Guest User

Untitled

a guest
Jan 31st, 2019
102
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.46 KB | None | 0 0
  1. else if($method=='add'){
  2. //echo $_FILES["image"]["name"];
  3. //echo $_FILES["image"]["type"];
  4.  
  5. if($_FILES["image"]["size"] > 1024*3*1024 OR $_FILES["filename"]["size"] > 1024*3*1024){
  6. echo ("Error 1");
  7. exit;
  8. }
  9.  
  10. if($_FILES['image']['type'] != "image/gif" AND $_FILES['image']['type'] != "image/jpeg" AND $_FILES['image']['type'] != "image/png") {
  11. echo "Error 2";
  12. exit;
  13. }
  14. $allowed_ext = array('doc','docx','pdf','xlsx','txt');
  15. $ext = pathinfo($_FILES["filename"]["name"], PATHINFO_EXTENSION);
  16. $name = $_FILES["filename"]["name"];
  17. $nameeq = getCheck($_POST['nameeq'],'text');
  18. $inv = getCheck($_POST['inv'],'int');
  19. $desc = getCheck($_POST['desc'],'text');
  20. if($nameeq!=''AND $inv!=''AND $desc!=''){
  21. $query = mysql_query('
  22. SELECT * FROM `equipment`
  23. (`name_equipment`,`inv_number`,`description`)
  24. VALUES
  25. ("'.$nameeq.'","'.$inv.'","'.$desc.'",1,NOW())
  26. ');
  27.  
  28. if(is_uploaded_file($_FILES["image"]["tmp_name"])){
  29. $ext = explode('.', $_FILES["image"]["name"]);
  30. $ext = array_pop($ext);
  31. $query= mysql_query('SELECT LAST_INSERT_ID()');
  32. $row = mysql_fetch_array($query);
  33. $id = $row[0];
  34. move_uploaded_file($_FILES["image"]["tmp_name"], "../archive/".$_FILES["image"]["name"]);
  35.  
  36. exit ( '<meta http-equiv="refresh" content="0;URL=../page/add/" />');
  37.  
  38. }
  39. else if(in_array($ext,$allowed_ext)){
  40. $newfilename = crc32($name.date("H:i:s")).$go;
  41. $bdfilename = $newfilename.".".$ext;
  42. $newfilename = '../archive/Doc/'.$newfilename.".".$ext;
  43. move_uploaded_file($_FILES["filename"]["tmp_name"], $ext);
  44. }
  45. else {
  46. exit("Недопустимый формат файлов");
  47. }
  48.  
  49. }
  50. else {
  51. exit ( 'Error 3'); `
  52.  
  53. function getConect(){
  54. $server = "localhost";
  55. $database = "work_log";
  56. $username = "user2018";
  57. $password = "user20182019";
  58. $connect = mysql_connect($server,$username,$password);
  59. $link = mysql_select_db($database) or die("Error!");
  60. mysql_query('SET NAMES utf8', $connect);
  61. return $connect;
  62. }
Add Comment
Please, Sign In to add comment