fixed formatting
This commit is contained in:
parent
91bb969d66
commit
6ba55c000b
3 changed files with 448 additions and 431 deletions
|
|
@ -4,22 +4,22 @@ include "db/functions.php";
|
|||
|
||||
session_start();
|
||||
|
||||
if(empty($_SESSION['csrf_token'])){
|
||||
if (empty($_SESSION['csrf_token'])) {
|
||||
die("Invalid request: No token supplied.");
|
||||
}
|
||||
|
||||
$sessionToken = (string)($_SESSION['csrf_token'] ?? '');
|
||||
$postToken = (string)($_POST['csrf_token'] ?? '');
|
||||
$getToken = (string)($_GET['csrf_token'] ?? '');
|
||||
$sessionToken = (string) ($_SESSION['csrf_token'] ?? '');
|
||||
$postToken = (string) ($_POST['csrf_token'] ?? '');
|
||||
$getToken = (string) ($_GET['csrf_token'] ?? '');
|
||||
|
||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||
|
||||
if(!hash_equals($sessionToken, $postToken)){
|
||||
if (!hash_equals($sessionToken, $postToken)) {
|
||||
die("Invalid request: Token mismatch.");
|
||||
}
|
||||
|
||||
//Book Submission
|
||||
if($_POST['submissionType'] == "book"){
|
||||
if ($_POST['submissionType'] == "book") {
|
||||
$title = $_POST['title'] ?? '';
|
||||
$author = $_POST['author'] ?? '';
|
||||
$area = $_POST['area'] ?? '';
|
||||
|
|
@ -30,9 +30,9 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||
echo "<p>Please fill in all fields.</p>";
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
//Copy Submission
|
||||
if($_POST['submissionType'] == "copy"){
|
||||
if ($_POST['submissionType'] == "copy") {
|
||||
$bookID = $_POST['book'] ?? '';
|
||||
$amount = $_POST['amount'] ?? '';
|
||||
$copyCondition = $_POST['condition'] ?? '';
|
||||
|
|
@ -45,80 +45,80 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||
}
|
||||
|
||||
//Borrower Submission
|
||||
if($_POST['submissionType'] == "borrower"){
|
||||
if ($_POST['submissionType'] == "borrower") {
|
||||
$firstname = $_POST['firstname'] ?? '';
|
||||
$lastname = $_POST['lastname'] ?? '';
|
||||
$role = $_POST['role'] ?? '';
|
||||
|
||||
if($firstname && $lastname && $role){
|
||||
if ($firstname && $lastname && $role) {
|
||||
addBorrower($pdo, $firstname, $lastname, $role);
|
||||
}else{
|
||||
} else {
|
||||
echo "<p>Please fill in all fields.</p>";
|
||||
}
|
||||
}
|
||||
|
||||
if($_POST['submissionType'] == "loan"){
|
||||
if ($_POST['submissionType'] == "loan") {
|
||||
$copyID = $_POST['copyID'] ?? '';
|
||||
$borrowerID = $_POST['borrowerID'] ?? '';
|
||||
$borrowedDate = $_POST['borrowedDate'] ?? '';
|
||||
$dueDate = $_POST['dueDate'];
|
||||
|
||||
if($copyID && $borrowerID && $borrowedDate && $dueDate){
|
||||
if ($copyID && $borrowerID && $borrowedDate && $dueDate) {
|
||||
addLoan($pdo, $copyID, $borrowerID, $borrowedDate, $dueDate);
|
||||
}else{
|
||||
} else {
|
||||
echo "<p>Please fill in all fields.</p>";
|
||||
}
|
||||
}
|
||||
|
||||
if($_POST['submissionType'] == "return"){
|
||||
if ($_POST['submissionType'] == "return") {
|
||||
$copyIDLoanID = explode("-", $_POST['copyID-loanID'], 2);
|
||||
|
||||
$copyID = $copyIDLoanID[0];
|
||||
$loanID = $copyIDLoanID[1];
|
||||
$returnedDate = $_POST['returnedDate'];
|
||||
|
||||
if($copyID && $loanID){
|
||||
if ($copyID && $loanID) {
|
||||
removeLoan($pdo, $copyID, $loanID, $returnedDate);
|
||||
}else{
|
||||
} else {
|
||||
echo "<p>Please fill in all fields</p>";
|
||||
}
|
||||
}
|
||||
|
||||
if($_POST['submissionType'] == "selectRequest"){
|
||||
if ($_POST['submissionType'] == "selectRequest") {
|
||||
$selectRequest = $_POST['sqlSelectTextarea'];
|
||||
|
||||
if($selectRequest){
|
||||
if ($selectRequest) {
|
||||
selectRequest($pdo, $selectRequest);
|
||||
}else{
|
||||
} else {
|
||||
echo "<p>Please fill in all fields</p>";
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($_SERVER['REQUEST_METHOD'] == 'GET'){
|
||||
if ($_SERVER['REQUEST_METHOD'] == 'GET') {
|
||||
|
||||
if(!hash_equals($sessionToken, $getToken)){
|
||||
if (!hash_equals($sessionToken, $getToken)) {
|
||||
die("Invalid request: Token mismatch.");
|
||||
}
|
||||
|
||||
if($_GET['submissionType'] == "getCopies"){
|
||||
if ($_GET['submissionType'] == "getCopies") {
|
||||
$bookID = $_GET['bookID'];
|
||||
if($bookID){
|
||||
if ($bookID) {
|
||||
$copies = getAvailableCopiesOfBook($pdo, $bookID);
|
||||
|
||||
|
||||
echo json_encode($copies);
|
||||
}else{
|
||||
} else {
|
||||
echo json_encode([]);
|
||||
}
|
||||
}
|
||||
|
||||
if($_GET['submissionType'] == "getReturnCopies"){
|
||||
if ($_GET['submissionType'] == "getReturnCopies") {
|
||||
$borrowerID = $_GET['borrowerID'];
|
||||
if($borrowerID){
|
||||
if ($borrowerID) {
|
||||
$copies = getBorrowedCopiesOfBorrower($pdo, $borrowerID);
|
||||
|
||||
echo json_encode($copies);
|
||||
}else{
|
||||
} else {
|
||||
echo json_encode([]);
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue