示例#1
0
<?php

session_start();
include_once "./default.php";
include_once "./config.php";
if (isset($_POST['submit'])) {
    $connect = mysqli_connect(DB, DBLOGIN, DBPASS, DBNAME) or die(mysqli_error());
    $query1 = "SELECT * FROM likes WHERE sess='" . $_POST['like_sess'] . "' AND id_comm='" . $_POST['like_id'] . "'";
    //из формы приняли id новости и id сесии для точной выборки
    $res = mysqli_query($connect, $query1);
    $num = mysqli_num_rows($res);
    // количество запроса по которому делаем условие
    if ($num == 1) {
        $query2 = "DELETE FROM likes WHERE sess='" . $_POST['like_sess'] . "' AND id_comm='" . $_POST['like_id'] . "' ";
        mysqli_query($connect, $query2) or die(mysqli_error($connect));
        header("Location: ../index.php");
    } else {
        $a = session_id();
        $idComm = intAll($_POST['like_id']);
        $query = "INSERT INTO likes VALUES ('','{$a}',{$idComm},1)";
        mysqli_query($connect, $query) or die(mysqli_error($connect));
        header("Location: ../index.php");
    }
}
        exit;
    }
}
if (isset($_POST['submit4']) && filter_var($_POST['newemail'], FILTER_VALIDATE_EMAIL)) {
    // условие на редактирование email
    $_POST = htmlAll($_POST);
    $email = $_POST['newemail'];
    $query = "UPDATE lightit SET email='{$email}' WHERE id='" . $_POST['user_id'] . "'" or die(mysqli_error());
    mysqli_query($connect, $query) or die(mysqli_error($connect));
    $_SESSION['info'] = 'Успешно отредактировано';
    header("Location: ../cabinet.php");
    exit;
}
if (isset($_POST['submit5'])) {
    // условие на редактирование телефона
    $_POST = intAll($_POST);
    $tell = $_POST['newtell'];
    $query = "UPDATE lightit SET tell='{$tell}' WHERE id='" . $_POST['user_id'] . "'" or die(mysqli_error());
    mysqli_query($connect, $query) or die(mysqli_error($connect));
    $_SESSION['info'] = 'Успешно отредактировано';
    header("Location: ../cabinet.php");
    exit;
}
if (isset($_POST['submit6'])) {
    $birthday = $_POST['birth_y'] . '-' . $_POST['birth_m'] . '-' . $_POST['birth_d'];
    $query = "UPDATE lightit SET birthday='{$birthday}' WHERE id='" . $_POST['user_id'] . "'" or die(mysqli_error());
    mysqli_query($connect, $query) or die(mysqli_error($connect));
    $_SESSION['info'] = 'Успешно отредактировано';
    header("Location: ../cabinet.php");
    exit;
}