[ Index ]

PHP Cross Reference of osCMax 2.0.4

title

Body

[close]

/admin/ -> reviews.php (source)

   1  <?php
   2  /*

   3  $Id: reviews.php 3 2006-05-27 04:59:07Z user $

   4  

   5    osCMax Power E-Commerce

   6    http://oscdox.com

   7  

   8    Copyright 2006 osCMax

   9  

  10    Released under the GNU General Public License

  11  */
  12  
  13    require ('includes/application_top.php');
  14  
  15    $action = (isset($HTTP_GET_VARS['action']) ? $HTTP_GET_VARS['action'] : '');
  16  
  17    if (tep_not_null($action)) {
  18      switch ($action) {
  19        case 'update':
  20          $reviews_id = tep_db_prepare_input($HTTP_GET_VARS['rID']);
  21          $reviews_rating = tep_db_prepare_input($HTTP_POST_VARS['reviews_rating']);
  22          $reviews_text = tep_db_prepare_input($HTTP_POST_VARS['reviews_text']);
  23  
  24          tep_db_query("update " . TABLE_REVIEWS . " set reviews_rating = '" . tep_db_input($reviews_rating) . "', last_modified = now() where reviews_id = '" . (int)$reviews_id . "'");
  25          tep_db_query("update " . TABLE_REVIEWS_DESCRIPTION . " set reviews_text = '" . tep_db_input($reviews_text) . "' where reviews_id = '" . (int)$reviews_id . "'");
  26  
  27          tep_redirect(tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $reviews_id));
  28          break;
  29        case 'deleteconfirm':
  30          $reviews_id = tep_db_prepare_input($HTTP_GET_VARS['rID']);
  31  
  32          tep_db_query("delete from " . TABLE_REVIEWS . " where reviews_id = '" . (int)$reviews_id . "'");
  33          tep_db_query("delete from " . TABLE_REVIEWS_DESCRIPTION . " where reviews_id = '" . (int)$reviews_id . "'");
  34  
  35          tep_redirect(tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page']));
  36          break;
  37      }
  38    }
  39  ?>
  40  <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN">
  41  <html <?php echo HTML_PARAMS; ?>>
  42  <head>
  43  <meta http-equiv="Content-Type" content="text/html; charset=<?php echo CHARSET; ?>">
  44  <title><?php echo TITLE; ?></title>
  45  <link rel="stylesheet" type="text/css" href="includes/stylesheet.css">
  46  <script language="javascript" src="includes/general.js"></script>
  47  </head>
  48  <body marginwidth="0" marginheight="0" topmargin="0" bottommargin="0" leftmargin="0" rightmargin="0" bgcolor="#FFFFFF" onload="SetFocus();">
  49  <!-- header //-->
  50  <?php require (DIR_WS_INCLUDES . 'header.php'); ?>
  51  <!-- header_eof //-->
  52  
  53  <!-- body //-->
  54  <table border="0" width="100%" cellspacing="2" cellpadding="2">
  55    <tr>
  56      <td width="<?php echo BOX_WIDTH; ?>" valign="top"><table border="0" width="<?php echo BOX_WIDTH; ?>" cellspacing="1" cellpadding="1" class="columnLeft">
  57  <!-- left_navigation //-->
  58  <?php require (DIR_WS_INCLUDES . 'column_left.php'); ?>
  59  <!-- left_navigation_eof //-->
  60      </table></td>
  61  <!-- body_text //-->
  62      <td width="100%" valign="top"><table border="0" width="100%" cellspacing="0" cellpadding="2">
  63        <tr>
  64          <td width="100%"><table border="0" width="100%" cellspacing="0" cellpadding="0">
  65            <tr>
  66              <td class="pageHeading"><?php echo HEADING_TITLE; ?></td>
  67              <td class="pageHeading" align="right"><?php echo tep_draw_separator('pixel_trans.gif', HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?></td>
  68            </tr>
  69          </table></td>
  70        </tr>
  71  <?php
  72    if ($action == 'edit') {
  73      $rID = tep_db_prepare_input($HTTP_GET_VARS['rID']);
  74  
  75      $reviews_query = tep_db_query("select r.reviews_id, r.products_id, r.customers_name, r.date_added, r.last_modified, r.reviews_read, rd.reviews_text, r.reviews_rating from " . TABLE_REVIEWS . " r, " . TABLE_REVIEWS_DESCRIPTION . " rd where r.reviews_id = '" . (int)$rID . "' and r.reviews_id = rd.reviews_id");
  76      $reviews = tep_db_fetch_array($reviews_query);
  77  
  78      $products_query = tep_db_query("select products_image from " . TABLE_PRODUCTS . " where products_id = '" . (int)$reviews['products_id'] . "'");
  79      $products = tep_db_fetch_array($products_query);
  80  
  81      $products_name_query = tep_db_query("select products_name from " . TABLE_PRODUCTS_DESCRIPTION . " where products_id = '" . (int)$reviews['products_id'] . "' and language_id = '" . (int)$languages_id . "'");
  82      $products_name = tep_db_fetch_array($products_name_query);
  83  
  84      $rInfo_array = array_merge($reviews, $products, $products_name);
  85      $rInfo = new objectInfo($rInfo_array);
  86  ?>
  87        <tr><?php echo tep_draw_form('review', FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $HTTP_GET_VARS['rID'] . '&action=preview'); ?>
  88          <td><table border="0" width="100%" cellspacing="0" cellpadding="0">
  89            <tr>
  90              <td class="main" valign="top"><b><?php echo ENTRY_PRODUCT; ?></b> <?php echo $rInfo->products_name; ?><br><b><?php echo ENTRY_FROM; ?></b> <?php echo $rInfo->customers_name; ?><br><br><b><?php echo ENTRY_DATE; ?></b> <?php echo tep_date_short($rInfo->date_added); ?></td>
  91              <td class="main" align="right" valign="top"><?php echo tep_image(DIR_WS_CATALOG_IMAGES . $rInfo->products_image, $rInfo->products_name, SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"'); ?></td>
  92            </tr>
  93          </table></td>
  94        </tr>
  95        <tr>
  96          <td><table witdh="100%" border="0" cellspacing="0" cellpadding="0">
  97            <tr>
  98              <td class="main" valign="top"><b><?php echo ENTRY_REVIEW; ?></b><br><br><?php echo tep_draw_textarea_field('reviews_text', 'soft', '60', '15', $rInfo->reviews_text); ?></td>
  99            </tr>
 100            <tr>
 101              <td class="smallText" align="right"><?php echo ENTRY_REVIEW_TEXT; ?></td>
 102            </tr>
 103          </table></td>
 104        </tr>
 105        <tr>
 106          <td><?php echo tep_draw_separator('pixel_trans.gif', '1', '10'); ?></td>
 107        </tr>
 108        <tr>
 109          <td class="main"><b><?php echo ENTRY_RATING; ?></b>&nbsp;<?php echo TEXT_BAD; ?>&nbsp;<?php for ($i=1; $i<=5; $i++) echo tep_draw_radio_field('reviews_rating', $i, '', $rInfo->reviews_rating) . '&nbsp;'; echo TEXT_GOOD; ?></td>
 110        </tr>
 111        <tr>
 112          <td><?php echo tep_draw_separator('pixel_trans.gif', '1', '10'); ?></td>
 113        </tr>
 114        <tr>
 115          <td align="right" class="main"><?php echo tep_draw_hidden_field('reviews_id', $rInfo->reviews_id) . tep_draw_hidden_field('products_id', $rInfo->products_id) . tep_draw_hidden_field('customers_name', $rInfo->customers_name) . tep_draw_hidden_field('products_name', $rInfo->products_name) . tep_draw_hidden_field('products_image', $rInfo->products_image) . tep_draw_hidden_field('date_added', $rInfo->date_added) . tep_image_submit('button_preview.gif', IMAGE_PREVIEW) . ' <a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $HTTP_GET_VARS['rID']) . '">' . tep_image_button('button_cancel.gif', IMAGE_CANCEL) . '</a>'; ?></td>
 116        </form></tr>
 117  <?php
 118    } elseif ($action == 'preview') {
 119      if (tep_not_null($HTTP_POST_VARS)) {
 120        $rInfo = new objectInfo($HTTP_POST_VARS);
 121      } else {
 122        $rID = tep_db_prepare_input($HTTP_GET_VARS['rID']);
 123  
 124        $reviews_query = tep_db_query("select r.reviews_id, r.products_id, r.customers_name, r.date_added, r.last_modified, r.reviews_read, rd.reviews_text, r.reviews_rating from " . TABLE_REVIEWS . " r, " . TABLE_REVIEWS_DESCRIPTION . " rd where r.reviews_id = '" . (int)$rID . "' and r.reviews_id = rd.reviews_id");
 125        $reviews = tep_db_fetch_array($reviews_query);
 126  
 127        $products_query = tep_db_query("select products_image from " . TABLE_PRODUCTS . " where products_id = '" . (int)$reviews['products_id'] . "'");
 128        $products = tep_db_fetch_array($products_query);
 129  
 130        $products_name_query = tep_db_query("select products_name from " . TABLE_PRODUCTS_DESCRIPTION . " where products_id = '" . (int)$reviews['products_id'] . "' and language_id = '" . (int)$languages_id . "'");
 131        $products_name = tep_db_fetch_array($products_name_query);
 132  
 133        $rInfo_array = array_merge($reviews, $products, $products_name);
 134        $rInfo = new objectInfo($rInfo_array);
 135      }
 136  ?>
 137        <tr><?php echo tep_draw_form('update', FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $HTTP_GET_VARS['rID'] . '&action=update', 'post', 'enctype="multipart/form-data"'); ?>
 138          <td><table border="0" width="100%" cellspacing="0" cellpadding="0">
 139            <tr>
 140              <td class="main" valign="top"><b><?php echo ENTRY_PRODUCT; ?></b> <?php echo $rInfo->products_name; ?><br><b><?php echo ENTRY_FROM; ?></b> <?php echo $rInfo->customers_name; ?><br><br><b><?php echo ENTRY_DATE; ?></b> <?php echo tep_date_short($rInfo->date_added); ?></td>
 141              <td class="main" align="right" valign="top"><?php echo tep_image(DIR_WS_CATALOG_IMAGES . $rInfo->products_image, $rInfo->products_name, SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"'); ?></td>
 142            </tr>
 143          </table>
 144        </tr>
 145        <tr>
 146          <td><table witdh="100%" border="0" cellspacing="0" cellpadding="0">
 147            <tr>
 148              <td valign="top" class="main"><b><?php echo ENTRY_REVIEW; ?></b><br><br><?php echo nl2br(tep_db_output(tep_break_string($rInfo->reviews_text, 15))); ?></td>
 149            </tr>
 150          </table></td>
 151        </tr>
 152        <tr>
 153          <td><?php echo tep_draw_separator('pixel_trans.gif', '1', '10'); ?></td>
 154        </tr>
 155        <tr>
 156          <td class="main"><b><?php echo ENTRY_RATING; ?></b>&nbsp;<?php echo tep_image(DIR_WS_CATALOG_IMAGES . 'stars_' . $rInfo->reviews_rating . '.gif', sprintf(TEXT_OF_5_STARS, $rInfo->reviews_rating)); ?>&nbsp;<small>[<?php echo sprintf(TEXT_OF_5_STARS, $rInfo->reviews_rating); ?>]</small></td>
 157        </tr>
 158        <tr>
 159          <td><?php echo tep_draw_separator('pixel_trans.gif', '1', '10'); ?></td>
 160        </tr>
 161  <?php
 162      if (tep_not_null($HTTP_POST_VARS)) {
 163  /* Re-Post all POST'ed variables */

 164        reset($HTTP_POST_VARS);
 165        while (list($key, $value) = each($HTTP_POST_VARS)) echo tep_draw_hidden_field($key, htmlspecialchars(stripslashes($value)));
 166  ?>
 167        <tr>
 168          <td align="right" class="smallText"><?php echo '<a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id . '&action=edit') . '">' . tep_image_button('button_back.gif', IMAGE_BACK) . '</a> ' . tep_image_submit('button_update.gif', IMAGE_UPDATE) . ' <a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id) . '">' . tep_image_button('button_cancel.gif', IMAGE_CANCEL) . '</a>'; ?></td>
 169        </form></tr>
 170  <?php
 171      } else {
 172        if (isset($HTTP_GET_VARS['origin'])) {
 173          $back_url = $HTTP_GET_VARS['origin'];
 174          $back_url_params = '';
 175        } else {
 176          $back_url = FILENAME_REVIEWS;
 177          $back_url_params = 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id;
 178        }
 179  ?>
 180        <tr>
 181          <td align="right"><?php echo '<a href="' . tep_href_link($back_url, $back_url_params, 'NONSSL') . '">' . tep_image_button('button_back.gif', IMAGE_BACK) . '</a>'; ?></td>
 182        </tr>
 183  <?php
 184      }
 185    } else {
 186  ?>
 187        <tr>
 188          <td><table border="0" width="100%" cellspacing="0" cellpadding="0">
 189            <tr>
 190              <td valign="top"><table border="0" width="100%" cellspacing="0" cellpadding="2">
 191                <tr class="dataTableHeadingRow">
 192                  <td class="dataTableHeadingContent"><?php echo TABLE_HEADING_PRODUCTS; ?></td>
 193                  <td class="dataTableHeadingContent" align="right"><?php echo TABLE_HEADING_RATING; ?></td>
 194                  <td class="dataTableHeadingContent" align="right"><?php echo TABLE_HEADING_DATE_ADDED; ?></td>
 195                  <td class="dataTableHeadingContent" align="right"><?php echo TABLE_HEADING_ACTION; ?>&nbsp;</td>
 196                </tr>
 197  <?php
 198      $reviews_query_raw = "select reviews_id, products_id, date_added, last_modified, reviews_rating from " . TABLE_REVIEWS . " order by date_added DESC";
 199      $reviews_split = new splitPageResults($HTTP_GET_VARS['page'], MAX_DISPLAY_SEARCH_RESULTS, $reviews_query_raw, $reviews_query_numrows);
 200      $reviews_query = tep_db_query($reviews_query_raw);
 201      while ($reviews = tep_db_fetch_array($reviews_query)) {
 202        if ((!isset($HTTP_GET_VARS['rID']) || (isset($HTTP_GET_VARS['rID']) && ($HTTP_GET_VARS['rID'] == $reviews['reviews_id']))) && !isset($rInfo)) {
 203          $reviews_text_query = tep_db_query("select r.reviews_read, r.customers_name, length(rd.reviews_text) as reviews_text_size from " . TABLE_REVIEWS . " r, " . TABLE_REVIEWS_DESCRIPTION . " rd where r.reviews_id = '" . (int)$reviews['reviews_id'] . "' and r.reviews_id = rd.reviews_id");
 204          $reviews_text = tep_db_fetch_array($reviews_text_query);
 205  
 206          $products_image_query = tep_db_query("select products_image from " . TABLE_PRODUCTS . " where products_id = '" . (int)$reviews['products_id'] . "'");
 207          $products_image = tep_db_fetch_array($products_image_query);
 208  
 209          $products_name_query = tep_db_query("select products_name from " . TABLE_PRODUCTS_DESCRIPTION . " where products_id = '" . (int)$reviews['products_id'] . "' and language_id = '" . (int)$languages_id . "'");
 210          $products_name = tep_db_fetch_array($products_name_query);
 211  
 212          $reviews_average_query = tep_db_query("select (avg(reviews_rating) / 5 * 100) as average_rating from " . TABLE_REVIEWS . " where products_id = '" . (int)$reviews['products_id'] . "'");
 213          $reviews_average = tep_db_fetch_array($reviews_average_query);
 214  
 215          $review_info = array_merge($reviews_text, $reviews_average, $products_name);
 216          $rInfo_array = array_merge($reviews, $review_info, $products_image);
 217          $rInfo = new objectInfo($rInfo_array);
 218        }
 219  
 220        if (isset($rInfo) && is_object($rInfo) && ($reviews['reviews_id'] == $rInfo->reviews_id) ) {
 221          echo '              <tr id="defaultSelected" class="dataTableRowSelected" onmouseover="rowOverEffect(this)" onmouseout="rowOutEffect(this)" onclick="document.location.href=\'' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id . '&action=preview') . '\'">' . "\n";
 222        } else {
 223          echo '              <tr class="dataTableRow" onmouseover="rowOverEffect(this)" onmouseout="rowOutEffect(this)" onclick="document.location.href=\'' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $reviews['reviews_id']) . '\'">' . "\n";
 224        }
 225  ?>
 226                  <td class="dataTableContent"><?php echo '<a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $reviews['reviews_id'] . '&action=preview') . '">' . tep_image(DIR_WS_ICONS . 'preview.gif', ICON_PREVIEW) . '</a>&nbsp;' . tep_get_products_name($reviews['products_id']); ?></td>
 227                  <td class="dataTableContent" align="right"><?php echo tep_image(DIR_WS_CATALOG_IMAGES . 'stars_' . $reviews['reviews_rating'] . '.gif'); ?></td>
 228                  <td class="dataTableContent" align="right"><?php echo tep_date_short($reviews['date_added']); ?></td>
 229                  <td class="dataTableContent" align="right"><?php if ( (is_object($rInfo)) && ($reviews['reviews_id'] == $rInfo->reviews_id) ) { echo tep_image(DIR_WS_IMAGES . 'icon_arrow_right.gif'); } else { echo '<a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $reviews['reviews_id']) . '">' . tep_image(DIR_WS_IMAGES . 'icon_info.gif', IMAGE_ICON_INFO) . '</a>'; } ?>&nbsp;</td>
 230                </tr>
 231  <?php
 232      }
 233  ?>
 234                <tr>
 235                  <td colspan="4"><table border="0" width="100%" cellspacing="0" cellpadding="2">
 236                    <tr>
 237                      <td class="smallText" valign="top"><?php echo $reviews_split->display_count($reviews_query_numrows, MAX_DISPLAY_SEARCH_RESULTS, $HTTP_GET_VARS['page'], TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?></td>
 238                      <td class="smallText" align="right"><?php echo $reviews_split->display_links($reviews_query_numrows, MAX_DISPLAY_SEARCH_RESULTS, MAX_DISPLAY_PAGE_LINKS, $HTTP_GET_VARS['page']); ?></td>
 239                    </tr>
 240                  </table></td>
 241                </tr>
 242              </table></td>
 243  <?php
 244      $heading = array();
 245      $contents = array();
 246  
 247      switch ($action) {
 248        case 'delete':
 249          $heading[] = array('text' => '<b>' . TEXT_INFO_HEADING_DELETE_REVIEW . '</b>');
 250  
 251          $contents = array('form' => tep_draw_form('reviews', FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id . '&action=deleteconfirm'));
 252          $contents[] = array('text' => TEXT_INFO_DELETE_REVIEW_INTRO);
 253          $contents[] = array('text' => '<br><b>' . $rInfo->products_name . '</b>');
 254          $contents[] = array('align' => 'center', 'text' => '<br>' . tep_image_submit('button_delete.gif', IMAGE_DELETE) . ' <a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id) . '">' . tep_image_button('button_cancel.gif', IMAGE_CANCEL) . '</a>');
 255          break;
 256        default:
 257        if (isset($rInfo) && is_object($rInfo)) {
 258          $heading[] = array('text' => '<b>' . $rInfo->products_name . '</b>');
 259  
 260          $contents[] = array('align' => 'center', 'text' => '<a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id . '&action=edit') . '">' . tep_image_button('button_edit.gif', IMAGE_EDIT) . '</a> <a href="' . tep_href_link(FILENAME_REVIEWS, 'page=' . $HTTP_GET_VARS['page'] . '&rID=' . $rInfo->reviews_id . '&action=delete') . '">' . tep_image_button('button_delete.gif', IMAGE_DELETE) . '</a>');
 261          $contents[] = array('text' => '<br>' . TEXT_INFO_DATE_ADDED . ' ' . tep_date_short($rInfo->date_added));
 262          if (tep_not_null($rInfo->last_modified)) $contents[] = array('text' => TEXT_INFO_LAST_MODIFIED . ' ' . tep_date_short($rInfo->last_modified));
 263          $contents[] = array('text' => '<br>' . tep_info_image($rInfo->products_image, $rInfo->products_name, SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT));
 264          $contents[] = array('text' => '<br>' . TEXT_INFO_REVIEW_AUTHOR . ' ' . $rInfo->customers_name);
 265          $contents[] = array('text' => TEXT_INFO_REVIEW_RATING . ' ' . tep_image(DIR_WS_CATALOG_IMAGES . 'stars_' . $rInfo->reviews_rating . '.gif'));
 266          $contents[] = array('text' => TEXT_INFO_REVIEW_READ . ' ' . $rInfo->reviews_read);
 267          $contents[] = array('text' => '<br>' . TEXT_INFO_REVIEW_SIZE . ' ' . $rInfo->reviews_text_size . ' bytes');
 268          $contents[] = array('text' => '<br>' . TEXT_INFO_PRODUCTS_AVERAGE_RATING . ' ' . number_format($rInfo->average_rating, 2) . '%');
 269        }
 270          break;
 271      }
 272  
 273      if ( (tep_not_null($heading)) && (tep_not_null($contents)) ) {
 274        echo '            <td width="25%" valign="top">' . "\n";
 275  
 276        $box = new box;
 277        echo $box->infoBox($heading, $contents);
 278  
 279        echo '            </td>' . "\n";
 280      }
 281  ?>
 282            </tr>
 283          </table></td>
 284        </tr>
 285  <?php
 286    }
 287  ?>
 288      </table></td>
 289  <!-- body_text_eof //-->
 290    </tr>
 291  </table>
 292  <!-- body_eof //-->
 293  
 294  <!-- footer //-->
 295  <?php require (DIR_WS_INCLUDES . 'footer.php'); ?>
 296  <!-- footer_eof //-->
 297  <br>
 298  </body>
 299  </html>
 300  <?php require (DIR_WS_INCLUDES . 'application_bottom.php'); ?>


Generated: Fri Jan 1 13:43:16 2010 Cross-referenced by PHPXref 0.7