connect_error) die($connection->connect_error); $accountNum=$_COOKIE['cookie_account']; $query="SELECT*FROM bank WHERE accountNum=$accountNum"; $result=$connection->query($query); if (!$result) die ($connection->error); $display=$result->fetch_array(MYSQLI_ASSOC); //deposit if (isset($_POST['deposit'])){ $deposit=sanitizeString($_POST['deposit']); if ($deposit<0){ die("deposit can't be lower than 0"); } $newMoney=$display['money']+$deposit; $query="BEGIN"; $connection->query($query); $query="UPDATE bank SET money=$newMoney WHERE accountNum=$accountNum"; $connection->query($query); $query="COMMIT"; $connection->query($query); $_POST['deposit']=0; //if you deposited money and then refreshed it deposited it again $_POST['withdraw']=NULL; } if (isset($_POST['withdraw'])){ $withdraw=sanitizeString($_POST['withdraw']); if ($withdraw<0){ die("withdraw can't be lower than 0"); } $newMoney=$display['money']-$withdraw; $query="BEGIN"; $connection->query($query); $query="UPDATE bank SET money=$newMoney WHERE accountNum=$accountNum"; $connection->query($query); $query="COMMIT"; $connection->query($query); $_POST['withdraw']=0; //if you withdrew money and then refreshed it deposited it again $_POST['deposit']=NULL; } $query="SELECT*FROM bank WHERE accountNum=$accountNum"; $result=$connection->query($query); if (!$result) die ($connection->error); $display=$result->fetch_array(MYSQLI_ASSOC); //display the name and everthing echo "Account Number: ".$display['accountNum']."
"; echo "Name: ".$display['firstName']."
"; echo "LastName: ".$display['lastName']."
"; echo "Money: ".$display['money']."
"; echo <<<_END

Deposit:
Withdraw:
_END; $result->close(); $connection->close(); function sanitizeString($string) {//gets rid of some html signs return htmlentities(mysql_fix_string($string)); } function mysql_fix_string($string) { if (get_magic_quotes_gpc()) $string = stripslashes($string); return $string; } ?>