Просмотр файла orf.php

Размер файла: 2.03Kb
  1. <?php
  2. include 'inc/db.php';
  3. include 'inc/1.php';
  4. if (!$_GET['id'])header("Location: /obmen.php");
  5. $id=intval($_GET['id']);
  6. $a=mysql_query("SELECT * FROM `obmen` WHERE `razdel` = '$id' ORDER BY `id` DESC");
  7. if ($_GET['delete'] && ($user['admin']==1)){
  8. $del=intval($_GET['delete']);
  9. mysql_query("DELETE FROM `obmen` WHERE `id` = '$del'");
  10. header("Location: /orf.php?id=$id");
  11. }
  12. if ($_GET['edit'] && ($user['admin']==1)){
  13. if (!$_POST['eok']){
  14. $n=mysql_query("SELECT * FROM `obmen_t` WHERE `id` = '$id'");
  15. $e=mysql_fetch_assoc($n);
  16. echo "<form action='?edit=1&id=$id' method='POST'>Имя:<br><input type='text' name='ename' value='".htmlspecialchars($e['name'])."'><br>Описание:<br><textarea name='emsg'>".htmlspecialchars($e['opis'])."</textarea><br><input type='submit' name='eok' value='Изменить'></form>";
  17. include_once 'inc/foot.php';
  18. exit;
  19. }
  20. elseif ($_POST['eok'] && $_POST['ename'])
  21. {
  22. $name=mysql_escape_string($_POST['ename']);
  23. $msg=mysql_escape_string($_POST['emsg']);
  24. mysql_query("UPDATE `obmen_t` SET `name` = '$name', `opis` = '$msg' WHERE `id` = '$id'");
  25. echo "<div class='msg'>Изменено</div>";
  26. }
  27. }
  28. echo "<div class='p0'><a href='onewf.php?id=$id'>Выгрузить файл</a>";
  29. if ($user['admin']==1)echo " | <a href='?id=$id&edit=1'>Изменить</a>";
  30. echo "</div>";
  31. if (mysql_num_rows($a)==0)echo "<div class='p1'>Файлов нет!</div>";
  32. $b=1;
  33. while ($f=mysql_fetch_assoc($a)){
  34. $o=($b%2);
  35. $ank=mysql_fetch_assoc(mysql_query("SELECT * FROM `user` WHERE `id` = '$f[user]'"));
  36. echo "<div class='p$o'>- <a href='file.php?id=$f[id]'>".htmlspecialchars($f['name']).".".htmlspecialchars($f['ras'])."</a>";
  37. //if ($user['admin']==1)echo " <a href='?id=$id&delete=$f[id]'>[<font color='red'>x</font> удал]</a>";
  38. echo "<br>$ank[name] (".vremja($f['time']).")</div>";
  39. $b++;
  40. }
  41. $rf=mysql_fetch_assoc(mysql_query("SELECT * FROM `obmen_t` WHERE `id` = '$id'"));
  42. echo "<div class='p0'><a href='orazdel.php?id=$rf[razdel]'>".htmlspecialchars($rf['name'])."</a></div>";
  43. include_once 'inc/foot.php';
  44. ?>