fhiiqm/raum_ins.php
changeset 23 a382de56a8e4
parent 14 32203b8f40ee
child 24 15f33315f045
equal deleted inserted replaced
22:aae5b0ecc47b 23:a382de56a8e4
    95 //            echo "1realer filename: " . $_FILES["vfile"]["name"] . "<br><br>\n";
    95 //            echo "1realer filename: " . $_FILES["vfile"]["name"] . "<br><br>\n";
    96         //INSERT Raum
    96         //INSERT Raum
    97         $raum['rbez'] = substr($raum['rbez'],0,50);
    97         $raum['rbez'] = substr($raum['rbez'],0,50);
    98         $raum['rnum'] = substr($raum['rnum'],0,10);
    98         $raum['rnum'] = substr($raum['rnum'],0,10);
    99         if ($raum['rtyp']== -1) $rtyp = "NULL"; else $rtyp = "'" . $raum['rtyp'] . "'"; 
    99         if ($raum['rtyp']== -1) $rtyp = "NULL"; else $rtyp = "'" . $raum['rtyp'] . "'"; 
       
   100         if ($raum['reityp']== -1) $raum['reityp'] = null;
   100         // Filename Vertrag
   101         // Filename Vertrag
   101         $raum['rfname'] = substr($raum['rfname'],0,50);
   102         $raum['rfname'] = substr($raum['rfname'],0,50);
   102         if (isset($raum['rflae']) && $raum['rflae']>"0")
   103         if (isset($raum['rflae']) && $raum['rflae']>"0")
   103             $raum['rflae'] = str_replace(",",".",$raum['rflae']);
   104             $raum['rflae'] = str_replace(",",".",$raum['rflae']);
   104         else
   105         else
   122         // vermeiden von SQL-Injection
   123         // vermeiden von SQL-Injection
   123         $stmt = $dbc -> stmtinit();
   124         $stmt = $dbc -> stmtinit();
   124         if (is_object($stmt))
   125         if (is_object($stmt))
   125         {
   126         {
   126             if ($raum['rtyp']== -1) $raum['rtyp']=null;
   127             if ($raum['rtyp']== -1) $raum['rtyp']=null;
   127             $stmt -> prepare ("INSERT INTO Raum (raum_nr,raum_name,geb_ID,raumtyp_ID,raum_flaeche) VALUES (?,?,?,?,?)");
   128             $stmt -> prepare ("INSERT INTO Raum (raum_nr,raum_name,geb_ID,raumtyp_ID,reinigung_typ_ID,raum_flaeche) VALUES (?,?,?,?,?,?)");
   128             $stmt -> bind_param('ssssd', $raum['rnum'], $raum['rbez'], $raum['geb'], $raum['rtyp'], $raum['rflae']);
   129             $stmt -> bind_param('sssssd', $raum['rnum'], $raum['rbez'], $raum['geb'], $raum['rtyp'], $raum["reityp"], $raum['rflae']);
   129             $result = $stmt -> execute();      
   130             $result = $stmt -> execute();      
   130         }
   131         }
   131         if ($dbc->error) echo "error: " . $dbc->error . "<br><br>\n";
   132         if ($stmt->error) echo "error: " . $stmt->error . "<br><br>\n";
   132         if ($result)
   133         if ($result)
   133         { // INSERT o.k.
   134         { // INSERT o.k.
   134           // raum_ID ermitteln
   135           // raum_ID ermitteln
   135            $rid = $dbc -> insertId();
   136            $rid = $dbc -> insertId();
   136 
   137