<?php if(issetSessionVariable('user_level')){ if(getSessionVariable('user_level') >= RES_USERLEVEL_ADMIN){ } else{ echo "Error: You don't have permissions to access this page!"; die(""); } } else{ echo "Error: You don't have permissions to access this page!"; die(""); } if($pageid == "messages"){ $messages = getAllMessages(); $select = "<select name=\"messageid\">"; while($row = mysql_fetch_assoc($messages)){ $select = $select . "<option value=\"".$row['message_id']."\">".$row['start_date']." to ".$row['end_date']." - Priority ".$row['priority']."</option>"; } $select = $select . "</select>";
} if ($pageid == "messages") { $messages = getAllMessages(); $select = "<select name=\"messageid\">"; while ($row = mysql_fetch_assoc($messages)) { $select = $select . "<option value=\"" . $row['message_id'] . "\">" . $row['start_date'] . " to " . $row['end_date'] . " - Priority " . $row['priority'] . "</option>"; } $select = $select . "</select>"; echo "\r\t<center><h3>Manage System Messages</h3></center>\r\t<form action=\"./index.php\" method=\"GET\" id=\"newmessageform\">\r\t\t<input type=\"hidden\" name=\"pageid\" value=\"newmessage\">\r\t</form>\r\t<form action=\"./index.php?pageid=editmessage\" method=\"POST\">\r\t\t" . $select . "\r\t<br><input type=\"submit\" value=\"Edit\"> <input type=\"button\" value=\"New\" onclick=\"document.getElementById('newmessageform').submit()\">\r\t"; } else { if ($pageid == "newmessage") { echo "\r\t\r\t<script language=\"JavaScript\" id=\"jscal1x\">\r\t\tvar cal1x = new CalendarPopup(\"testdiv1\");\r\t</script>\r\t<script language=\"JavaScript\" id=\"jscal2x\">\r\t\tvar cal2x = new CalendarPopup(\"testdiv2\");\r\t</script>\r\t\r\t<center><h3>Create New System Message</h3></center>\r\t<form action=\"index.php?pageid=createmessage\" method=\"POST\">\r\t\r\t\t<table class=\"newmessage\">\r\t\r\t\t<tr>\r\r\t\t\t<td colspan=4 class=\"header\">Message Information</td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td class=\"centeredcellbold\">Start Date</td>\r\t\t\t<td class=\"centeredcell\"><input type=\"text\" name=\"startdate\" id=\"startdate\" onClick=\"cal1x.select(document.forms[0].startdate,'anchor1x','yyyy-MM-dd'); return false;\"><a style=\"visibility:hidden;\" name=\"anchor1x\" id=\"anchor1x\">a</a></td>\r\t\t\t<td class=\"centeredcellbold\">End Date</td>\r\t\t\t<td class=\"centeredcell\"><input type=\"text\" name=\"enddate\" id=\"enddate\" onClick=\"cal2x.select(document.forms[0].enddate,'anchor2x','yyyy-MM-dd'); return false;\"><a style=\"visibility:hidden;\" name=\"anchor2x\" id=\"anchor2x\">a</a></td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"2\" class=\"centeredcellbold\">Message Priority</td>\r\t\t\t<td colspan=\"2\" class=\"centeredcell\">\r\t\t\t\t<select name=\"priority\">\r\t\t\t\t\t<option value=\"1\">Priority 1 (Low)</option>\r\t\t\t\t\t<option value=\"2\">Priority 2 (High)</option>\r\t\t\t\t</select>\r\t\t\t</td> \r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"4\" class=\"header\">Message Body</td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"4\" class=\"centeredcell\"><textarea cols=\"59\" rows=\"3\" name=\"body\"></textarea></td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"4\" class=\"centeredcell\"><input type=\"submit\" value=\"Create\"></td>\r\t\t\t\r\t\t</tr>\r\t\t\r\t\t</table>\r\t\r\t</form><DIV ID=\"testdiv1\" STYLE=\"position:absolute;visibility:hidden;background-color:white;\"></DIV><DIV ID=\"testdiv2\" STYLE=\"position:absolute;visibility:hidden;background-color:white;\"></DIV>\r\t\r\t"; } else { if ($pageid == "editmessage") { $messageid = $_POST['messageid']; $message = mysql_fetch_assoc(getMessageByID($messageid)); $pri1 = ""; $pri2 = ""; if ($message['priority'] == 1) { $pri1 = "selected"; } else { $pri2 = "selected"; } echo "\r\t\r\t<script language=\"JavaScript\" id=\"jscal1x\">\r\t\tvar cal1x = new CalendarPopup(\"testdiv1\");\r\t</script>\r\t<script language=\"JavaScript\" id=\"jscal2x\">\r\t\tvar cal2x = new CalendarPopup(\"testdiv2\");\r\t</script>\r\t\r\t<center><h3>Edit System Message</h3></center>\r\t<form action=\"index.php?pageid=deletemessage\" method=\"POST\" id=\"deleteform\">\r\t\t<input type=\"hidden\" name=\"messageid\" value=\"" . $messageid . "\">\r\t</form>\r\t<form action=\"index.php?pageid=savemessage\" method=\"POST\">\r\t<input type=\"hidden\" name=\"messageid\" value=\"" . $messageid . "\">\r\t\t<table class=\"newmessage\">\r\t\r\t\t<tr>\r\r\t\t\t<td colspan=4 class=\"header\">Message Information</td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td class=\"centeredcellbold\">Start Date</td>\r\t\t\t<td class=\"centeredcell\"><input type=\"text\" name=\"startdate\" id=\"startdate\" onClick=\"cal1x.select(document.forms[1].startdate,'anchor1x','yyyy-MM-dd'); return false;\" value=\"" . $message['start_date'] . "\"><a style=\"visibility:hidden;\" name=\"anchor1x\" id=\"anchor1x\">a</a></td>\r\t\t\t<td class=\"centeredcellbold\">End Date</td>\r\t\t\t<td class=\"centeredcell\"><input type=\"text\" name=\"enddate\" id=\"enddate\" onClick=\"cal2x.select(document.forms[1].enddate,'anchor2x','yyyy-MM-dd'); return false;\" value=\"" . $message['end_date'] . "\"><a style=\"visibility:hidden;\" name=\"anchor2x\" id=\"anchor2x\">a</a></td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"2\" class=\"centeredcellbold\">Message Priority</td>\r\t\t\t<td colspan=\"2\" class=\"centeredcell\">\r\t\t\t\t<select name=\"priority\">\r\t\t\t\t\t<option value=\"1\" " . $pri1 . ">Priority 1 (Low)</option>\r\t\t\t\t\t<option value=\"2\" " . $pri2 . ">Priority 2 (High)</option>\r\t\t\t\t</select>\r\t\t\t</td> \r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"4\" class=\"header\">Message Body</td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"4\" class=\"centeredcell\"><textarea cols=\"59\" rows=\"3\" name=\"body\">" . $message['body'] . "</textarea></td>\r\t\t\t\r\t\t</tr>\r\t\t<tr>\r\r\t\t\t<td colspan=\"2\" class=\"centeredcell\"><input type=\"button\" value=\"Delete\" onclick=\"if(confirm('Are you sure you want to delete this message?')){document.getElementById('deleteform').submit();}\"></td>\r\t\t\t<td colspan=\"2\" class=\"centeredcell\"><input type=\"submit\" value=\"Save\"></td>\r\t\t\t\r\t\t</tr>\r\t\t\r\t\t</table>\r\t\r\t</form><DIV ID=\"testdiv1\" STYLE=\"position:absolute;visibility:hidden;background-color:white;\"></DIV><DIV ID=\"testdiv2\" STYLE=\"position:absolute;visibility:hidden;background-color:white;\"></DIV>\r\t\r\t"; } else { if ($pageid == "createmessage") { require 'adminfunctions.php'; $startdate = $_POST['startdate']; $enddate = $_POST['enddate']; $priority = $_POST['priority']; $body = $_POST['body'];