<?php
session_start();
$db=mysql_connect('xxx','xxx','xxx');
mysql_select_db('xxx',$db);
// *********************************
$username = $_POST["username"];
$passwort = md5($_POST["password"]);
$abfrage = "SELECT username, passwort FROM komplett WHERE username LIKE '$username' LIMIT 1";
$ergebnis = mysql_query($abfrage);
$row = mysql_fetch_object($ergebnis);
if($row->passwort == $passwort)
{
$_SESSION["username"] = $username;
echo "Login zum Userprofil erfolgreich. <br> <br><em>Leider noch nicht verfügbar</em>";
}
else
{
echo "Benutzername und/oder Passwort waren falsch.<br> <a href=\"profil3.html\">Zurück</a>";
}
//****************************************
if (isset($_POST['insert']))
{
mysql_query ("INSERT into `komplett` (vorname,nachname,strasse,ort,email,lat,lng,sonstiges,username,passwort) values ('".$_POST['vorname']."', '".$_POST['nachname']."', '".$_POST['strasse']."', '".$_POST['ort']."', '".$_POST['email']."', '".$_POST['lat']."', '".$_POST['lng']."', '".$_POST['sonstiges']."', '".$_POST['username']."', '".$_POST['passwort']."')",$db);
}
elseif (isset($_POST['update']))
{
mysql_query("update `komplett` set `vorname`='".$_POST['vorname']."', `nachname`='".$_POST['nachname']."', `strasse`='".$_POST['strasse']."', `ort`='".$_POST['ort']."', `email`='".$_POST['email']."', `lat`='".$_POST['lat']."', `lng`='".$_POST['lng']."', `sonstiges`='".$_POST['sonstiges']."', `username`='".$_POST['username']."', `passwort`='".$_POST['passwort']."' where `location_id`='".$_POST['location_id']."'",$db);
}
elseif (!empty($_GET['delete']))
{
mysql_query("delete from `komplett` where `location_id`='".$_GET['delete']."'",$db);
}
// elseif (!empty($_GET['edit']))
elseif (!empty($_GET['edit']) and !empty($_SESSION["username"]))
{
// $results=mysql_query("select * from `komplett` where `location_id`='".$_GET['edit']."'",$db);
$results=mysql_query("select * from `komplett` where `location_id`='".$_GET['edit']."' AND username='".$_SESSION["username"]."'",$db);
$result=mysql_fetch_assoc($results);
echo '<form method="post" action="'.$_SERVER['PHP_SELF'].'">';
echo 'Vorname: <input type="text" name="vorname" value="'.$result['vorname'].'"><br><br>';
echo 'Nachname: <input type="text" name="nachname" value="'.$result['nachname'].'"><br><br>';
echo 'Strasse: <input type="text" name="strasse" value="'.$result['strasse'].'"><br><br>';
echo 'Ort: <input type="text" name="ort" value="'.$result['ort'].'"><br><br>';
echo 'E-Mail: <input type="text" name="email" value="'.$result['email'].'"><br><br>';
echo 'Latitude: <input type="text" name="lat" value="'.$result['lat'].'"><br><br>';
echo 'Longitude: <input type="text" name="lng" value="'.$result['lng'].'"><br><br>';
echo 'Sonstiges: <input type="text" name="sonstiges" value="'.$result['sonstiges'].'"><br><br>';
echo 'Username: <input type="text" name="username" value="'.$result['username'].'"><br><br>';
echo 'Passwort: <input type="text" name="passwort" value="'.$result['passwort'].'"><br><br>';
echo '<input type="hidden" name="location_id" value="'.$_GET['edit'].'"><br>';
echo '<input type="submit" name="update" value="Update"><input type=button value="Zurück" onClick="history.back()">';
echo '</form>';
}
else
{
echo '<table border="1">';
echo '<tr><th>Vorname</th><th>Nachname</th><th>Strasse</th><th>Ort</th><th>E-Mail</th><th>Latitude</th><th>Longitude</th><th>Sonstiges</th><th>Username</th><th>Passwort</th><th colspan="2">Aktion</th></tr>';
$results=mysql_query("select * from `komplett` WHERE username='".$_SESSION["username"]."'",$db);
while ($result=mysql_fetch_assoc($results))
{
echo '<tr><td>'.$result['vorname'].'</td><td>'.$result['nachname'].'</td><td>'.$result['strasse'].'</td><td>'.$result['ort'].'</td><td>'.$result['email'].'</td><td>'.$result['lat'].'</td><td>'.$result['lng'].'</td><td>'.$result['sonstiges'].'</td><td>'.$result['username'].'</td><td>'.$result['passwort'].'</td><td><a href="'.$_SERVER['PHP_SELF'].'?edit='.$result['location_id'].'">Bearbeiten</a></td><td><a href="'.$_SERVER['PHP_SELF'].'?delete='.$result['location_id'].'">Loeschen</a></td></tr>';
}
echo '</table>';
}
mysql_close($db);
?>