include_once "includes/dbConnNew.php";
include_once "includes/loggedOnPop.php";
if($_POST['theAction'] == "addIt"){
$SQL = "INSERT INTO grocery_list (User_ID, Title) VALUES ('" . $_SESSION["sessionUserID"] . "' , '" . htmlentities($_POST['Item'], ENT_QUOTES) . "' )";
$result = mysql_query($SQL) or die(mysql_error());
}
if($_REQUEST['theAction'] == "delete"){
$SelectStr3 = "select grocery_list.ID from privacy,users,grocery_list where (privacy.deleted = 0) AND ((grocery_list.deleted = 0) AND ((privacy.friend_id = users.ID) and (grocery_list.User_ID = users.ID) and (privacy.user_id = '" . $_SESSION["sessionUserID"] . "' or privacy.friend_id = '" . $_SESSION["sessionUserID"] . "') and (privacy.grocery = 'Y') and (grocery_list.ID = '" . htmlentities($_REQUEST['Item_ID'], ENT_QUOTES) . "')))";
$result3 = mysql_query($SelectStr3) or die(mysql_error());
if($myrow3=MySQL_fetch_array($result3)){
$SQLd2 = "UPDATE grocery_list SET deleted = 1 WHERE ID = '" . htmlentities($_REQUEST['Item_ID'], ENT_QUOTES) . "' limit 1" ;
$result2 = mysql_query($SQLd2) or die(mysql_error());
} else {
$SQLd1 = "UPDATE grocery_list SET deleted = 1 WHERE User_ID = '" . $_SESSION["sessionUserID"] . "' AND ID = '" . htmlentities($_REQUEST['Item_ID'], ENT_QUOTES) . "' limit 1" ;
$result1 = mysql_query($SQLd1) or die(mysql_error());
}
}
if($_REQUEST['theAction'] == "buy"){
$SelectStr3 = "select grocery_list.ID from privacy,users,grocery_list where (privacy.deleted = 0) AND ((grocery_list.deleted = 0) AND ((privacy.friend_id = users.ID) and (grocery_list.User_ID = users.ID) and (privacy.user_id = '" . $_SESSION["sessionUserID"] . "' or privacy.friend_id = '" . $_SESSION["sessionUserID"] . "') and (privacy.grocery = 'Y') and (grocery_list.ID = '" . $_REQUEST['Item_ID'] . "')))";
$result3 = mysql_query($SelectStr3) or die(mysql_error());
if($myrow3=MySQL_fetch_array($result3)){
$SQLd = "UPDATE grocery_list SET Buy_It = 'Y' WHERE ID = '" . $_REQUEST['Item_ID'] . "'" ;
$result = mysql_query($SQLd) or die(mysql_error());
} else {
$SQLd = "UPDATE grocery_list SET Buy_It = 'Y' WHERE User_ID = '" . $_SESSION["sessionUserID"] . "' AND ID = '" . $_REQUEST['Item_ID'] . "'" ;
$result = mysql_query($SQLd) or die(mysql_error());
}
}
if($_REQUEST['theAction'] == "removeFromBuy"){
$SelectStr3 = "select grocery_list.ID from privacy,users,grocery_list where (privacy.deleted = 0) AND ((grocery_list.deleted = 0) AND ((privacy.friend_id = users.ID) and (grocery_list.User_ID = users.ID) and (privacy.user_id = '" . $_SESSION["sessionUserID"] . "' or privacy.friend_id = '" . $_SESSION["sessionUserID"] . "') and (privacy.grocery = 'Y') and (grocery_list.ID = '" . $_REQUEST['Item_ID'] . "')))";
$result3 = mysql_query($SelectStr3) or die(mysql_error());
if($myrow3=MySQL_fetch_array($result3)){
$SQLd = "UPDATE grocery_list SET Buy_It = ' ' WHERE ID = '" . $_REQUEST['Item_ID'] . "'" ;
$result = mysql_query($SQLd) or die(mysql_error());
} else {
$SQLd = "UPDATE grocery_list SET Buy_It = ' ' WHERE User_ID = '" . $_SESSION["sessionUserID"] . "' AND ID = '" . $_REQUEST['Item_ID'] . "'" ;
$result = mysql_query($SQLd) or die(mysql_error());
}
}
?>
Yada Home | Journal
include 'beforeEndHead.php'; ?>
 |
 |
 |
 |
include "topSignIn.php"; ?> |
 |
include "nav-new.php" ;?>
 |
 |
|
| |
|
| |
 |
| include "bottomLocalSearch.php"; ?> |
|
|
include "googAna.php"; ?>