get_opendb_config_var('item_review', 'delete_support') !== FALSE) {
             if (is_review_author($review_r['sequence_number']) || is_user_granted_permission(PERM_ADMIN_REVIEWER)) {
                 if ($HTTP_VARS['confirmed'] == 'true') {
                     if (delete_review($HTTP_VARS['sequence_number'])) {
                         echo "<p class=\"success\">" . get_opendb_lang_var('review_deleted') . "</p>";
                     } else {
                         echo "<p class=\"error\">" . get_opendb_lang_var('review_not_deleted') . "</p>";
                     }
                 } else {
                     if ($HTTP_VARS['confirmed'] == 'false') {
                         echo "<p class=\"success\">" . get_opendb_lang_var('review_not_deleted') . "</p>";
                     } else {
                         echo get_op_confirm_form($PHP_SELF, get_opendb_lang_var('confirm_delete_review'), $HTTP_VARS);
                     }
                 }
             } else {
                 echo "<p class=\"error\">" . get_opendb_lang_var('operation_not_available') . "</p>";
             }
         } else {