1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
|
<?php global $dbh;
//----------------------------------------------------------------------------- // Check permission //----------------------------------------------------------------------------- if (!Util::isAdmin()) { redirectAndExit('index.php?message=No permission!'); }
//----------------------------------------------------------------------------- // Define customer //----------------------------------------------------------------------------- $customer = array( 'enable' => 1, );
//----------------------------------------------------------------------------- // Save if POST method //----------------------------------------------------------------------------- if (isPost()) { $sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?"; $parameters = array('v_cm_customer_support'); if (!($sth = $dbh->prepare($sql))) { throw new Exception("sql prepare statement failure: $sql"); } $sth->setFetchMode(PDO::FETCH_ASSOC); if (!$sth->execute($parameters)) { throw new Exception("sql execute statement failure: $sql"); } $columns = $sth->fetchAll(); foreach ($columns as $column) { $column = $column['column_name']; if (isset($_POST[$column])) { switch ($column) { case 'loginpw': { if (!empty($_POST[$column])) { $customer[$column] = md5($_POST[$column]); } break; } default: { $customer[$column] = $_POST[$column]; break; } } } } // Append record time $now = date("Y-m-d H:i:s"); $customer = array_merge($customer, array( 'creation_date' => $now, 'creation_by' => $_SESSION['webadmin']['id'],
)); // Create customer $columns = array(); $values = array(); $parameters = array(); foreach ($customer as $column => $value) { $columns[] = $column; $parameters[] = !strlen($value) ? null : $value; $values[] = '?'; } $sql = "INSERT v_cm_customer_support (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";
if (!($sth = $dbh->prepare($sql))) { throw new Exception("sql prepare statement failure: $sql"); } $sth->setFetchMode(PDO::FETCH_ASSOC); if (!$sth->execute($parameters)) { throw new Exception("sql execute statement failure: $sql"); } $customer['id'] = $dbh->lastInsertId(); $data = array( 'message' => 'Saved', ); redirectAndExit(Util::link(__DIR__ . '/index.php') . '?' . http_build_query($data)); }
//----------------------------------------------------------------------------- // Return array parameters //----------------------------------------------------------------------------- return array( 'customer' => $customer, //'roleOptions' => customer::roleOptions(), );
|