Browse Source

more session fun

development
mauirixxx 8 years ago
parent
commit
141074eb99
2 changed files with 5 additions and 3 deletions
  1. +2
    -2
      gw-action.php
  2. +3
    -1
      gw-pull.php

+ 2
- 2
gw-action.php View File

@@ -1,12 +1,12 @@
<?php <?php
session_start(); session_start();
$playerid = $_SESSION['playerid']; $playerid = $_SESSION['playerid'];
$toonid = $_POST['playerid'];
//$toonid = $_POST['playerid'];
$action = $_POST['gwaction']; $action = $_POST['gwaction'];
echo'<TITLE>Redirecting ...</TITLE>'; echo'<TITLE>Redirecting ...</TITLE>';
if ($action == 1){ //insert dropped items data if ($action == 1){ //insert dropped items data
echo '<BODY onload="document.record.submit()">'; echo '<BODY onload="document.record.submit()">';
echo '<FORM METHOD="POST" ACTION="gw-location.php" NAME="record"><INPUT TYPE="HIDDEN" NAME="playerid" VALUE="'. $toonid . '"><INPUT TYPE="SUBMIT" ID="clkRecord"></FORM></BODY>';
echo '<FORM METHOD="POST" ACTION="gw-location.php" NAME="record"><INPUT TYPE="HIDDEN" NAME="playerid" VALUE="'. $playerid . '"><INPUT TYPE="SUBMIT" ID="clkRecord"></FORM></BODY>';
} else if ($action == 2){ //view history of dropped items } else if ($action == 2){ //view history of dropped items
echo '<BODY onload="document.insert.submit()">'; echo '<BODY onload="document.insert.submit()">';
echo '<FORM METHOD="POST" ACTION="gw-pull.php" NAME="insert"><INPUT TYPE="HIDDEN" NAME="cnameid" VALUE="' . $playerid . '"><INPUT TYPE="SUBMIT" ID="clkInsert"></FORM></BODY>'; echo '<FORM METHOD="POST" ACTION="gw-pull.php" NAME="insert"><INPUT TYPE="HIDDEN" NAME="cnameid" VALUE="' . $playerid . '"><INPUT TYPE="SUBMIT" ID="clkInsert"></FORM></BODY>';


+ 3
- 1
gw-pull.php View File

@@ -1,9 +1,11 @@
<TITLE>Treasure Data</TITLE> <TITLE>Treasure Data</TITLE>
<BODY> <BODY>
<?php <?php
session_start();
include_once 'gw-connect.php'; include_once 'gw-connect.php';
$con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME);
$cnameid = mysqli_real_escape_string($con, $_POST['cnameid']); //need to sanitize & validate this input somehow
//$cnameid = mysqli_real_escape_string($con, $_POST['cnameid']); //need to sanitize & validate this input somehow
$cnameid = $_SESSION['playerid'];
if ($con->connect_errno > 0){ if ($con->connect_errno > 0){
die ('Unable to connect to database [' . $db->connect_errno . ']'); die ('Unable to connect to database [' . $db->connect_errno . ']');
} }


Loading…
Cancel
Save