-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathedit.php
169 lines (155 loc) · 6.79 KB
/
edit.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
<?php
//Require database in this file & image helpers
require_once "includes/database.php";
//Update the reservation in the database
$stmt = $db->prepare("UPDATE `reserveringssysteem`
SET naam = ?, `telefoonnummer` = ?, `mail` = ?, `datum` = ?, `tijd` = ?, `personen` = ?, `opmerkingen` = ?
WHERE `id` = ?");
$stmt->bind_param("sisssisi", $name, $telnr, $mail, $datum, $time, $personen, $opmerkingen, $reserverenId);
//Check if Post isset, else do nothing
if (isset($_POST['submit'])) {
//Postback with the data showed to the user, first retrieve data from 'Super global'
$reserverenId = mysqli_escape_string($db, $_POST['id']);
$name = mysqli_escape_string($db, $_POST['naam']);
$telnr = mysqli_escape_string($db, $_POST['telefoonnummer']);
$mail = mysqli_escape_string($db, $_POST['mail']);
$datum = mysqli_escape_string($db, $_POST['datum']);
$time = mysqli_escape_string($db, $_POST['tijd']);
$personen = mysqli_escape_string($db, $_POST['personen']);
$opmerkingen = mysqli_escape_string($db, $_POST['opmerkingen']);
function getErrorsForFields($name, $telnr, $mail, $datum, $time, $personen, $opmerkingen) {
//Check if data is valid & generate error if not so
$errors = [];
if ($name == "") {
$errors[] = 'Uw Naam cannot be empty';
}
if ($telnr == "") {
$errors[] = 'Uw Telefoonnummer cannot be empty';
}
if ($mail == "") {
$errors[] = ' Uw E-mail cannot be empty';
}
if ($datum == "") {
$errors[] = 'dd-mm-jjjj cannot be empty';
}
if ($time == "") {
$errors[] = 'Tijd cannot be empty';
}
if (!is_numeric($personen) || strlen($personen) != 1 && strlen($personen) != 2) {
$errors[] = ' Aantal Personen needs to be a number with the length of 1 or 2';
}
return $errors;
}
$errors = getErrorsForFields($name, $telnr, $mail, $datum, $time, $personen, $opmerkingen);
$hasErrors = !empty($errors);
//Save variables to array so the form won't break
//This array is build the same way as the db result
$reserveren = [
'id' => $reserverenId,
'naam' => $name,
'telefoonnummer' => $telnr,
'mail' => $mail,
'datum' => $datum,
'tijd' => $time,
'personen' => $personen,
'opmerkingen' => $opmerkingen,
];
$stmt->execute();
if (empty($errors)) {
header('Location: overzicht.php');
exit;
} else {
$errors[] = 'Something went wrong in your database query: ' . mysqli_error($db);
}
} else if(isset($_GET['id'])) {
//Retrieve the GET parameter from the 'Super global'
$reserverenId = $_GET['id'];
//Get the record from the database result
$query = "SELECT * FROM reserveringssysteem WHERE id = " . mysqli_escape_string($db, $reserverenId);
$result = mysqli_query($db, $query);
if(mysqli_num_rows($result) == 1)
{
$reserveren = mysqli_fetch_assoc($result);
}
else {
// redirect when db returns no result
header('Location: overzicht.php');
exit;
}
} else {
header('Location: overzicht.php');
exit;
}
//Close connection
mysqli_close($db);
?>
<!doctype html>
<html lang="en">
<head>
<title>Edit - <?= $reserveren['id'] . ' - ' . $reserveren['naam'] ?></title>
<meta charset="utf-8"/>
<link rel="stylesheet" type="text/css" href="css/editstyle.css"/>
</head>
<body>
<style>
h1 {
color: white;
}
</style>
<h1>Edit - <?= $reserveren['id'] . ' - ' . $reserveren['naam'] ?></h1>
<?php if (isset($errors) && !empty($errors)) { ?>
<ul class="errors">
<?php for ($i = 0; $i < count($errors); $i++) { ?>
<li><?= $errors[$i]; ?></li>
<?php } ?>
</ul>
<?php } ?>
<?php if (isset($success)) { ?>
<p class="success">Je reservering is bijgewerkt in de database</p>
<?php } ?>
<form action="<?= htmlspecialchars($_SERVER['REQUEST_URI']); ?>" method="post" enctype="multipart/form-data">
<div class="data-field">
<label for="Uw Naam">Naam</label>
<input id="naam" type="text" placeholder="Uw Naam" name="naam" value="<?= $reserveren['naam'] ?>" required/>
<span class="errors"><?= (isset($errors['naam']) ? $errors['naam'] : '') ?></span>
</div>
<div class="data-field">
<label for="Uw Telefoonnummer">Telefoonnummer</label>
<input id="telefoonnummer" type="text" placeholder="Uw Telefoonnummer" name="telefoonnummer" value="<?= $reserveren['telefoonnummer'] ?>" required/>
<span class="errors"><?= isset($errors['telefoonnummer']) ? $errors['telefoonnummer'] : '' ?></span>
</div>
<div class="data-field">
<label for="Uw E-mail">Email</label>
<input id="email" type="email" placeholder="Uw E-mail" name="mail" value="<?= $reserveren['mail'] ?>" required/>
<span class="errors"><?= isset($errors['mail']) ? $errors['mail'] : '' ?></span>
</div>
<div class="data-field">
<label for="dd-mm-jjjj">Datum</label>
<input id="dd-mm-jjjj" type="date" placeholder="Datum" name="datum" value="<?= $reserveren['datum'] ?>" required/>
<span class="errors"><?= isset($errors['datum']) ? $errors['datum'] : '' ?></span>
</div>
<div class="data-field">
<label for="Tijd">Tijd</label>
<input id="tijd" type="time" placeholder="Tijd" name="tijd" value="<?= $reserveren['tijd'] ?>" required/>
<span class="errors"><?= isset($errors['tijd']) ? $errors['tijd'] : '' ?></span>
</div>
<div class="data-field">
<label for="Aantal Personen">Aantal Personen</label>
<input id="personen" type="number" placeholder="Aantal Personen" name="personen" value="<?= $reserveren['personen'] ?>" required/>
<span class="errors"><?= isset($errors['personen']) ? $errors['personen'] : '' ?></span>
</div>
<div class="data-field">
<label for="Opmerkingen">Opmerkingen</label>
<input id="opmerkingen" type="text" placeholder="Opmerkingen" name="opmerkingen" value="<?= $reserveren['opmerkingen'] ?>"/>
<span class="errors"><?= isset($errors['opmerkingen']) ? $errors['opmerkingen'] : '' ?></span>
</div>
<div class="data-submit">
<input type="hidden" name="id" value="<?= $reserverenId ?>"/>
<input type="submit" class="btn" name="submit" value="Save"/>
</div>
</form>
<form action="overzicht.php">
<input type="submit" class="btn" value="Ga terug naar reserveringslijst"/>
</form>
</body>
</html>