public static function addTalent($obj_Talent) { $db = config::dbconfig(); $obj_retresult = new returnResult(); $obj_Talent->TalentId = DAL_manageTalent::getLastTalentId() + 1; $sql = "INSERT INTO tbl_talent (TalentId,TalentType,TalentField,Description,TalentName) \n\t\tVALUES (" . common::noSqlInject($obj_Talent->TalentId) . "," . common::noSqlInject($obj_Talent->TalentType) . "," . "'" . common::noSqlInject($obj_Talent->TalentField) . "'" . "," . "'" . common::noSqlInject($obj_Talent->Description) . "'" . "," . "'" . common::noSqlInject($obj_Talent->TalentName) . "'" . ");"; $rs = mysql_query($sql); if (mysql_affected_rows() > 0) { $obj_retresult->type = 1; $obj_retresult->msg = "success"; $obj_retresult->data = $obj_Talent; } else { $obj_retresult->type = 0; $obj_retresult->msg = "failed"; } return $obj_retresult; }