function add_user($user_id, $real_name, $password, $phone, $email, $full_access, $language)
{
$sql = "INSERT INTO ".TB_PREF."users (user_id, real_name, password, phone, email, full_access, language)
- VALUES ('$user_id', '$real_name', '" . $password ."', '$phone', '$email', $full_access, '$language')";
+ VALUES (".db_escape($user_id).",
+ ".db_escape($real_name).", ".db_escape($password) .",".db_escape($phone).",
+ ".db_escape($email).", $full_access, ".db_escape($language).")";
db_query($sql, "could not add user for $user_id");
}
function update_user_password($user_id, $password)
{
- $sql = "UPDATE ".TB_PREF."users SET password='" . $password . "'
- WHERE user_id = '$user_id'";
+ $sql = "UPDATE ".TB_PREF."users SET password=".db_escape($password) . "
+ WHERE user_id = ".db_escape($user_id);
db_query($sql, "could not update user password for $user_id");
}
function update_user($user_id, $real_name, $phone, $email, $full_access, $language)
{
- $sql = "UPDATE ".TB_PREF."users SET real_name='$real_name', phone='$phone',
- email='$email',
+ $sql = "UPDATE ".TB_PREF."users SET real_name=".db_escape($real_name).
+ ", phone=".db_escape($phone).",
+ email=".db_escape($email).",
full_access=$full_access,
- language='$language'
- WHERE user_id = '$user_id'";
+ language=".db_escape($language)."
+ WHERE user_id = ".db_escape($user_id);
db_query($sql, "could not update user for $user_id");
}
//-----------------------------------------------------------------------------------------------
function update_user_display_prefs($user_id, $price_dec, $qty_dec, $exrate_dec, $percent_dec, $showgl,
- $showcodes, $date_format, $date_sep, $tho_sep, $dec_sep, $theme, $pagesize)
+ $showcodes, $date_format, $date_sep, $tho_sep, $dec_sep, $theme, $pagesize, $show_hints)
{
$sql = "UPDATE ".TB_PREF."users SET
- prices_dec=$price_dec,
- qty_dec=$qty_dec,
- rates_dec=$exrate_dec,
- percent_dec=$percent_dec,
- show_gl=$showgl,
- show_codes=$showcodes,
- date_format=$date_format,
- date_sep=$date_sep,
- tho_sep=$tho_sep,
- dec_sep=$dec_sep,
- theme='$theme',
- page_size='$pagesize'
- WHERE user_id = '$user_id'";
+ prices_dec=".db_escape($price_dec).",
+ qty_dec=".db_escape($qty_dec).",
+ rates_dec=".db_escape($exrate_dec).",
+ percent_dec=".db_escape($percent_dec).",
+ show_gl=".db_escape($showgl).",
+ show_codes=".db_escape($showcodes).",
+ date_format=".db_escape($date_format).",
+ date_sep=".db_escape($date_sep).",
+ tho_sep=".db_escape($tho_sep).",
+ dec_sep=".db_escape($dec_sep).",
+ theme=".db_escape($theme).",
+ page_size=".db_escape($pagesize).",
+ show_hints=$show_hints
+ WHERE user_id = ".db_escape($user_id);
db_query($sql, "could not update user display prefs for $user_id");
}
function update_user_visitdate($user_id)
{
$sql = "UPDATE ".TB_PREF."users SET last_visit_date='". date("Y-m-d H:i:s") ."'
- WHERE user_id='$user_id'";
+ WHERE user_id=".db_escape($user_id);
db_query($sql, "could not update last visit date for user $user_id");
}