예제 #1
0
 function getSearchBookTable($item)
 {
     $bookModel = new BookModel();
     $books = array();
     $books = $bookModel->searchBook($item);
     $result = "";
     if ($books) {
         foreach ($books as $b) {
             $_SESSION['current_book'] = $b->idBook;
             $result = $result . "<div class='row '>\n\t\t\t\t\t<div class='large-2 columns'>\n\t\t\t\t\t  <a href='#'> <span> </span><img src='{$b->cover}' alt='book cover' class=' thumbnail'></a>\n\t\t\t\t\t</div>\n\t\t\t\t\t<div class='large-10 columns'>\n\t\t\t\t\t  <div class='row'>\n\t\t\t\t\t\t<div class=' large-9 columns'>\n\t\t\t\t\t\t  <h5><a href='book.php?title={$b->title}&author={$b->author}&current_book={$b->idBook}'>{$b->title}</a></h5>\n\t\t\t\t\t\t</div>\n\t\t\t\t\t\t<div class=' large-3 columns'>\n\t\t\t\t\t\t  <a href='book.php?title={$b->title}&author={$b->author}&current_book={$b->idBook}'  class='button  expand medium'><span>Open Book</span> </a>\n\t\t\t\t\t\t</div>\n\t\t\t\t\t\t<div class='row'>\n\t\t\t\t\t\t  <div class=' large-12 columns'>\n\t\t\t\t\t\t\t<ul class='large-block-grid-2'>\n\t\t\t\t\t\t\t  <li>\n\t\t\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t  <li><strong>Author : </strong>{$b->author}</li>\n\t\t\t\t\t\t\t\t  <li><strong>Published by : </strong>{$b->publisher}</li>\n\t\t\t\t\t\t\t\t  <li><strong>Publish year : </strong>{$b->rYear}</li>\n\t\t\t\t\t\t\t\t  <li><strong>Price : </strong>{$b->price}</li>\n\t\t\t\t\t\t\t\t</ul>\n\t\t\t\t\t\t\t  </li>\n\t\t\t\t\t\t\t</ul>\n\t\t\t\t\t\t  </div>\n\t\t\t\t\t\t</div>\n\t\t\t\t\t  </div>\n\t\t\t\t\t</div>\n\t\t\t\t\t<hr>\n\t\t\t\t  </div>";
         }
     }
     return $result;
 }
예제 #2
0
include_once "testdb.php";
include_once "models/book_model.php";
$bookModel = new BookModel();
if (session_status() == PHP_SESSION_NONE) {
    session_start();
}
$serror = '';
if (isset($_POST['search'])) {
    if (!empty($_POST['tosearch'])) {
        $item = $_POST['tosearch'];
        //echo $item;
        // To protect MySQL injection for Security purpose
        $item = stripslashes($item);
        $item = mysql_real_escape_string($item);
        //$query = "SELECT * FROM book WHERE title LIKE '%$item%'";
        //echo $query;
        //$result = mysql_query($query);
        $book_array = array();
        $book_array = $bookModel->searchBook($item);
        if ($book_array) {
            $_SESSION['searched_item'] = $item;
            header("location: book_page.php");
        } else {
            if (isset($_SESSION['searched_item'])) {
                unset($_SESSION['searched_item']);
            }
            $serror = "No books found";
            header("location: book_page.php");
        }
    }
}