-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsubmitForm.php
More file actions
59 lines (50 loc) · 1.91 KB
/
Copy pathsubmitForm.php
File metadata and controls
59 lines (50 loc) · 1.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
<?php
session_start();
$con = mysqli_connect("localhost", "root", "", "escape_room");
$first_name = mysqli_real_escape_string($con, $_POST["first_name"]);
$last_name = mysqli_real_escape_string($con, $_POST["last_name"]);
$phone_number = mysqli_real_escape_string($con, $_POST["phone_number"]);
$email = mysqli_real_escape_string($con, $_POST["email"]);
$comment = mysqli_real_escape_string($con, $_POST["comment"]);
$room_id = mysqli_real_escape_string($con, $_POST["room"]);
$date = mysqli_real_escape_string($con, $_POST["date"]);
$time = mysqli_real_escape_string($con, $_POST["time"]);
$players = mysqli_real_escape_string($con, $_POST["players"]);
$sql = "SELECT id
FROM reservation
WHERE room_id = '$room_id'
AND reservation_date = '$date'
AND reservation_time = '$time'";
mysqli_set_charset($con, 'utf8mb4');
$result = mysqli_query($con, $sql);
if(!empty($_POST["token"])){
if(mysqli_num_rows($result)== 0 && hash_equals($_SESSION["token"], $_POST["token"])){
$price_total = $price = $extra_cost = 0;
$players = intval($players);
$sql = "SELECT price, extra_cost
FROM room
WHERE id = $room_id";
$result = mysqli_query($con, $sql);
while($row = mysqli_fetch_assoc($result)){
$price = intval($row["price"]);
$extra_cost = intval($row["extra_cost"]);
}
if($players>6){
$price_total = $price + $extra_cost * (intval($players) - 6);
}
else{
$price_total = $price;
}
$sql = "INSERT INTO reservation(first_name, last_name, phone_num, email_addr, comment, room_id, reservation_date, reservation_time, player_count, price)
VALUES ('$first_name', '$last_name', '$phone_number', '$email', '$comment', '$room_id', '$date', '$time', '$players', '$price_total')";
mysqli_query($con, $sql);
echo "1"; //viskas gerai
}
else{
echo "2"; //tokenas nelygus arba yra tokiu pat laiku
}
}
else{
echo "3"; //tokeno nera
}
?>