PK

ADDRLIN : /home/anibklip/aelogifts.com/cms/
FLL :
Current File : /home/anibklip/aelogifts.com/cms/product_add.php

<script>
	function showImg(input,imgid) {
		//alert(imgid);
		if (input.files && input.files[0]) {
			var reader = new FileReader();
			im=document.getElementById(imgid);

			document.getElementById(imgid).style.display="block";

			reader.onload = function (e) {
				//alert(e.target.result);
				//$(imgid).attr('src', e.target.result);
				im.src=e.target.result;
				im.width="150";
			};

			reader.readAsDataURL(input.files[0]);
		}
	}
</script>
<?php
if ($_POST['doAction'] == "add" || $_POST['doAction'] == "edit") {
	// echo "<pre>"; print_r($_POST); echo "</pre>"; die;
	if(is_array($_POST['colors'])){
		$colors = implode(",", $_POST['colors']);
	}else{
		$colors = NULL;
	}
	$fields = " prd set
		ctid		= '" . mysqli_escape_string($conn, $_POST['ctid']) . "',
		pname 		= '".mysqli_escape_string($conn,$_POST['pname'])."',
		colors 		= '".$colors."',
		s_desc		= '" . mysqli_escape_string($conn, $_POST['s_desc']) . "',
		pdesc		= '" . mysqli_escape_string($conn, $_POST['descp']) . "',
		shw_home	= '$_POST[shw_home]',
		dprice		= '" . mysqli_escape_string($conn, $_POST['dprice']) . "', 
		price 		= '" . mysqli_escape_string($conn, $_POST['price']) . "',
		weight		= '" . mysqli_escape_string($conn, $_POST['weight']) . "', 
		stock_qty	= '" . mysqli_escape_string($conn, $_POST['stock_qty']) . "', 
		sort_id 	= '" . mysqli_escape_string($conn, $_POST['sort_id']) . "'
	";

	if ($_POST['doAction'] == "add") {
		$query = "INSERT into $fields, status=1 ";
		mysqli_query($conn, $query) or die(mysqli_error($conn));
		$pid = mysqli_insert_id($conn);

		$_SESSION['msg'] = "Record added successfully.";
	} elseif ($_POST['doAction'] == "edit") {
		$query = "UPDATE $fields
			where pid='" . $_GET['pid'] . "'
		";
		mysqli_query($conn, $query) or die(mysqli_error($conn));
		$pid = $_POST['pid'];

		$_SESSION['msg'] = "Record updated successfully.";
	}
	// echo $query;die;

	// var_dump($_FILES);
	for ($i = 1; $i <= 6; $i++) {
		if ($_FILES['img' . $i]['name']) {
			$ext2 = strtolower(substr($_FILES['img' . $i]['name'], -4));
			if ($ext2 == ".jpg" || $ext2 == ".jpeg" || $ext2 == ".gif" || $ext2 == ".png") {
				// @unlink("site_data/$row[img]");
				// @unlink("site_data/th_$row[img]");

				$uploaddir = "../products/";
				$ext2 = strstr($_FILES['img' . $i]['name'], '.');
				$picname1 = $pid . "_prd_" . $i . $ext2;

				$uploadfile = $uploaddir . $picname1;
				if($_FILES['img'.$i]['tmp_name']) {
					// if (move_uploaded_file($_FILES['img' . $i]['tmp_name'], $uploadfile)) {
					// createthumb1($picname1,"site_data/");
					// thumb_jpeg($_FILES['img'.$i]['tmp_name'],$picname1,$uploaddir,500,500);
					// thumb_jpeg($_FILES['img'.$i]['tmp_name'],"th_".$picname1,$uploaddir,600,700);

					$obj_img = new thumbnail_images();
					$obj_img->PathImgOld = $_FILES['img'.$i]['tmp_name'];
					$obj_img->PathImgNew = $uploaddir."".$picname1;
					$obj_img->NewWidth = 1200;
					$obj_img->NewHeight	= 1400;
					$obj_img->create_thumbnail_images();

					$query = "UPDATE prd set pic" . $i . "= '$picname1' where pid = '" . $pid . "' ";
					// echo $query; die;
					mysqli_query($conn, $query);
				}
			} else {
				echo "<font color='red'><b>SORRY only .jpg, .png, .gif file is allowed<br></b></font>";
				//die();
			}
		}
	}

	if ($_FILES['pic_360']['name']) {
		$ext2 = strtolower(substr($_FILES['pic_360']['name'], -4));
		if ($ext2 == ".jpg" || $ext2 == ".jpeg" || $ext2 == ".gif" || $ext2 == ".png") {
			// @unlink("site_data/$row[img]");
			// @unlink("site_data/th_$row[img]");

			$uploaddir = "../products/";
			$ext2 = strstr($_FILES['pic_360']['name'], '.');
			$picname1 = $pid . "_360_" . $ext2;

			$uploadfile = $uploaddir . $picname1;
			if($_FILES['pic_360']['tmp_name']) {
				move_uploaded_file($_FILES['pic_360']['tmp_name'], $uploadfile);

				$query = "UPDATE prd set pic_360 = '$picname1' where pid = '" . $pid . "' ";
				// echo $query; die;
				mysqli_query($conn, $query) or die(mysqli_error($conn));
			}
		} else {
			echo "<font color='red'><b>SORRY only .jpg, .png, .gif file is allowed<br></b></font>";
			//die();
		}
	}

	echo "<script>window.location.href='main.php?action=product_add&pid=$_GET[pid]'</script>";
	die;
}

if ($_GET['delimg']) {
	$query = "UPDATE prd set pic" . $_GET['i'] . "='' where pid = '$_GET[pid]' ";
	mysqli_query($conn, $query) or die(mysqli_error($conn));

	@unlink("../products/" . $_GET['delimg']);

	echo "<script>window.location.href='main.php?action=product_add&pid=".$_GET['pid']."';</script>";
	die;
}

if ($_SESSION['msg']) {
	$msg = $_SESSION['msg'];
	unset($_SESSION['msg']);
}
if ($_SESSION['errmsg']) {
	$errmsg = $_SESSION['errmsg'];
	unset($_SESSION['errmsg']);
}

$query = "SELECT * from prd where pid = '$_GET[pid]'";
$query = mysqli_query($conn, $query) or die(mysqli_error($conn));
if ($editrow = mysqli_fetch_array($query, MYSQLI_ASSOC)) {
}
?>
<div class="content-wrapper">
	<!-- Content Header (Page header) -->
	<section class="content-header">
		<div class="container-fluid">
			<div class="row mb-2">
				<div class="col-sm-6">
					<h1>Product <?php echo ($_GET['pid'] != "" ? "Edit" : "Add"); ?></h1>
				</div>
				<div class="col-sm-6">
					<ol class="breadcrumb float-sm-right">
						<li class="breadcrumb-item"><a href="#">Home</a></li>
						<li class="breadcrumb-item active">Product <?php echo ($_GET['pid'] != "" ? "Edit" : "Add"); ?></li>
					</ol>
				</div>
			</div>
		</div><!-- /.container-fluid -->
	</section>

	<!-- Main content -->
	<section class="content">
		<div class="row">
			<div class="col-md-12">
				<?php if ($msg) { ?><div class="alert alert-success"><strong>Success!</strong> <?php echo $msg; ?></div><?php } ?>
				<?php if ($errmsg) { ?><div class="alert alert-danger"><strong>Success!</strong> <?php echo $errmsg; ?></div><?php } ?>

				<div class="card card-outline card-info">
					<!-- <div class="card-header">
						<h3 class="card-title">Body</h3>
					</div> -->
					<!-- /.card-header -->

					<form name="textEditor" method="POST" action="" enctype="multipart/form-data">
						<input type="hidden" name="doAction" value="<?php if ($_GET['pid'] != "") { echo "edit"; } else { echo "add"; } ?>">
						<input type="hidden" name="pid" value="<?php echo $_GET['pid']; ?>">
						<input type="hidden" name="sort_id" value="0">

						<div class="card-body">
							<div class="form-group">
								<label for="ctid">Category</label>
								<select name="ctid" id="ctid" required class="form-control">
									<option value="">Select</option>
									<?php
									$query="SELECT * from cate where parent_id=0 order by bname";	//and typ=1 
									$q=mysqli_query($conn,$query) or die(mysqli_error($conn));
									while ($row11=mysqli_fetch_array($q)){
										if($editrow['ctid'] == $row11["ctid"]){
											$sel1="selected";
										}else{
											$sel1="";
										}
										?>
										<option <?php echo $sel1?> value="<?php echo $row11['ctid']?>" style="color:blue;"><?php echo $row11['bname']?></option>
										<?php
										$query1="SELECT * from cate where parent_id=$row11[ctid] order by bname";
										$q1=mysqli_query($conn, $query1) or die(mysqli_error($conn));
										while($row1=mysqli_fetch_array($q1)){
											if($editrow['ctid'] == $row1["ctid"]){
												$sel1="selected";
											}else{
												$sel1="";
											}
											?>
											<option <?php echo $sel1?> value="<?php echo $row1['ctid']?>">&nbsp; - <?php echo $row1['bname']?></option>
											<?php
											$q2="SELECT * from cate where parent_id=$row1[ctid] order by bname";
											$q2=mysqli_query($conn, $q2);
											while($row2=mysqli_fetch_array($q2)){
												if ($editrow['ctid'] == $row2["ctid"]){
													$sel="selected";
												}else{
													$sel="";
												}
												?>
												<option <?php echo $sel?> value="<?php echo $row2['ctid']?>">&nbsp; - - <?php echo $row2['bname']?></option>
												<?php
											}
										}
									}
									?>
								</select>
							</div>
							<div class="form-group">
								<label for="pname">Product Title</label>
								<input type="text" class="form-control" name="pname" id="pname" value="<?php echo $editrow['pname']; ?>" required />
							</div>
							<div class="row">
								<div class="col-lg-3 col-md-4 col-sm-6">
									<!-- text input -->
									<div class="form-group">
										<label for="dprice">Discounted Price</label>
										<input type="text" class="form-control" name="dprice" id="dprice" value="<?php echo $editrow['dprice']; ?>" />
									</div>
								</div>
								<div class="col-lg-3 col-md-4 col-sm-6">
									<div class="form-group">
										<label for="price">Price Mrp</label>
										<input type="text" class="form-control" name="price" id="price" value="<?php echo $editrow['price']; ?>" required />
									</div>
								</div>
								
							</div>
							<div class="row">
								<div class="col-lg-3 col-md-4 col-sm-6">
									<div class="form-group">
										<label for="weight">Weight</label>
										<input type="number" step=".01" class="form-control" name="weight" id="weight" value="<?php echo $editrow['weight']; ?>" />(eg: 1Kg or in gm 500gms = 0.5kg)
									</div>
								</div>
								<div class="col-lg-3 col-md-4 col-sm-6">
									<div class="form-group">
										<label for="stock_qty">Stock</label>
										<input type="number" class="form-control" name="stock_qty" id="stock_qty" value="<?php echo $editrow['stock_qty']; ?>" required />
									</div>
								</div>
								<div class="col-lg-3 col-md-4 col-sm-6">
									<div class="form-group">
										<label for="colors">Colors</label>
										<!-- <input type="text" class="form-control" name="colors" id="colors" value="<?php echo $editrow['colors']; ?>" required /> -->
										<div class="select2-purple">
											<select class="select2" name="colors[]" id="colors" value="<?php echo $editrow['colors']; ?>" multiple="multiple" data-placeholder="Add colors" data-dropdown-css-class="select2-purple" style="width: 100%;">
												<?php
												if($editrow['colors']){
													$colors = explode(",", $editrow['colors']);
													foreach ($colors as $color) {
														$sel = "selected";
														?>
														<option <?php echo $sel; ?> value="<?php echo $color; ?>"><?php echo ucfirst($color); ?></option>
														<?php
													}
												}
												?>
											</select>
										</div>
									</div>
								</div>
							</div>
							<div class="form-group">
								<label for="shw_home">Featured</label>
								<input type="checkbox" value="1" class="" name="shw_home" <?php echo ($editrow['shw_home']=="1"?"checked='checked'":"")?> />
							</div>
							
							<div class="form-group">
								<label for="s_desc">Short Description</label>
								<textarea name="s_desc" class="form-control" rows="5"><?php echo $editrow['s_desc']; ?></textarea>
							</div>
							<div class="form-group">
								<label for="summernote">Product Description</label>
								<textarea class="summernote" name="descp" id="summernote"><?php echo $editrow['pdesc']; ?></textarea>
							</div>
							<?php
							for ($i = 1; $i <= 6; $i++) {
								?>
								<div class="col-lg-3 col-md-4 col-sm-6">
									<div class="form-group">
										<label for="exampleInputFile1">Image <?php echo $i; ?> - 1200px x 1400px</label>
										<div class="input-group">
											<div class="custom-file1">
												<input type="file" class="custom-file-input" onchange="showImg(this,'img_'+<?php echo $i;?>)" id="InputFile_<?php echo $i;?>" name="img<?php echo $i; ?>" accept="image/png, image/jpeg" />
												<img src='' id="img_<?php echo $i;?>" style="display1: none;" border="1" width="80" />
												<label class="custom-file-label" for="InputFile_<?php echo $i;?>">Choose file</label>
											</div>
										</div>
										<?php
										if ($editrow['pic' . $i]) {
											?>
											<img src="../products/<?php echo $editrow['pic'.$i];?>" width="80" />
											<a href="main.php?action=product_add&pid=<?php echo $_GET['pid']; ?>&i=<?php echo $i; ?>&delimg=<?php echo $editrow['pic' . $i]; ?>" class="btn btn-sm btn-info mt-2">Delete Image</a>
											<?php
										}
										?>
									</div>
								</div>
								<?php
							}
							?>
							<div class="col-lg-3 col-md-4 col-sm-6">
								<div class="form-group">
									<label for="exampleInputFile1">360 View Panorama Image</label>
									<div class="input-group">
										<div class="custom-file1">
											<input type="file" class="custom-file-input" onchange="showImg(this,'pic_360_v')" id="pic_360" name="pic_360" accept="image/png, image/jpeg" />
											<img src='' id="pic_360_v" style="border:1px solid #000; width:100%" />
											<label class="custom-file-label" for="pic_360">Choose file</label>
										</div>
									</div>
									<?php
									if ($editrow['pic_360']) {
										?>
										<img src="../products/<?php echo $editrow['pic_360'];?>" width="200" />
										<a href="main.php?action=product_add&pid=<?php echo $_GET['pid'];?>&delimg=<?php echo $editrow['pic_360']; ?>" class="btn btn-sm btn-info mt-2">Delete Image</a>
										<?php
									}
									?>
								</div>
							</div>
						</div>
						<!-- /.card-body -->

						<div class="card-footer">
							<button type="submit" value="1" name="sbmt_btn" class="btn btn-primary"><?php echo ($_GET['pid'] ? "Update" : "Add"); ?></button>
						</div>
					</form>
				</div>
			</div>
			<!-- /.col-->
		</div>
	</section>
	<!-- /.content -->
</div>


PK 99