代码拉取完成,页面将自动刷新
<?php
// check the input 原drug.php更名为add_delete_pre.php 医生开删处方和Diagnosis
function check($value)
{
if (get_magic_quotes_gpc()) {
$value = htmlspecialchars(trim($value));
} else {
$value = addslashes(htmlspecialchars(trim($value)));
}
return $value;
}
session_start();
if (!isset($_SESSION['username']) or !isset($_SESSION['identity']) or $_SESSION['identity'] != 1) {
header("Location:login.php");
exit();
}
$username = check($_POST['Pno']);
$Sno=check($_POST['Sno']);
$DrugNo = check($_POST['DrugNo']);
$DrugNum = check($_POST['DrugNum']);
$Diagnosis = check($_POST['Diagnosis']);
$operation = $_POST['operation_choice'];
if ($operation == 1) { // modify
if ($username == "" || $DrugNo == "" || $DrugNum == "" || $Sno == "" || $Diagnosis == "" ) {
echo "
<script>
alert('处方信息不完整!!');
window.location.href = 'doctor_pre.php';
</script>
";
exit();
} else {
$db = @mysqli_connect("localhost", "root", "123456", "MIS");
if (!$db) {
die("Fail to connect the database!!" . mysqli_connect_error());
}
mysqli_query($db, "begin");
mysqli_query($db, "set names utf8");
$check_pre = mysqli_query($db, "SELECT * FROM Prescription WHERE Pno='$username' AND Sno='$Sno' for update");
$check_mdrecord = mysqli_query($db, "SELECT * FROM MedicalRecord WHERE Pno='$username' AND Sno='$Sno' for update");
if (mysqli_fetch_array($check_pre) && mysqli_fetch_array($check_mdrecord)) {
$result1 = mysqli_query($db, "UPDATE Prescription SET DrugNo='$DrugNo', DrugNum='$DrugNum' WHERE Pno='$username' AND Sno='$Sno'");
$result2 = mysqli_query($db, "UPDATE MedicalRecord SET Diagnosis='$Diagnosis' WHERE Pno='$username' AND Sno='$Sno'");
if ($result1 && $result2) {
mysqli_query($db, "commit");
mysqli_close($db);
echo "
<script>
alert('处方添加成功!!');
window.location.href = 'doctor_pre.php';
</script>
";
exit();
} else {
echo '添加失败!!', mysqli_error($db), '<br />';
echo 'Click here to <a href="javascript:history.back(-1);">go back</a> and retry..';
mysqli_query($db, "rollback");
mysqli_close($db);
exit();
}
} else {
mysqli_query($db, "commit");
mysqli_close($db);
echo "
<script>
alert('该患者并未预约!!');
window.location.href = 'doctor_pre.php';
</script>
";
exit();
}
}
} elseif ($operation == -1) { // wipe
if ($Sno == "" || $username == "") {
echo "
<script>
alert('信息不能为空!!');
window.location.href = 'doctor_pre.php';
</script>
";
exit();
} else {
$db = @mysqli_connect("localhost", "root", "123456", "MIS");
if (!$db) {
die("Fail to connect the database!!" . mysqli_connect_error());
}
mysqli_query($db, "begin");
mysqli_query($db, "set names utf8");
$check_mdrecord = mysqli_query($db, "SELECT * FROM MedicalRecord WHERE Pno='$username' AND Sno='$Sno' for update");
$check_pre = mysqli_query($db, "SELECT * FROM Prescription WHERE Pno='$username' AND Sno='$Sno' for update");
if (mysqli_fetch_array($check_pre) && mysqli_fetch_array($check_mdrecord)) {
$result1 = mysqli_query($db, "UPDATE Prescription SET DrugNo=NULL, DrugNum=NULL WHERE Pno='$username' AND Sno='$Sno'");
$result2 = mysqli_query($db, "UPDATE MedicalRecord SET Diagnosis=NULL WHERE Pno='$username' AND Sno='$Sno'");
if ($result1 && $result2) {
mysqli_query($db, "commit");
mysqli_close($db);
echo "
<script>
alert('处方信息成功清除!!');
window.location.href = 'doctor_pre.php';
</script>
";
exit();
} else {
echo '清除失败!!', mysqli_error($db), '<br />';
echo 'Click here to <a href="javascript:history.back(-1);">go back</a> and retry..';
mysqli_query($db, "rollback");
mysqli_close($db);
exit();
}
} else {
mysqli_query($db, "commit");
mysqli_close($db);
echo "
<script>
alert('该预约记录不存在!!');
window.location.href = 'doctor_pre.php';
</script>
";
exit();
}
}
}
?>
此处可能存在不合适展示的内容,页面不予展示。您可通过相关编辑功能自查并修改。
如您确认内容无涉及 不当用语 / 纯广告导流 / 暴力 / 低俗色情 / 侵权 / 盗版 / 虚假 / 无价值内容或违法国家有关法律法规的内容,可点击提交进行申诉,我们将尽快为您处理。