Advertisement
Guest User

Untitled

a guest
Mar 11th, 2017
84
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.43 KB | None | 0 0
  1. <?php
  2. session_start();
  3.  
  4. $userno = $_SESSION['userno'];
  5. $rate = $_POST['rate'];
  6. $comment = $_POST['comment'];
  7. $reviewno = $_POST['reviewno'];
  8.  
  9. $host = "localhost";
  10. $user = "root";
  11. $pass = "";
  12.  
  13. $DBConnect = @mysqli_connect($host, $user, $pass, 'hotel') or die('Incorrect values.');
  14.  
  15. $numberquery = "SELECT * FROM member WHERE userNo = '$userno'";
  16. $res = mysqli_query($DBConnect, $numberquery);
  17. $rows = mysqli_num_rows($res);
  18. if(mysqli_fetch_assoc($res) != NULL){
  19. $numquery = "SELECT * FROM member WHERE userNo = '$userno'";
  20. $r = mysqli_query($DBConnect, $numquery);
  21. $row = mysqli_fetch_assoc($r);
  22. $memno = $row['memNo'];
  23.  
  24. $query = "SELECT * FROM review WHERE reviewNo = '$reviewno'";
  25. $result = mysqli_query($DBConnect, $query);
  26. $numrows = mysqli_num_rows($result);
  27.  
  28. if ($numrows > 0){
  29. echo '<p align="center"><font size="+2" color="red">Sorry, cannot add review. The Member ID already exists.</font></p>';
  30. echo '<p align="center"><font size="+2"><a href="accomodations.php">Please enter another one.</a></font></p>';
  31. echo '<br><br>';
  32. }
  33.  
  34. if ($numrows == 0){
  35. $SQLqueryAdd = "INSERT INTO review VALUES('$reviewno','$memno','$rate','$comment')";
  36. mysqli_query($DBConnect, $SQLqueryAdd);
  37. echo '<p><font size="+2">Thank you for rating us!</font></p>';
  38. }
  39. }
  40. else{
  41. echo "Error: User ID not found. Only members can give a rating/review.";
  42. }
  43.  
  44. mysqli_close($DBConnect);
  45. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement