changeset 23 | a382de56a8e4 |
parent 14 | 32203b8f40ee |
child 24 | 15f33315f045 |
22:aae5b0ecc47b | 23:a382de56a8e4 |
---|---|
95 // echo "1realer filename: " . $_FILES["vfile"]["name"] . "<br><br>\n"; |
95 // echo "1realer filename: " . $_FILES["vfile"]["name"] . "<br><br>\n"; |
96 //INSERT Raum |
96 //INSERT Raum |
97 $raum['rbez'] = substr($raum['rbez'],0,50); |
97 $raum['rbez'] = substr($raum['rbez'],0,50); |
98 $raum['rnum'] = substr($raum['rnum'],0,10); |
98 $raum['rnum'] = substr($raum['rnum'],0,10); |
99 if ($raum['rtyp']== -1) $rtyp = "NULL"; else $rtyp = "'" . $raum['rtyp'] . "'"; |
99 if ($raum['rtyp']== -1) $rtyp = "NULL"; else $rtyp = "'" . $raum['rtyp'] . "'"; |
100 if ($raum['reityp']== -1) $raum['reityp'] = null; |
|
100 // Filename Vertrag |
101 // Filename Vertrag |
101 $raum['rfname'] = substr($raum['rfname'],0,50); |
102 $raum['rfname'] = substr($raum['rfname'],0,50); |
102 if (isset($raum['rflae']) && $raum['rflae']>"0") |
103 if (isset($raum['rflae']) && $raum['rflae']>"0") |
103 $raum['rflae'] = str_replace(",",".",$raum['rflae']); |
104 $raum['rflae'] = str_replace(",",".",$raum['rflae']); |
104 else |
105 else |
122 // vermeiden von SQL-Injection |
123 // vermeiden von SQL-Injection |
123 $stmt = $dbc -> stmtinit(); |
124 $stmt = $dbc -> stmtinit(); |
124 if (is_object($stmt)) |
125 if (is_object($stmt)) |
125 { |
126 { |
126 if ($raum['rtyp']== -1) $raum['rtyp']=null; |
127 if ($raum['rtyp']== -1) $raum['rtyp']=null; |
127 $stmt -> prepare ("INSERT INTO Raum (raum_nr,raum_name,geb_ID,raumtyp_ID,raum_flaeche) VALUES (?,?,?,?,?)"); |
128 $stmt -> prepare ("INSERT INTO Raum (raum_nr,raum_name,geb_ID,raumtyp_ID,reinigung_typ_ID,raum_flaeche) VALUES (?,?,?,?,?,?)"); |
128 $stmt -> bind_param('ssssd', $raum['rnum'], $raum['rbez'], $raum['geb'], $raum['rtyp'], $raum['rflae']); |
129 $stmt -> bind_param('sssssd', $raum['rnum'], $raum['rbez'], $raum['geb'], $raum['rtyp'], $raum["reityp"], $raum['rflae']); |
129 $result = $stmt -> execute(); |
130 $result = $stmt -> execute(); |
130 } |
131 } |
131 if ($dbc->error) echo "error: " . $dbc->error . "<br><br>\n"; |
132 if ($stmt->error) echo "error: " . $stmt->error . "<br><br>\n"; |
132 if ($result) |
133 if ($result) |
133 { // INSERT o.k. |
134 { // INSERT o.k. |
134 // raum_ID ermitteln |
135 // raum_ID ermitteln |
135 $rid = $dbc -> insertId(); |
136 $rid = $dbc -> insertId(); |
136 |
137 |