diff --git a/header.php b/header.php index 76f27c1..83c8e6d 100644 --- a/header.php +++ b/header.php @@ -32,13 +32,15 @@ if ($conn->connect_error) { echo json_encode(array('response' => "Database connection error (".$conn->connect_error.")")); exit; } - -if(isset($_POST["selectedschool"]) && $loggedin){ +if(isset($_POST["selectedcompany"]) && $loggedin){ + $_SESSION["selectedcompany"] = $_POST["selectedcompany"]; +}elseif(isset($_POST["selectedschool"]) && $loggedin){ $_SESSION["selectedschool"] = $_POST["selectedschool"]; } -if(!isset($liteload) && !$loggedin && $isadmin){ +if(!isset($liteload) && !$loggedin && $isadmin && ($type == 1 || $type == 2)){ header("Location: ".$curdir."login.php"); + die(); }else{ if($loggedin == true){ $id = $_SESSION["id"]; @@ -49,7 +51,11 @@ if(!isset($liteload) && !$loggedin && $isadmin){ $sqlvals = $result->fetch_assoc(); $username = $sqlvals["username"]; $type = $sqlvals["type"]; - $connctdschids = explode(",", $sqlvals["connectedschoolids"]); + if($type == 2){ + $connctdcmps = explode(",", $sqlvals["connectedcompanyids"]); + }else{ + $connctdschids = explode(",", $sqlvals["connectedschoolids"]); + } $sql = "SELECT * FROM `acctypes` WHERE `id` = '".$type."'"; mysqli_free_result($result); $result = $conn->query($sql); @@ -77,32 +83,63 @@ if(!isset($liteload) && !$loggedin && $isadmin){ } } - for($i = 0; $iquery($viewsql); - if ($result == TRUE) { - if(!isset($_SESSION["selectedschool"])) { - $_SESSION["selectedschool"] = "s".$connctdschids[$i]; + if($type == 2){ + for($i = 0; $iquery($viewsql); + if ($result == TRUE) { + if(!isset($_SESSION["selectedcompany"])) { + $_SESSION["selectedcompany"] = "c".$connctdcmps[$i]; + } + if (empty($result) || $result->num_rows == 0) { + $modsql = "INSERT INTO `companies` (`id`, `name`, `type`, `spec`, `postalcode`, `location`, `locationspec`, `phonenumber`, `emailaddress`) VALUES ('".$connctdcmps[$i]."', '', '', '', '', '', '', '', '')"; + $conn->query($modsql); + } } - if (empty($result) || $result->num_rows == 0) { - $modsql = "INSERT INTO `schools` (`id`, `name`, `type`, `spec`, `postalcode`, `location`, `locationspec`, `phonenumber`, `email`) VALUES ('".$connctdschids[$i]."', '', '', '', '', '', '', '', '')"; - $conn->query($modsql); + } + }else{ + for($i = 0; $iquery($viewsql); + if ($result == TRUE) { + if(!isset($_SESSION["selectedschool"])) { + $_SESSION["selectedschool"] = "s".$connctdschids[$i]; + } + if (empty($result) || $result->num_rows == 0) { + $modsql = "INSERT INTO `schools` (`id`, `name`, `type`, `spec`, `postalcode`, `location`, `locationspec`, `phonenumber`, `emailaddress`) VALUES ('".$connctdschids[$i]."', '', '', '', '', '', '', '', '')"; + $conn->query($modsql); + } } } } mysqli_free_result($result); - $viewsql = "SELECT * FROM `schools` WHERE `id` = ".substr($_SESSION["selectedschool"], 1); - $result = $conn->query($viewsql); - if ($result == TRUE) { - if (!empty($result) && $result->num_rows > 0) { - $selschvals = $result->fetch_assoc(); + if($type == 2){ + $viewsql = "SELECT * FROM `companies` WHERE `id` = ".substr($_SESSION["selectedcompany"], 1); + $result = $conn->query($viewsql); + if ($result == TRUE) { + if (!empty($result) && $result->num_rows > 0) { + $selcomvals = $result->fetch_assoc(); + } + //else{ + //$modsql = "INSERT INTO `schools` (`id`, `name`, `type`, `spec`, `postalcode`, `location`, `locationspec`, `phonenumber`) VALUES ('".substr($_SESSION["selectedschool"], 1)."', '', '', '', '', '', '', '')"; + //$conn->query($modsql); + //header("Refresh:0"); + //} + } + }else{ + $viewsql = "SELECT * FROM `schools` WHERE `id` = ".substr($_SESSION["selectedschool"], 1); + $result = $conn->query($viewsql); + if ($result == TRUE) { + if (!empty($result) && $result->num_rows > 0) { + $selschvals = $result->fetch_assoc(); + } + //else{ + //$modsql = "INSERT INTO `schools` (`id`, `name`, `type`, `spec`, `postalcode`, `location`, `locationspec`, `phonenumber`) VALUES ('".substr($_SESSION["selectedschool"], 1)."', '', '', '', '', '', '', '')"; + //$conn->query($modsql); + //header("Refresh:0"); + //} } - //else{ - //$modsql = "INSERT INTO `schools` (`id`, `name`, `type`, `spec`, `postalcode`, `location`, `locationspec`, `phonenumber`) VALUES ('".substr($_SESSION["selectedschool"], 1)."', '', '', '', '', '', '', '')"; - //$conn->query($modsql); - //header("Refresh:0"); - //} } mysqli_free_result($result); }else{ @@ -279,37 +316,69 @@ if(!isset($liteload) && !$loggedin && $isadmin){ business @@ -358,7 +427,7 @@ if(!isset($liteload) && !$loggedin && $isadmin){