1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
|
<?php $formid = "MaterialPriceList"; require_once "inc/configure.php";
//vdump($_REQUEST); if( $_REQUEST['action']=="master_mat_pricelist_add" ){ $lastid = (int) filter_var($_REQUEST['id'], FILTER_SANITIZE_NUMBER_INT); $gold = (float) filter_var($_REQUEST['gold'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $silver = (float) filter_var($_REQUEST['silver'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $copper = (float) filter_var($_REQUEST['copper'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $platinum = (float) filter_var($_REQUEST['platinum'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $aluminum = (float) filter_var($_REQUEST['aluminum'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $usd_cny = (float) filter_var($_REQUEST['usd-cny'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $usd_eur = (float) filter_var($_REQUEST['usd-eur'], FILTER_SANITIZE_NUMBER_FLOAT,FILTER_FLAG_ALLOW_FRACTION); $createby = filter_var($_SESSION['user'], FILTER_SANITIZE_STRING); if(havePermission("GNu")){ //add stone /* $sql = "INSERT INTO master_mat_pricelist SET gold = :gold, silver = :silver, copper = :copper, platinum = :platinum, aluminum = :aluminum, createby = :createby, createdate = GETDATE()";*/ if (defined("MSSQL")) { $sql = "INSERT INTO master_mat_pricelist ( gold, silver, copper, platinum, aluminum, [usd-cny], [usd-eur], createby, createdate ) Values ( :gold, :silver, :copper, :platinum, :aluminum, :usd_cny, :usd_eur, :createby, GETDATE() ) "; } $sth = $dbh->prepare($sql); $q= $sth->execute( array(':gold' => $gold, ':silver' => $silver, ':copper' => $copper, ':platinum' => $platinum, ':aluminum' => $aluminum, ':usd_cny' => $usd_cny, ':usd_eur' => $usd_eur, ':createby' => $createby) ); pdo_showerror($sth, $q); /*echo $sth->getSQL( ) . HTML_EOL;*/
} //exit; header("Location: master_mat_pricelist_addform.php?msg=Saved."); print "Saved."; exit; } print "Invalid Request";
|