사용자단 따옴표 작업 bbs/write_update.php 할 차례

This commit is contained in:
whitedot
2012-11-30 19:10:49 +09:00
parent 68ae98cd95
commit de88c60cd2
54 changed files with 1264 additions and 1247 deletions

View File

@ -1,27 +1,27 @@
<?
include_once('./_common.php');
include_once("$g4['path']/lib/mailer.lib.php");
include_once($g4['path'].'/lib/mailer.lib.php');
if ($w == "")
{
$po = sql_fetch(" select * from $g4[poll_table] where po_id = '$po_id' ");
$po = sql_fetch(" select * from {$g4[poll_table]} where po_id = '{$po_id}' ");
if (!$po[po_id])
alert("po_id 값이 제대로 넘어오지 않았습니다.");
alert('po_id 값이 제대로 넘어오지 않았습니다.');
$tmp_row = sql_fetch(" select max(pc_id) as max_pc_id from $g4[poll_etc_table] ");
$tmp_row = sql_fetch(" select max(pc_id) as max_pc_id from {$g4[poll_etc_table]} ");
$pc_id = $tmp_row[max_pc_id] + 1;
$sql = " insert into $g4[poll_etc_table]
( pc_id, po_id, mb_id, pc_name, pc_idea, pc_datetime )
values ( '$pc_id', '$po_id', '$member[mb_id]', '$pc_name', '$pc_idea', '$g4[time_ymdhis]' ) ";
$sql = " insert into {$g4[poll_etc_table]}
( pc_id, po_id, mb_id, pc_name, pc_idea, pc_datetime )
values ( '{$pc_id}', '{$po_id}', '{$member[mb_id]}', '{$pc_name}', '{$pc_idea}', '{$g4[time_ymdhis]}' ) ";
sql_query($sql);
$pc_idea = stripslashes($pc_idea);
$name = cut_str($pc_name, $config[cf_cut_name]);
$mb_id = "";
$mb_id = '';
if ($member[mb_id])
$mb_id = "($member[mb_id])";
$mb_id = '($member[mb_id])';
// 환경설정의 투표 기타의견 작성시 최고관리자에게 메일발송 사용에 체크되어 있을 경우
if ($config[cf_email_po_super_admin])
@ -30,25 +30,25 @@ if ($w == "")
$content = $pc_idea;
ob_start();
include_once ("./poll_etc_update_mail.php");
include_once ('./poll_etc_update_mail.php');
$content = ob_get_contents();
ob_end_clean();
// 관리자에게 보내는 메일
$admin = get_admin("super");
mailer($name, "", $admin[mb_email], "설문조사 기타의견 메일", $content, 1);
$admin = get_admin('super');
mailer($name, '', $admin[mb_email], '설문조사 기타의견 메일', $content, 1);
}
}
else if ($w == "d")
else if ($w == 'd')
{
if ($member[mb_id] || $is_admin == "super")
if ($member[mb_id] || $is_admin == 'super')
{
$sql = " delete from $g4[poll_etc_table] where pc_id = '$pc_id' ";
$sql = " delete from {$g4[poll_etc_table]} where pc_id = '{$pc_id}' ";
if (!$is_admin)
$sql .= " and mb_id = '$member[mb_id]' ";
$sql .= " and mb_id = '{$member[mb_id]}' ";
sql_query($sql);
}
}
goto_url("./poll_result.php?po_id=$po_id&skin_dir=$skin_dir");
goto_url('./poll_result.php?po_id='.$po_id.'&amp;skin_dir='.$skin_dir);
?>