-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathAddRating.php
More file actions
50 lines (36 loc) · 1.25 KB
/
Copy pathAddRating.php
File metadata and controls
50 lines (36 loc) · 1.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
<?php
/**
* Created by PhpStorm.
* User: dronca
* Date: 11/27/18
* Time: 9:19 PM
*/
header("Access-Control-Allow-Origin: *");
header("Access-Control-Allow-Headers: access");
header("Access-Control-Allow-Methods: POST");
header("Access-Control-Allow-Credentials: true");
header('Content-Type: application/json');
include_once 'lib/DBHelper.php';
$dbh = new DBHelper();
$user = $_POST["user"];
$rating = $_POST["rating"];
$comments = $_POST["comments"];
$productCode = $_POST["productCode"];
$domain = $_POST["domain"];
$safeComments = $dbh->escapeString($comments);
$query = "SELECT * FROM Roncabeanz.Ratings WHERE productCode = $productCode AND uid = '$user'";
$result = $dbh->query($query);
if($result->num_rows != 0){
$query = "UPDATE Roncabeanz.Ratings SET rating = $rating, comments = '$safeComments' WHERE productCode = $productCode AND uid = '$user'";
}
else {
$query = "INSERT INTO Roncabeanz.Ratings (productCode, uId, domain, rating, comments) VALUES ($productCode, '$user', '$domain', $rating, '$safeComments') ";
}
error_log($query);
$dbh->query($query);
$returnAddress = $_GET["retAddr"];
if($returnAddress == "") {
$returnAddress = "http://www.roncabeanz.com";
}
$hdr = "Location: $returnAddress?userToken=" . $uToken;
header($hdr);