$_POST['Fill'] = 'true'; } else { //Show the record that's about to be deleted. echo "Record deleted:"; display_results(my_trusted_mysql_query("SELECT * FROM COMPANY WHERE Email = '{$q['Email']}'")); display_results(my_trusted_mysql_query("SELECT Email, Number FROM COMPANY_PHONE WHERE Email = '{$q['Email']}'")); $company_query = "DELETE FROM COMPANY WHERE Email='{$q['Email']}'"; my_trusted_mysql_query($company_query); $company_phone_query = "DELETE FROM COMPANY_PHONE WHERE Email='{$q['Email']}'"; my_trusted_mysql_query($company_phone_query); my_mysql_close(); $_POST['Fill'] = 'false'; } } else { echo "An unexpected selection has been made. <br />"; my_mysql_close(); die; } } } } } } } ?> </div> <div class="style35"> <ul> <strong>Company insert/update/delete instructions:</strong><br /> <li>When inserting a new company, you need to supply as much information as possible about the company.</li>
/** * fn: safe_inputs * brief: takes in an array and returns an array containing the * mysql_real_escape_string() version of each element. * param: $inputs -- array of inputs from $_POST probably */ function safe_inputs($inputs) { $q = array(); my_mysql_connect(); foreach ($inputs as $key => $value) { if (is_array($value)) { $q[mysql_real_escape_string($key)] = $value; } else { $q[mysql_real_escape_string($key)] = mysql_real_escape_string($value); } } my_mysql_close(); return $q; }