<?php
include("dbstuff.inc");
$cxn = mysql_connect($host,$user,$password,$database)
or die("Couldn't connect to server");
mysql_select_db($database);
session_start();
if(isset($SESSION['Login'])) {
$user=$SESSION['Login'];
$access = mysql_query("SELECT * FROM User WHERE username = '$user'");
if(mysql_num_rows($access)!=1){
header("Location: login.php?1");
} else {
$accessrow = mysql_fetch_row($access);
if($accessrow[8] != "on") {
header("Location: admincp.php?2");
}
}
} else {
header("Location: login.php?3");
}
if($_POST['formid'] != "true")
{
?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
<style type="text/css">
<!--
body {
background-color: #F4F4F4;
margin-left: 0px;
margin-top: 10px;
margin-right: 0px;
margin-bottom: 0px;
}
.style12 {
font-family: tahoma;
font-size: 11px;
font-weight: bold;
}
.style13 {font-size: 11px; color: #000000; font-family: tahoma;}
.style15 {
color: #CEEFFF;
font-size: 11px;
font-family: tahoma;
font-weight: bold;
}
.style16 {
font-size: 9px;
color: #F4F4F4;
}
.style19 {
font-family: tahoma;
font-size: 11px;
}
.style20 {font-family: tahoma; font-size: 11px; font-style: italic; }
-->
</style>
<script type="text/javascript">
<!--
function MM_preloadImages() { //v3.0
var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
if (a.indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a;}}
}
//-->
</script>
</head>
<form id="form" name="form" method="post" action="">
<body>
<div align="center">
<table width="760" border="0" cellspacing="0" cellpadding="0">
<tr>
<td><a href="http://www.lsrag.co.uk/frames/admincp.php" target="main"><img src="http://www.lsrag.co.uk/images/admin/addraidheader.jpg" border="0" /></a></td>
</tr>
<tr>
<td></td>
</tr>
</table>
<table width="760" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="760"><span class="style16">.</span></td>
</tr>
</table>
<table width="760" border="0" cellpadding="0" cellspacing="0">
<tr background="http://www.lsrag.co.uk/images/tables/title2.jpg">
<td width="10"> </td>
<td width="742"><div align="center"><span class="style12">Add Raid</span></div></td>
<td width="8"><img src="http://www.lsrag.co.uk/images/tables/title2.jpg" alt="" /></td>
</tr>
</table>
<table width="759" border="0" cellpadding="0" cellspacing="0" bgcolor="#FFFFFF">
<tr bgcolor="#FFFFFF" background="http://www.lsrag.co.uk/images/tables/background2.jpg">
<td width="9" background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
<td width="746" background="http://www.lsrag.co.uk/images/tables/background2.jpg" class="style13"><p><br />
This section of the Administration Control Panel allows you to add a new raid to the database.<br />
<br />
<strong> Raid Information</strong><br />
Please fill out all the fields of the form below with accurate information about the raid. You should not create raids unless you have authority to do so by the Chair, Vice Chair, Treasurer or Administrator.<br />
<br />
Any questions please email them to me!<br />
<br />
</p>
</td>
<td width="10" background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
</tr>
<tr bgcolor="#FFFFFF" class="style16" background="http://www.lsrag.co.uk/images/tables/background2.jpg">
<td> </td>
<td class="style13"> </td>
<td> </td>
</tr>
</table>
<table width="760" border="0" cellpadding="0" cellspacing="0">
<tr>
<td width="8" background="http://www.lsrag.co.uk/images/tables/background3.jpg"> </td>
<td colspan="6" background="http://www.lsrag.co.uk/images/tables/background3.jpg"><div align="center"><span class="style15">Add Raid Form</span></div> </td>
<td width="10" background="http://www.lsrag.co.uk/images/tables/background3.jpg"> </td>
</tr>
<tr>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
<td colspan="6" background="http://www.lsrag.co.uk/images/tables/background2.jpg" class="style12"><div align="center"><br />
Raid Information<br />
<br />
</div></td>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
</tr>
<tr>
<td bgcolor="#FFFFFF"> </td>
<td bgcolor="#FFFFFF"><span class="style19">Location</span></td>
<td colspan="5" bgcolor="#FFFFFF">
<?php
$query="SELECT locname,locid FROM Location ORDER BY locname ASC";
$result = mysql_query ($query);
?>
<select name=raidlocation>Raid Location
<option>-SELECT-</option>
<?php
while($nt=mysql_fetch_array($result)){//Array or records stored in $nt
echo "<option value=$nt[locname]>$nt[locname]</option>";
}
?>
</select>
<? if($accessrow[49] == "on")
echo '</span><span class="style12"> <a href="http://www.lsrag.co.uk/frames/addloc.php" target="main"><img border="0" src="http://www.lsrag.co.uk/images/admin/addicon.jpg"></a> <a href="http://www.lsrag.co.uk/frames/editloc.php" target="main"><img border="0" src="http://www.lsrag.co.uk/images/admin/editicon.jpg"></a></span></td>'; ?>
<td bgcolor="#FFFFFF"> </td>
</tr><tr>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"><span class="style19">Charity</span></td>
<td colspan="5" background="http://www.lsrag.co.uk/images/tables/background2.jpg">
<?php
$query="SELECT charityname,charityid FROM Charity ORDER BY charityname ASC";
$result = mysql_query ($query);
?>
<select name=charityname>Charity Name
<option>-SELECT1-</option>
<?php
while($nt=mysql_fetch_array($result)){//Array or records stored in $nt
echo "<option value=$nt[charityname]>$nt[charityname]</option>";
}
?>
</select>
<? if($accessrow[48] == "on") echo '</span><span class="style12"> <a href="http://www.lsrag.co.uk/frames/addcharity.php" target="main"><img border="0" src="http://www.lsrag.co.uk/images/admin/addicon.jpg"></a> <a href="http://www.lsrag.co.uk/frames/editcharity.php" target="main"><img border="0" src="http://www.lsrag.co.uk/images/admin/editicon.jpg"></a></span></td>'; ?>
<td background=" size="45"http://www.lsrag.co.uk/images/tables/background2.jpg">
</td>
</tr>
<tr>
<td bgcolor="#FFFFFF"> </td>
<td bgcolor="#FFFFFF"><span class="style19">Date</span></td>
<td colspan="5" bgcolor="#FFFFFF" class="style20"><input name="raidday" type="text" id="raidday" value="DD" size="2" maxlength="2" />
<span class="style19">/</span>
<input name="raidmonth" type="text" id="raidmonth" value="MM" size="2" maxlength="2" />
<span class="style19">/</span>
<input name="raidyear" type="text" id="raidyear" value="YYYY" size="4" maxlength="4" /></td>
<td bgcolor="#FFFFFF"> </td>
</tr>
<tr>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"><span class="style19">Description</span></td>
<td colspan="5" background="http://www.lsrag.co.uk/images/tables/background2.jpg"><textarea name="raiddescription" cols="45" rows="6" id="raiddescription"></textarea></td>
<td background="http://www.lsrag.co.uk/images/tables/background2.jpg"> </td>
</tr>
<tr>
<td colspan="8"><br><div align="center"><input type="hidden" name="formid" value="true" /><input type="submit" name="Step 2" id="submit" value="Add Raid" /> <span class="style19"><a href="http://www.lsrag.co.uk/frames/admincp.php" target="main"> Return to Admin CP</a> </div><br><br></td>
</tr>
</table>
</div></form>
</body>
</html>
?>
<?
}
else
{
$username=$SESSION['Login'];
$date=$POST["raidyear"]."-".$POST["raidmonth"]."-".$POST["raidday"];
$raidtitle = "".$POST["raidlocation"] ." - ".$POST["charityname"]."";
$raiddescription = "".$_POST["raiddescription"]."";
$sql = "INSERT INTO Event (Date,Type,Title,description,username) VALUES
('$date','Raid','$raidtitle','$raiddescription','$username')";
$result = mysql_query($sql);
$redirect=mysql_query("SELECT MAX(EntID) FROM Event");
$row = mysql_fetch_row($redirect);
header("Location: addraidstep2.php?EntID=$row[0]");
}
?>