| @@ -3,10 +3,10 @@ $toonid = $_POST['playerid']; | |||||
| $action = $_POST['gwaction']; | $action = $_POST['gwaction']; | ||||
| if ($action == 1){ | if ($action == 1){ | ||||
| echo '<body onload="javascript:submitForm()">'; | echo '<body onload="javascript:submitForm()">'; | ||||
| echo '<FORM METHOD="POST" ACTION="gw-record.php" NAME="record"><INPUT TYPE="HIDDEN" NAME="playerid" VALUE="'. $toonid . '"><INPUT TYPE="SUBMIT" ID="clkRecord"></FORM>'; | |||||
| echo '<FORM METHOD="POST" ACTION="gw-record.php" NAME="record"><INPUT TYPE="HIDDEN" NAME="playerid" VALUE="'. $toonid . '"><INPUT TYPE="SUBMIT" ID="clkRecord"></FORM></BODY>'; | |||||
| } else if ($action == 2){ | } else if ($action == 2){ | ||||
| echo '<body onload="javascript:submitForm()">'; | echo '<body onload="javascript:submitForm()">'; | ||||
| echo '<FORM METHOD="POST" ACTION="gw-pull.php" NAME="insert"><INPUT TYPE="HIDDEN" NAME="cname" VALUE="' . $toonid . '"><INPUT TYPE="SUBMIT" ID="clkInsert"></FORM>'; | |||||
| echo '<FORM METHOD="POST" ACTION="gw-pull.php" NAME="insert"><INPUT TYPE="HIDDEN" NAME="cname" VALUE="' . $toonid . '"><INPUT TYPE="SUBMIT" ID="clkInsert"></FORM></BODY>'; | |||||
| } else { | } else { | ||||
| echo 'You shouldn\'t be seeing this, something went horribly horribly wrong!'; | echo 'You shouldn\'t be seeing this, something went horribly horribly wrong!'; | ||||
| } | } | ||||
| @@ -3,7 +3,7 @@ | |||||
| <?php | <?php | ||||
| include_once 'gw-connect.php'; | include_once 'gw-connect.php'; | ||||
| $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); | $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); | ||||
| $cnameid = mysqli_real_escape_string($con, $_POST['cname']); //need to sanitize & validate this input somehow | |||||
| $cnameid = mysqli_real_escape_string($con, $_POST['cnameid']); //need to sanitize & validate this input somehow | |||||
| if ($con->connect_errno > 0){ | if ($con->connect_errno > 0){ | ||||
| die ('Unable to connect to database [' . $db->connect_errno . ']'); | die ('Unable to connect to database [' . $db->connect_errno . ']'); | ||||
| } | } | ||||
| @@ -2,8 +2,8 @@ | |||||
| <?php | <?php | ||||
| include_once 'gw-connect.php'; | include_once 'gw-connect.php'; | ||||
| $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); | $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); | ||||
| #$toonid = mysqli_real_escape_string($con, $_POST['playerid']); //enable this after character selection is working | |||||
| $toonid = '3'; //delete this line after character selection is finished/working | |||||
| $toonid = mysqli_real_escape_string($con, $_POST['playerid']); //enable this after character selection is working | |||||
| //$toonid = '3'; //delete this line after character selection is finished/working | |||||
| #$location = mysqli_real_escape_string($con, $_POST['locationid']); //enable this after location selection is working | #$location = mysqli_real_escape_string($con, $_POST['locationid']); //enable this after location selection is working | ||||
| $location = 4; //delete this line after location selection is finished/working | $location = 4; //delete this line after location selection is finished/working | ||||
| $whatdropped = mysqli_real_escape_string($con, $_POST['gwdrop']); | $whatdropped = mysqli_real_escape_string($con, $_POST['gwdrop']); | ||||
| @@ -2,7 +2,13 @@ | |||||
| include_once 'gw-connect.php'; | include_once 'gw-connect.php'; | ||||
| $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); | $con = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASS, DATABASE_NAME); | ||||
| $userid = 1; //need to actually pull this info from cookie/session (preferable) | $userid = 1; //need to actually pull this info from cookie/session (preferable) | ||||
| $whattoon = mysqli_real_escape_string($con, $_POST['cname']); | |||||
| $whattoon = mysqli_real_escape_string($con, $_POST['cnameid']); | |||||
| $nameoftoon = mysqli_real_escape_string($con, $_POST['charactername']); | |||||
| if ($toonid == ""){ | |||||
| echo '<TITLE>Choose a character!</TITLE><BODY>'; | |||||
| } else { | |||||
| echo '<TITLE>' . $nameoftoon . '</TITLE></BODY>"'; | |||||
| } | |||||
| if ($con->connect_errno > 0){ | if ($con->connect_errno > 0){ | ||||
| die ('Unable to connect to database [' . $db->connect_errno . ']'); | die ('Unable to connect to database [' . $db->connect_errno . ']'); | ||||
| } | } | ||||
| @@ -18,13 +24,14 @@ if ($whattoon == "0"){ | |||||
| $charid = $row['playerid']; | $charid = $row['playerid']; | ||||
| $charname = $row['charname']; | $charname = $row['charname']; | ||||
| echo '<OPTION VALUE="' . $charid . '">' . $charname . '</OPTION>'; | echo '<OPTION VALUE="' . $charid . '">' . $charname . '</OPTION>'; | ||||
| echo '<INPUT TYPE="HIDDEN" NAME="charactername" VALUE="' . $charname . '">'; | |||||
| } | } | ||||
| echo '</SELECT><NOSCRIPT><INPUT TYPE="SUBMIT" VALUE="Choose Toon"></NOSCRIPT></FORM></CENTER>'; | echo '</SELECT><NOSCRIPT><INPUT TYPE="SUBMIT" VALUE="Choose Toon"></NOSCRIPT></FORM></CENTER>'; | ||||
| } else { | } else { | ||||
| echo '<CENTER><FORM METHOD="POST" ACTION="gw-action.php">'; | echo '<CENTER><FORM METHOD="POST" ACTION="gw-action.php">'; | ||||
| echo '<INPUT TYPE="HIDDEN" NAME="playerid" VALUE=' . $whattoon . '">'; | echo '<INPUT TYPE="HIDDEN" NAME="playerid" VALUE=' . $whattoon . '">'; | ||||
| echo '<FIELDSET CLASS="radiogroup"><LEGEND>Select your course of action</LEGEND><UL CLASS="radio">'; | echo '<FIELDSET CLASS="radiogroup"><LEGEND>Select your course of action</LEGEND><UL CLASS="radio">'; | ||||
| echo '<LI style="text-align:left;">><INPUT TYPE="RADIO" NAME="gwaction" VALUE="1">Record loot info</LI><LI style="text-align:left;">><INPUT TYPE="RADIO" NAME="gwaction" VALUE="2">View Character loot history</LI></UL></FIELDSET>'; | |||||
| echo '<INPUT TYPE="SUBMIT" VALUE="Choose action"></FORM><BR /><BR /><FORM METHOD="POST" ACTION="gw-toon.php"><INPUT TYPE="HIDDEN" NAME="cname" VALUE="0"><INPUT TYPE="SUBMIT" VALUE="Return to character selection"></FORM></CENTER>'; | |||||
| echo '<LI style="text-align:left;"><INPUT TYPE="RADIO" NAME="gwaction" VALUE="1">Record loot info</LI><LI style="text-align:left;"><INPUT TYPE="RADIO" NAME="gwaction" VALUE="2">View Character loot history</LI></UL></FIELDSET>'; | |||||
| echo '<INPUT TYPE="SUBMIT" VALUE="Choose action"></FORM><BR /><BR /><FORM METHOD="POST" ACTION="gw-toon.php"><INPUT TYPE="HIDDEN" NAME="cnameid" VALUE="0"><INPUT TYPE="SUBMIT" VALUE="Return to character selection"></FORM></CENTER>'; | |||||
| } | } | ||||
| ?> | ?> | ||||