加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
文件
该仓库未声明开源许可证文件(LICENSE),使用请关注具体项目描述及其代码上游依赖。
克隆/下载
private.php 3.45 KB
一键复制 编辑 原始数据 按行查看 历史
wenxin lai 提交于 2022-05-30 02:40 . update private.php.
<?php
// check the input
function check($value)
{
if (get_magic_quotes_gpc()) {
$value = htmlspecialchars(trim($value));
} else {
$value = addslashes(htmlspecialchars(trim($value)));
}
return $value;
}
session_start();
if (!isset($_SESSION['username']) or !isset($_SESSION['identity']) or ($_SESSION['identity'] != 0 && $_SESSION['identity'] != 1)) {
header("Location:login.php");
exit();
}
$username = $_SESSION['username'];
$name = check($_POST['name']);
if (isset($_POST['Pid'])) {
$pid = check($_POST['Pid']);
}
if (isset($_POST['PtelNo'])) {
$ptelno = check($_POST['PtelNo']);
}
if (isset($_POST['PmedicareCard'])) {
$pmcard = check($_POST['PmedicareCard']);
}
if (isset($_POST['Dtitle'])) {
$dtitle = check($_POST['Dtitle']);
}
if (isset($_POST['Department'])) {
$department = check($_POST['Department']);
}
if ($_SESSION['identity'] == 0) { // patient
if ($pid != "" || strlen($pid) != 18 ) {
echo "
<script>
alert('身份证号有误!!');
window.location.href = 'patient_patient.php';
</script>
";
exit();
}
if ( strlen($ptelno) != 11) {
echo "
<script>
alert('手机号需为11位!!');
window.location.href = 'patient_patient.php';
</script>
";
exit();
}
$db = @mysqli_connect("localhost", "root", "123456", "MIS");
if (!$db) {
die("Fail to connect the database!!" . mysqli_connect_error());
}
mysqli_query($db, "begin");
mysqli_query($db, "set names utf8");
$result1 = mysqli_query($db, "UPDATE Patient SET Pname='$name', Pid='$pid', PtelNo='$ptelno',
PmedicareCard='$pmcard' WHERE Pno='$username'");
$result2 = mysqli_query($db, "UPDATE User SET name='$name' WHERE username='$username'");
if ($result1 && $result2) {
mysqli_query($db, "commit");
mysqli_close($db);
echo "
<script>
alert('个人信息保存成功!!');
window.location.href = 'patient_patient.php';
</script>
";
exit();
} else {
echo '保存失败!!', mysqli_error($db), '<br />';
echo 'Click here to <a href="javascript:history.back(-1);">go back</a> and retry..';
mysqli_query($db, "rollback");
mysqli_close($db);
exit();
}
} elseif ($_SESSION['identity'] == 1) { // doctor
$db = @mysqli_connect("localhost", "root", "123456", "MIS");
if (!$db) {
die("Fail to connect the database!!" . mysqli_connect_error());
}
mysqli_query($db, "begin");
mysqli_query($db, "set names utf8");
$result1 = mysqli_query($db, "UPDATE Doctor SET Dname='$name', Department='$department', Dtitle='$dtitle' WHERE Dno='$username'");
$result2 = mysqli_query($db, "UPDATE User SET name='$name' WHERE username='$username'");
if ($result1 && $result2) {
mysqli_query($db, "commit");
mysqli_close($db);
echo "
<script>
alert('个人信息保存成功!!');
window.location.href = 'doctor_doctor.php';
</script>
";
exit();
} else {
echo '保存失败!!', mysqli_error($db), '<br />';
echo 'Click here to <a href="javascript:history.back(-1);">go back</a> and retry..';
mysqli_query($db, "rollback");
mysqli_close($db);
exit();
}
}
?>
Loading...
马建仓 AI 助手
尝试更多
代码解读
代码找茬
代码优化