Det er da helt rigtigt :-) Min fejl! Her er koden til uploadsiden:
<?php require_once('../Connections/test.php'); ?>
<?php
// Buzz inet PHPLS03 - Check User Session is set
session_start();
if(!isset($HTTP_SESSION_VARS['login'])){
header("Location: /doks/fejl.php");
}
?>
<?php
// Buzz inet PHPLS06 - User Details
session_start();
$varSearch_rsUserDetails = "1";
if (isset($HTTP_SESSION_VARS['login'])) {
$varSearch_rsUserDetails = (get_magic_quotes_gpc()) ? $HTTP_SESSION_VARS['login'] : addslashes($HTTP_SESSION_VARS['login']);
}
mysql_select_db($database_test, $test);
$query_rsUserDetails = sprintf("SELECT * FROM udlejer WHERE email = '%s'", $varSearch_rsUserDetails);
$rsUserDetails = mysql_query($query_rsUserDetails, $test) or die(mysql_error());
$row_rsUserDetails = mysql_fetch_assoc($rsUserDetails);
$totalRows_rsUserDetails = mysql_num_rows($rsUserDetails);
mysql_select_db($database_test, $test);
$query_produkter = "SELECT Id, produkt, antal, beskrivelse, forestillinger, udlejerID, katagori FROM produkter";
$produkter = mysql_query($query_produkter, $test) or die(mysql_error());
$row_produkter = mysql_fetch_assoc($produkter);
$totalRows_produkter = mysql_num_rows($produkter);
session_start();
?>
<?php
//initialize the session
session_start();
// ** Logout the current user. **
$logoutAction = $_SERVER['PHP_SELF']."?doLogout=true";
if ((isset($_SERVER['QUERY_STRING'])) && ($_SERVER['QUERY_STRING'] != "")){
$logoutAction .="&". htmlentities($_SERVER['QUERY_STRING']);
}
if ((isset($_GET['doLogout'])) &&($_GET['doLogout']=="true")){
//to fully log out a visitor we need to clear the session varialbles
session_unregister('MM_Username');
session_unregister('MM_UserGroup');
$logoutGoTo = "/doks/farvel.php";
if ($logoutGoTo) {
header("Location: $logoutGoTo");
exit;
}
}
?>
<?php
// *** Simply Upload ***
require_once("FXInc/uploadAction.inc");
$errMsg = "";
$action = true;
$noPath = false;
$rename = false;
$delete = false;
$FX_successRedirect = "";
$FX_DirPath = "../upload/" . $row_rsUserDetails['Id'] . "/";
$FX_typearray = array("image");
$FX_extarray = array("jpg","gif","png");
$FX_size = "300000";
$FX_fields = array();
if ((isset($HTTP_POST_VARS["FX_upload"])) && ($HTTP_POST_VARS["FX_upload"] == "form2")) {
require_once("FXInc/upload.inc");
}
function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "")
{
$theValue = (!get_magic_quotes_gpc()) ? addslashes($theValue) : $theValue;
switch ($theType) {
case "text":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "long":
case "int":
$theValue = ($theValue != "") ? intval($theValue) : "NULL";
break;
case "double":
$theValue = ($theValue != "") ? "'" . doubleval($theValue) . "'" : "NULL";
break;
case "date":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "defined":
$theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
break;
}
return $theValue;
}
$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
$editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}
if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form2")) {
$insertSQL = sprintf("INSERT INTO produkter (produkt, antal, beskrivelse, forestillinger, billed, udlejerID, katagori, halvaalig, helaarlig) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s)",
GetSQLValueString($_POST['produkt'], "text"),
GetSQLValueString($_POST['antal'], "text"),
GetSQLValueString($_POST['beskrivelse'], "text"),
GetSQLValueString($_POST['forestillinger'], "text"),
GetSQLValueString($_POST['billede'], "text"),
GetSQLValueString($_POST['udlejerID'], "text"),
GetSQLValueString($_POST['select'], "text"),
GetSQLValueString(isset($_POST['halvaarlig']) ? "true" : "", "defined","'Ja'","'Nej'"),
GetSQLValueString(isset($_POST['helaarlig']) ? "true" : "", "defined","'Ja'","'Nej'"));
mysql_select_db($database_test, $test);
$Result1 = mysql_query($insertSQL, $test) or die(mysql_error());
$insertGoTo = "/doks/bekraeft.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
}
?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "
http://www.w3.org/TR/html4/loose.dtd"><html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<title>Untitled Document</title>
<script language="JavaScript" type="text/JavaScript">
<!--
function FX_processPop() {
var theLeft = (screen.width - 240)/2;
var theRight = (screen.height - 100)/2;
document.processWindow = window.open('FXInc/ProcessWindow.htm','process','width=240,height=100,left='+theLeft+',top='+theRight);
window.onunload = function () {document.processWindow.close()};
}
//-->
</script>
</head>
<body>
<h2>Velkommen til administrationssiden: 2 <br>
</h2>
<table width="250" border="0" cellspacing="2" cellpadding="2">
<tr>
<td><?php echo $row_rsUserDetails['Id']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['Firmanavn']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['Kontaktperson']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['Adresse']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['Post']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['Bynavn']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['Tlf']; ?></td>
</tr>
<tr>
<td><?php echo $row_rsUserDetails['email']; ?></td>
</tr>
<tr>
<td align="right"><form name="form1" method="post" action="">
<a href="<?php echo $logoutAction ?>">Log out</a>
</form></td>
</tr>
</table>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<form action="<?php echo $editFormAction; ?>" method="post" enctype="multipart/form-data" name="form2" onSubmit="FX_processPop()" >
<table align="center">
<tr valign="baseline">
<td nowrap align="right">Produkt:</td>
<td><input type="text" name="produkt" value="" size="32"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Antal:</td>
<td><input type="text" name="antal" value="" size="32"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Beskrivelse:</td>
<td><input type="text" name="beskrivelse" value="" size="32"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Forestillinger:</td>
<td><input type="text" name="forestillinger" value="" size="32"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Billede:</td>
<td><input name="billede" type="file" id="billede"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Katagori:</td>
<td><select name="select" size="1">
<option>Rekvisit</option>
<option>Kulisse</option>
<option>Kostume</option>
</select></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Halvårlig</td>
<td><input name="halvaarlig" type="checkbox" id="halvaarlig" value="checkbox" checked></td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Helårlig</td>
<td><input name="helaarlig" type="checkbox" id="helaarlig" value="checkbox"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right"> </td>
<td><input type="hidden" name="udlejerID" value="<?php echo $row_rsUserDetails['Id']; ?>" size="32"></td>
</tr>
<tr valign="baseline">
<td nowrap align="right"> </td>
<td><input type="submit" value="Opret"></td>
</tr>
</table>
<input type="hidden" name="MM_insert" value="form2">
<input type="hidden" name="FX_upload" value="form2">
</form>
<p> </p>
</body>
</html>
<?php
mysql_free_result($rsUserDetails);
mysql_free_result($produkter);
?>