<?php include "../commons.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\nUPDATE\r\n\taddress \r\nSET\r\n\t\taddressLine1='" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\taddressLine2='" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\taddressCity='" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\taddressState='" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\taddressZip='" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\taddressPOBox='" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\taddressLat='" . $coordinates[0] . "',\r\n\t\taddressLong='" . $coordinates[1] . "'\r\nWHERE\r\n\t\taddressId=" . $_REQUEST['a'] . "\r\n\t\t"; //p_array($_REQUEST); mysql_query($queryAddress, $conexion); //p_array($_SESSION); $queryVendor = "\r\nUPDATE\r\n\tvendor\r\nSET\r\n\t\tvendorName='" . mysql_real_escape_string($_REQUEST['vendorName']) . "',\r\n\t\tvendorInfo='" . mysql_real_escape_string($_REQUEST['vendorInfo']) . "',\r\n\t\tvendorTel='" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['vendorTel'])) . "',\r\n\t\tvendorFax='" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['vendorFax'])) . "',\r\n\t\tvendorComment ='" . mysql_real_escape_string($_REQUEST['vendorComment']) . "'\r\nWHERE\r\n\t\tvendorId=" . $_REQUEST['i'] . "\r\n\t\t"; //echo $queryVendor; mysql_query($queryVendor, $conexion); $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",2,' " . mysql_real_escape_string($_REQUEST['vendorName']) . " into vendors');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:/trucking/php/view/viewVendor.php?i=" . $_REQUEST['i']);
function saveEditSupplier($handler, $supplierId, $vendor, $name, $tel, $fax, $info, $dumptime, $line1, $line2, $city, $state, $zip, $box) { $supplier = getBasicSupplierInfo($handler, $supplierId); $tel = cleanPhoneNumber(mysql_real_escape_string($tel)); $fax = cleanPhoneNumber(mysql_real_escape_string($fax)); $addressId = editAddress($handler, $supplier['addressId'], $line1, $line2, $city, $state, $zip, $box); $supplierQuery = "UPDATE supplier SET\n\t\tsupplierName = '{$name}',\n\t\tvendorId = '{$vendor}',\n\t\tsupplierTel = '{$tel}',\n\t\tsupplierFax = '{$fax}',\n\t\tsupplierInfo = '{$info}',\n\t\tsupplierDumptime = '{$dumptime}'\n\tWHERE supplierId = '{$supplierId}'"; mysql_query($supplierQuery, $handler); return $supplierId; }
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\ninsert into\r\n\taddress \r\n\t(\r\n\t\taddressLine1,\r\n\t\taddressLine2,\r\n\t\taddressCity,\r\n\t\taddressState,\r\n\t\taddressZip,\r\n\t\taddressPOBox,\r\n\t\taddressLat,\r\n\t\taddressLong\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\t'" . $coordenadas[0] . "',\r\n\t\t'" . $coordenadas[1] . "'\r\n\t)"; //insert mysql_query($queryAddress, $conexion); $addressId = mysql_insert_id(); $queryCustomer = "\r\ninsert into\r\n\tcustomer\r\n\t(\r\n\t\tcustomerName,\r\n\t\taddressId,\r\n\t\tcustomerTel,\r\n\t\tcustomerFax,\r\n\t\tcustomerWebsite,\r\n\t\ttermId\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['customerName']) . "',\r\n\t\t'" . mysql_real_escape_string($addressId) . "',\r\n\t\t'" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['customerTel'])) . "',\r\n\t\t'" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['customerFax'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['customerWebsite']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['termId']) . "'\r\n\t)"; mysql_query($queryCustomer, $conexion); $customerId = mysql_insert_id(); if (!is_dir("../../archive/customerId{$customerId}")) { mkdir("../../archive/customerId{$customerId}"); } $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",1,' " . mysql_real_escape_string($_REQUEST['customerName']) . " into customers');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:newCustomer.php");
<?php include "../commons.php"; session_start(); ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\nUPDATE\r\n\taddress \r\nSET\r\n\t\taddressLine1='" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\taddressLine2='" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\taddressCity='" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\taddressState='" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\taddressZip='" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\taddressPOBox='" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\taddressLat='" . $coordinates[0] . "',\r\n\t\taddressLong='" . $coordinates[1] . "'\r\nWHERE\r\n\t\taddressId=" . $_REQUEST['a'] . "\r\n\t\t"; //echo $queryAddress; mysql_query($queryAddress, $conexion); $queryBroker = "\r\nUPDATE\r\n\tbroker\r\nSET\r\n\t\tbrokerPid='" . mysql_real_escape_string($_REQUEST['brokerPid']) . "',\r\n\t\tbrokerName='" . mysql_real_escape_string($_REQUEST['brokerName']) . "',\r\n\t\tbrokerContactName='" . mysql_real_escape_string($_REQUEST['brokerContactName']) . "',\r\n\t\tbrokerRadio='" . mysql_real_escape_string($_REQUEST['brokerRadio']) . "',\r\n\t\tbrokerMobile='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['brokerMobile'])) . "',\r\n\t\tcarrierId='" . mysql_real_escape_string($_REQUEST['carrierId']) . "',\r\n\t\tbrokerEmail='" . mysql_real_escape_string($_REQUEST['brokerMail']) . "',\r\n\t\tbrokerTax='" . mysql_real_escape_string($_REQUEST['brokerTax']) . "',\r\n\t\tbrokerIccCert='" . mysql_real_escape_string($_REQUEST['brokerIccCert']) . "',\r\n\t\tbrokerInsuranceWc='" . mysql_real_escape_string($_REQUEST['brokerInsWc']) . "',\r\n\t\tbrokerWcExpire='" . to_YMD(mysql_real_escape_string($_REQUEST['brokerWcExpire'])) . "',\r\n\t\tbrokerInsuranceLiability='" . mysql_real_escape_string($_REQUEST['brokerInsLiability']) . "',\r\n\t\tbrokerLbExpire='" . to_YMD(mysql_real_escape_string($_REQUEST['brokerLbExpire'])) . "',\r\n\t\tbrokerGeneralLiability='" . mysql_real_escape_string($_REQUEST['brokerGeneralLiability']) . "',\r\n\t\tbrokerGlExp='" . to_YMD(mysql_real_escape_string($_REQUEST['brokerGlExp'])) . "',\r\n\t\tbrokerPercentage='" . mysql_real_escape_string($_REQUEST['brokerPercentage']) . "',\r\n\t\tbrokerStartDate='" . to_YMD(mysql_real_escape_string($_REQUEST['startupDate'])) . "',\r\n\t\tbrokerStatus='" . mysql_real_escape_string($_REQUEST['brokerStatus']) . "',\r\n\t\tbrokerTel='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['brokerTel'])) . "',\r\n\t\tbrokerFax='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['brokerFax'])) . "',\r\n\t\tbrokerGender='" . mysql_real_escape_string($_REQUEST['brokerGender']) . "',\r\n\t\tethnicId='" . mysql_real_escape_string($_REQUEST['ethnicId']) . "',\r\n\t\ttermId ='" . mysql_real_escape_string($_REQUEST['termId']) . "'\r\nWHERE\r\n\t\tbrokerId=" . $_REQUEST['i'] . "\r\n\t\t"; //echo $queryBroker; mysql_query($queryBroker, $conexion); $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",2,' " . mysql_real_escape_string($_REQUEST['brokerName']) . " into brokers');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:/trucking/php/view/viewBroker.php?i=" . $_REQUEST['i']);
addressLine2='".mysql_real_escape_string($_REQUEST['addressLine2'])."', addressCity='".mysql_real_escape_string($_REQUEST['addressCity'])."', addressState='".mysql_real_escape_string($_REQUEST['addressState'])."', addressZip='".mysql_real_escape_string($_REQUEST['addressZip'])."', addressPOBox='".mysql_real_escape_string($_REQUEST['addressPOBox'])."', addressLat='".$coordenadas[0]."', addressLong='".$coordenadas[1]."' WHERE addressId=".$_GET['i']; $queryMfi=" UPDATE mfiinfo SET mfiTel='".cleanPhoneNumber(mysql_real_escape_string($_REQUEST['mfiTel']))."', mfiFax='".cleanPhoneNumber(mysql_real_escape_string($_REQUEST['mfiFax']))."', mfiMail='".mysql_real_escape_string($_REQUEST['mfiMail'])."', mfiPass='******'mfiPass'])."'"; $queryLog=" insert into log (logDate, userId, logAction, logDescription) values (NOW(),".$_SESSION['user']->id.",2,' mfiInfo Table');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */
<?php include "../commons.php"; session_start(); ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\nUPDATE\r\n\taddress \r\nSET\r\n\t\taddressLine1='" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\taddressLine2='" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\taddressCity='" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\taddressState='" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\taddressZip='" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\taddressPOBox='" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\taddressLat='" . $coordinates[0] . "',\r\n\t\taddressLong='" . $coordinates[1] . "'\r\nWHERE\r\n\t\taddressId=" . $_REQUEST['a'] . "\r\n\t\t"; //echo $queryAddress; mysql_query($queryAddress, $conexion); $queryBroker = "\r\nUPDATE\r\n\tdriver\r\nSET\r\n\t\tdriverFirstName='" . mysql_real_escape_string($_REQUEST['driverFirstName']) . "',\r\n\t\tdriverLastName='" . mysql_real_escape_string($_REQUEST['driverLastName']) . "',\r\n\t\tdriverMobile='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['driverMobile'])) . "',\r\n\t\tcarrierId='" . mysql_real_escape_string($_REQUEST['carrierId']) . "',\r\n\t\tdriverEmail='" . mysql_real_escape_string($_REQUEST['driverMail']) . "',\r\n\t\tdriverSSN='" . mysql_real_escape_string($_REQUEST['driverSSN']) . "',\r\n\t\tdriverPercentage='" . mysql_real_escape_string($_REQUEST['driverPercentage']) . "',\r\n\t\tdriverStartDate='" . to_YMD(mysql_real_escape_string($_REQUEST['driverStartDate'])) . "',\r\n\t\tdriverStatus='" . mysql_real_escape_string($_REQUEST['driverStatus']) . "',\r\n\t\tdriverTel='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['driverTel'])) . "',\r\n\t\ttermId ='" . mysql_real_escape_string($_REQUEST['termId']) . "',\r\n\t\tethnicId ='" . mysql_real_escape_string($_REQUEST['ethnicId']) . "',\r\n\t\tworkId ='" . mysql_real_escape_string($_REQUEST['workId']) . "',\r\n\t\tdriverClass ='" . mysql_real_escape_string($_REQUEST['driverClass']) . "',\r\n\t\tdriverGender ='" . mysql_real_escape_string($_REQUEST['driverGender']) . "',\r\n\t\tdriverPW ='" . mysql_real_escape_string($_REQUEST['driverPW']) . "',\r\n\t\tunionId ='" . mysql_real_escape_string($_REQUEST['unionId']) . "'\r\nWHERE\r\n\t\tdriverId=" . $_REQUEST['i'] . "\r\n\t\t"; //echo $queryBroker; mysql_query($queryBroker, $conexion); //if($_REQUEST['driverRemaining731']>0){ $firstRemaining = mysql_fetch_assoc(mysql_query("select * from remainings_731 where driverId=" . $_REQUEST['i'] . " and remainingStartDate='0000-00-00' limit 1", $conexion)); if ($firstRemaining != null) { //update mysql_query("update remainings_731 set remainingValue='" . mysql_real_escape_string($_REQUEST['driverRemaining731']) . "' where driverId=" . $_REQUEST['i'] . " and remainingStartDate='0000-00-00' ", $conexion); //echo "update remainings_731 set remainingValue='".mysql_real_escape_string($_REQUEST['driverRemaining731'])."' where driverId=".$_REQUEST['i']." and remainingStartDate='0000-00-00' "; } else { //insert mysql_query("insert into remainings_731 (driverId,remainingValue) values (" . $_REQUEST['i'] . "," . mysql_real_escape_string($_REQUEST['driverRemaining731']) . ")", $conexion); } //} $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",2,' " . mysql_real_escape_string($_REQUEST['driverName']) . " into drivers');"; /* For Log Actions: 1 -> New (insert into)
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\ninsert into\r\n\taddress \r\n\t(\r\n\t\taddressLine1,\r\n\t\taddressLine2,\r\n\t\taddressCity,\r\n\t\taddressState,\r\n\t\taddressZip,\r\n\t\taddressPOBox,\r\n\t\taddressLat,\r\n\t\taddressLong\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\t'" . $coordinates[0] . "',\r\n\t\t'" . $coordinates[1] . "'\r\n\t)"; mysql_query($queryAddress, $conexion); $addressId = mysql_insert_id(); $queryVendor = "\r\ninsert into\r\n\tvendor\r\n\t(\r\n\t\tvendorName,\r\n\t\tvendorInfo,\r\n\t\tvendorComment,\r\n\t\tvendorTel,\r\n\t\tvendorFax,\r\n\t\taddressId\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['vendorName']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['vendorComment']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['vendorInfo']) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['vendorTel'])) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['vendorFax'])) . "',\r\n\t\t'" . $addressId . "'\r\n\t)"; mysql_query($queryVendor, $conexion); $vendorId = mysql_insert_id(); //echo $queryVendor; $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",1,' " . mysql_real_escape_string($_REQUEST['vendorName']) . " into vendors');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:newVendor.php");
function getBrokersTable($handler, $params, $limit = '200') { $values = $params['values']; $headers = $params['headers']; $types = $params['variables']; $brokersQuery = "\n\t\tSELECT\n\t\t\t*\n\t\tFROM\n\t\t\tbroker\n\t\t\tJOIN address USING (addressId)\n\t\t\tJOIN term USING (termId)\n\t\t\tLEFT JOIN ethnic USING (ethnicId)\n\t\tWHERE brokerId <> 0\n\t"; if (isset($params['brokerId']) && $params['brokerId'] != '') { $brokersQuery .= " AND brokerId = '" . $params['brokerId'] . "'"; } if (isset($params['brokerPid']) && $params['brokerPid'] != '') { $brokersQuery .= " AND brokerPid like '%" . $params['brokerPid'] . "%'"; } if (isset($params['brokerName']) && $params['brokerName'] != '') { $brokersQuery .= " AND brokerName like '%" . $params['brokerName'] . "%'"; } if (isset($params['addressLine1']) && $params['addressLine1'] != '') { $brokersQuery .= " AND addressLine1 like '%" . $params['addressLine1'] . "%'"; } if (isset($params['tel']) && $params['tel'] != '') { $brokersQuery .= " AND brokerTel like '%" . cleanPhoneNumber($params['tel']) . "%'"; } if (isset($params['addressCity']) && $params['addressCity'] != '') { $brokersQuery .= " AND addressCity like '%" . $params['addressCity'] . "%'"; } if (isset($params['addressState']) && $params['addressState'] != '0') { $brokersQuery .= " AND addressState ='" . $params['addressState'] . "'"; } if (isset($params['addressZip']) && $params['addressZip'] != '') { $brokersQuery .= " AND addressZip ='" . $params['addressZip'] . "'"; } if (isset($params['brokerGender']) && $params['brokerGender'] != '0') { $brokersQuery .= " AND brokerGender ='" . $params['brokerGender'] . "'"; } if (isset($params['ethnicId']) && $params['ethnicId'] != '0') { $brokersQuery .= " AND ethnicId ='" . $params['ethnicId'] . "'"; } $brokersQuery .= " ORDER BY brokerName asc " . ($limit == '' ? '' : ' limit ' . $limit); $dataTable = array(); $headerArray = explode("~", $headers); $headerRow = array("id"); foreach ($headerArray as $header) { $headerRow[] = $header; } $dataTable[] = $headerRow; $typeMap = createTypeMap($values, $types, '~'); $brokers = mysql_query($brokersQuery, $handler); while ($broker = mysql_fetch_assoc($brokers)) { $dataTable[] = explode('~', $broker['brokerId'] . mapValuesWithTypes($broker, $typeMap, '~', '')); } return $dataTable; }
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\ninsert into\r\n\taddress \r\n\t(\r\n\t\taddressLine1,\r\n\t\taddressLine2,\r\n\t\taddressCity,\r\n\t\taddressState,\r\n\t\taddressZip,\r\n\t\taddressPOBox,\r\n\t\taddressLat,\r\n\t\taddressLong\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\t'" . $coordinates[0] . "',\r\n\t\t'" . $coordinates[1] . "'\r\n\t)"; //insert mysql_query($queryAddress, $conexion); $addressId = mysql_insert_id(); $queryBroker = "\r\ninsert into\r\n\tbroker\r\n\t(\r\n\t\tbrokerPid,\r\n\t\tbrokerName,\r\n\t\tbrokerContactName,\r\n\t\taddressId,\r\n\t\tbrokerTax,\r\n\t\tbrokerTel,\r\n\t\tbrokerFax,\r\n\t\tbrokerRadio,\r\n\t\tbrokerMobile,\r\n\t\tcarrierId,\r\n\t\tbrokerEmail,\r\n\t\tbrokerIccCert,\r\n\t\tbrokerInsuranceWc,\r\n\t\tbrokerWcExpire,\r\n\t\tbrokerInsuranceLiability,\r\n\t\tbrokerLbExpire,\r\n\t\tbrokerGeneralLiability,\r\n\t\tbrokerGlExp,\r\n\t\tbrokerStartDate,\r\n\t\tbrokerStatus,\r\n\t\tbrokerPercentage,\r\n\t\tbrokerGender,\r\n\t\tethnicId,\r\n\t\ttermId\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerPid']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerName']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerContactName']) . "',\r\n\t\t'" . mysql_real_escape_string($addressId) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerTax']) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['brokerTel'])) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['brokerFax'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerRadio']) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['brokerMobile'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['carrierId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerMail']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerIccCert']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerInsWc']) . "',\r\n\t\t'" . mysql_real_escape_string(to_YMD($_REQUEST['brokerWcExpire'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerInsLiability']) . "',\r\n\t\t'" . mysql_real_escape_string(to_YMD($_REQUEST['brokerLbExpire'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerGeneralLiability']) . "',\r\n\t\t'" . mysql_real_escape_string(to_YMD($_REQUEST['brokerGlExp'])) . "',\r\n\t\t'" . mysql_real_escape_string(to_YMD($_REQUEST['startupDate'])) . "',\r\n\t\t'1',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerPercentage']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerGender']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['ethnicId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['termId']) . "'\r\n\t)"; //echo $queryBroker; mysql_query($queryBroker, $conexion); $brokerId = mysql_insert_id(); if (!is_dir("../../archive/brokerId{$brokerId}")) { mkdir("../../archive/brokerId{$brokerId}"); } $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",1,' " . mysql_real_escape_string($_REQUEST['customerName']) . " into customers');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion);
<?php include "../commons.php"; session_start(); ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\nUPDATE\r\n\taddress \r\nSET\r\n\t\taddressLine1='" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\taddressLine2='" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\taddressCity='" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\taddressState='" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\taddressZip='" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\taddressPOBox='" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\taddressLat='" . $coordinates[0] . "',\r\n\t\taddressLong='" . $coordinates[1] . "'\r\nWHERE\r\n\t\taddressId=" . $_REQUEST['a'] . "\r\n\t\t"; //insert //echo $queryAddress; mysql_query($queryAddress, $conexion); $queryCustomer = "\r\nUPDATE\r\n\tcustomer\r\nSET\r\n\t\tcustomerName='" . mysql_real_escape_string($_REQUEST['customerName']) . "',\r\n\t\tcustomerTel='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['customerTel'])) . "',\r\n\t\tcustomerFax='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['customerFax'])) . "',\r\n\t\tcustomerWebsite='" . mysql_real_escape_string($_REQUEST['customerWebsite']) . "',\r\n\t\ttermId ='" . mysql_real_escape_string($_REQUEST['termId']) . "'\r\nWHERE\r\n\t\tcustomerId=" . $_REQUEST['i'] . "\r\n\t\t"; //echo $queryCustomer; mysql_query($queryCustomer, $conexion); $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",2,' " . mysql_real_escape_string($_REQUEST['customerName']) . " into customers');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:/trucking/php/view/viewCustomer.php?i=" . $_REQUEST['i']);
<?php include "../commons.php"; session_start(); ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\nUPDATE\r\n\taddress \r\nSET\r\n\t\taddressLine1='" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\taddressLine2='" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\taddressCity='" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\taddressState='" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\taddressZip='" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\taddressPOBox='" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\taddressLat='" . $coordinates[0] . "',\r\n\t\taddressLong='" . $coordinates[1] . "'\r\nWHERE\r\n\t\taddressId=" . $_REQUEST['a'] . "\r\n\t\t"; //insert //echo $queryAddress; mysql_query($queryAddress, $conexion); $queryContact = "\r\nUPDATE\r\n\tcontact\r\nSET\r\n\t\tcontactName='" . mysql_real_escape_string($_REQUEST['contactName']) . "',\r\n\t\tcontactTel='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['contactTel'])) . "',\r\n\t\tcontactFax='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['contactFax'])) . "',\r\n\t\tcontactMobil='" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['contactMobil'])) . "',\r\n\t\tcontactMail='" . mysql_real_escape_string($_REQUEST['contactMail']) . "',\r\n\t\tcontactInfo='" . mysql_real_escape_string($_REQUEST['contactInfo']) . "',\r\n\t\tcustomerId ='" . mysql_real_escape_string($_REQUEST['customerId']) . "'\r\nWHERE\r\n\t\tcontactId=" . $_REQUEST['i'] . "\r\n\t\t"; //echo $queryContact; mysql_query($queryContact, $conexion); $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",2,' " . mysql_real_escape_string($_REQUEST['contactName']) . " into contacts');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:/trucking/php/view/viewContact.php?i=" . $_REQUEST['i']);
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\ninsert into\r\n\taddress \r\n\t(\r\n\t\taddressLine1,\r\n\t\taddressLine2,\r\n\t\taddressCity,\r\n\t\taddressState,\r\n\t\taddressZip,\r\n\t\taddressPOBox,\r\n\t\taddressLat,\r\n\t\taddressLong\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\t'" . $coordinates[0] . "',\r\n\t\t'" . $coordinates[1] . "'\r\n\t)"; //insert mysql_query($queryAddress, $conexion); $addressId = mysql_insert_id(); $queryBroker = "\r\ninsert into\r\n\tdriver\r\n\t(\r\n\t\tdriverFirstName,\r\n\t\tdriverLastName,\r\n\t\taddressId,\r\n\t\tdriverSSN,\r\n\t\tdriverTel,\r\n\t\tdriverMobile,\r\n\t\tcarrierId,\r\n\t\tdriverEmail,\r\n\t\tdriverUnion,\r\n\t\tdriverStartDate,\r\n\t\tdriverStatus,\r\n\t\tdriverPercentage,\r\n\t\tbrokerId,\r\n\t\ttermId,\r\n\t\tdriverGender,\r\n\t\tdriverClass,\r\n\t\tethnicId,\r\n\t\tworkId\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverFirst']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverLast']) . "',\r\n\t\t'" . mysql_real_escape_string($addressId) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverSSN']) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['driverTel'])) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['driverMobile'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['carrierId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverMail']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverUnion']) . "',\r\n\t\t'" . mysql_real_escape_string(to_YMD($_REQUEST['startupDate'])) . "',\r\n\t\t'1',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverPercentage']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['brokerId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['termId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverGender']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['driverClass']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['ethnicId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['workId']) . "'\r\n\t)"; //echo $queryBroker; mysql_query($queryBroker, $conexion); $brokerId = mysql_insert_id(); mysql_close($conexion); header("Location:newDriver.php");
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\ninsert into\r\n\taddress \r\n\t(\r\n\t\taddressLine1,\r\n\t\taddressLine2,\r\n\t\taddressCity,\r\n\t\taddressState,\r\n\t\taddressZip,\r\n\t\taddressPOBox,\r\n\t\taddressLat,\r\n\t\taddressLong\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\t'" . $coordinates[0] . "',\r\n\t\t'" . $coordinates[1] . "'\r\n\t)"; //insert mysql_query($queryAddress, $conexion); $addressId = mysql_insert_id(); $querySupplier = "\r\ninsert into\r\n\tsupplier\r\n\t(\r\n\t\tsupplierName,\r\n\t\tsupplierTel,\r\n\t\tsupplierFax,\r\n\t\taddressId,\r\n\t\tvendorId,\r\n\t\tsupplierDumptime,\r\n\t\tsupplierInfo\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['supplierName']) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['supplierTel'])) . "',\r\n\t\t'" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['supplierFax'])) . "',\r\n\t\t'" . mysql_real_escape_string($addressId) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['vendorId']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['supplierDumptime']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['supplierInfo']) . "'\r\n\t)"; //echo$querySupplier; mysql_query($querySupplier, $conexion); $supplierId = mysql_insert_id(); foreach ($_REQUEST['material'] as $material) { foreach ($material as $key => $value) { if (preg_match("/free/i", $value)) { $value = 0; } if (!is_nan($value) && $value != "") { $query = "insert into \r\n\t\t\t\tsupplierMaterial \r\n\t\t\t(\r\n\t\t\tsupplierId,\r\n\t\t\tmaterialId,\r\n\t\t\tsupplierMaterialLastModified,\r\n\t\t\tsupplierMaterialPrice\r\n\t\t\t) \r\n\t\t\t\tvalues\r\n\t\t\t(\r\n\t\t\t" . $supplierId . ",\r\n\t\t\t" . $key . ",\r\n\t\t\tnow(),\r\n\t\t\t" . decimalPad($value) . "\r\n\t\t\t)"; //echo$query."<br/>"; mysql_query($query, $conexion); } } }
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\ninsert into\r\n\taddress \r\n\t(\r\n\t\taddressLine1,\r\n\t\taddressLine2,\r\n\t\taddressCity,\r\n\t\taddressState,\r\n\t\taddressZip,\r\n\t\taddressPOBox,\r\n\t\taddressLat,\r\n\t\taddressLong\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\t'" . $coordinates[0] . "',\r\n\t\t'" . $coordinates[1] . "'\r\n\t)"; //insert mysql_query($queryAddress, $conexion); $addressId = mysql_insert_id(); //echo $queryAddress; $queryContact = "\r\ninsert into\r\n\tcontact\r\n\t(\r\n\t\tcontactName,\r\n\t\taddressId,\r\n\t\tcontactTel,\r\n\t\tcontactFax,\r\n\t\tcontactMobil,\r\n\t\tcontactMail,\r\n\t\tcontactInfo,\r\n\t\tcustomerId\r\n\t)\r\n\tvalues\r\n\t(\r\n\t\t'" . mysql_real_escape_string($_REQUEST['contactName']) . "',\r\n\t\t'" . mysql_real_escape_string($addressId) . "',\r\n\t\t'" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['contactTel'])) . "',\r\n\t\t'" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['contactFax'])) . "',\r\n\t\t'" . cleanPhoneNumber(mysql_real_escape_string($_REQUEST['contactMobil'])) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['contactMail']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['contactInfo']) . "',\r\n\t\t'" . mysql_real_escape_string($_REQUEST['customerId']) . "'\r\n\t)"; mysql_query($queryContact, $conexion); $contactId = mysql_insert_id(); //echo $queryContact; $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",1,' " . mysql_real_escape_string($_REQUEST['contactName']) . " into contacts');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:newContact.php");
<?php include "../commons.php"; include "../conexion.php"; ini_set('display_errors', 'Off'); ini_set('display_startup_errors', 'Off'); error_reporting(0); session_start(); //p_array($_REQUEST); //p_array($_SESSION); $coordinates = getCoordinates("{$_REQUEST['addressLine1']} {$_REQUEST['addressZip']} {$_REQUEST['addressCity']} {$_REQUEST['addressState']}"); $queryAddress = "\r\nUPDATE\r\n\taddress \r\nSET\r\n\t\taddressLine1='" . mysql_real_escape_string($_REQUEST['addressLine1']) . "',\r\n\t\taddressLine2='" . mysql_real_escape_string($_REQUEST['addressLine2']) . "',\r\n\t\taddressCity='" . mysql_real_escape_string($_REQUEST['addressCity']) . "',\r\n\t\taddressState='" . mysql_real_escape_string($_REQUEST['addressState']) . "',\r\n\t\taddressZip='" . mysql_real_escape_string($_REQUEST['addressZip']) . "',\r\n\t\taddressPOBox='" . mysql_real_escape_string($_REQUEST['addressPOBox']) . "',\r\n\t\taddressLat='" . $coordinates[0] . "',\r\n\t\taddressLong='" . $coordinates[1] . "'\r\nWHERE\r\n\t\taddressId=" . $_REQUEST['a'] . "\r\n\t\t"; //insert //echo $queryAddress; mysql_query($queryAddress, $conexion); $querySupplier = "\r\nUPDATE\r\n\tsupplier\r\nSET\r\n\t\tsupplierName='" . mysql_real_escape_string($_REQUEST['supplierName']) . "',\r\n\t\tsupplierTel='" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['supplierTel'])) . "',\r\n\t\tsupplierFax='" . mysql_real_escape_string(cleanPhoneNumber($_REQUEST['supplierFax'])) . "',\r\n\t\tsupplierInfo='" . mysql_real_escape_string($_REQUEST['supplierInfo']) . "',\r\n\t\tsupplierDumptime='" . mysql_real_escape_string($_REQUEST['supplierDumptime']) . "',\r\n\t\tvendorId ='" . mysql_real_escape_string($_REQUEST['vendorId']) . "'\r\nWHERE\r\n\t\tsupplierId=" . $_REQUEST['i'] . "\r\n\t\t"; //echo $queryContact; mysql_query($querySupplier, $conexion); $queryLog = "\r\ninsert into \r\n\tlog\r\n\t\t(logDate, userId, logAction, logDescription)\r\n\tvalues\r\n\t\t(NOW()," . $_SESSION['user']->id . ",2,' " . mysql_real_escape_string($_REQUEST['contactName']) . " into contacts');"; /* For Log Actions: 1 -> New (insert into) 2 -> Edit (update from) 3 -> Delete (delete from) */ mysql_query($queryLog, $conexion); mysql_close($conexion); header("Location:/trucking/php/view/viewSupplier.php?i=" . $_REQUEST['i']);