function update() { if ($_POST['lid'] == "" || $_POST['title'] == "" || $_POST['time'] == "" || $_POST['location'] == "") { return "-1"; } $db = new DBClass(); $sql = "SELECT uid FROM `app_lecture_info` WHERE lid = " . $_POST['lid']; $result = $db->query($sql); if ($result->num_rows <= 0) { return "-2"; } else { $row = $result->fetch_assoc(); $userObj = new UserClass(); $permisson = $userObj->get_privilege($_SESSION['uid']); if ($_SESSION['uid'] != $row["uid"] && $permisson != '1') { return "-3"; } } $lecture_inc = new LectureClass(); $result = $lecture_inc->update_lecture($_POST['lid'], $_POST['title'], $_POST['time'], $_POST['location'], $_POST['tag'], $_POST['description'], $_POST['slide']); return $result; }