2400, 'use_only_cookies' => true, ]); require_once '../root_login.php'; // The following makes sure the pages load using HTTPS /*if ($_SERVER['HTTPS'] != "on") { $url = "https://". $_SERVER['SERVER_NAME'] . $_SERVER['REQUEST_URI']; header("Location: $url"); exit; } */ if ($_SESSION["memberid"] == "") { header("Location: wslogin.php"); exit(); } //$_SESSION['id'] = $_POST['view']; //$_SESSION['groupid'] = $_POST['groupid']; ?>

Post Attendee Payments

$
prepare('DELETE FROM flush WHERE memberid = :memberid'); $stmt->bindValue(':memberid', $_SESSION['memberid'], PDO::PARAM_INT); $stmt->execute(); $_SESSION['flush'] = 0; echo ''; } if($_POST['fetch']) { $id = $_POST['view']; // Pass this to see which attendee was selected in the Selection box options $_SESSION['id'] = $_POST['view']; $i = 0; // Set to use below in alternating bg-colors with function getbgc($i) if($id == '') { exit(); // Nothing was selected } else { try { $stmt = $db->prepare('SELECT fname, lname, amount, subsidy, last_payment, amount_paid, balance, a.groupid, a.attendeeid, h.historyid FROM history AS h INNER JOIN attendees AS a ON a.attendeeid = h.attendeeid where h.attendeeid = :id ORDER BY h.historyid DESC LIMIT 1'); $stmt->bindValue(':id', $_SESSION['id'], PDO::PARAM_INT); $stmt->execute(); $result = $stmt->fetchAll(); ?>
0) { ?> ' ?>
F-Name L-Name Group ID Weekly Amt Subsidy Last Payment Amount Paid Balance
' ?>
alert("There was an unforeseen database error."+"\\n"+"The database administrator has been contacted."+"\\n"+"\\n"+"Please try again later. Thank you"); '; mail_error($ex); } } } elseif($_POST['postpayment']) { if($_POST['view'] == '') { // Nothing was selected failed_fetch(); } if($_SESSION['btnhs'] == 3) { /* At login, this var is set to 3. If it is still set to 3 at this point, it means the user made a name selection but did not click FETCH. */ failed_fetch(); } if($_SESSION['btnhs'] == 0) { // Set to 1 here so the user can use the Post button event $_SESSION['btnhs'] = 1; // Increase to 1 to eliminate double-clicking Post on one Fetch } elseif($_SESSION['btnhs'] = 1) { // If var == 1 then exit coz the user is double-clicking Post on just one Fetch failed_fetch(); } if (empty($_POST["payment"])) { $payment = "0.0"; } else { $payment = test_input($_POST["payment"]); if (!preg_match("/^[0-9.]*$/",$payment)) { $paymentErr = "* Numerals and decimal point only"; } } if(empty($paymentErr)) { $newbal = $_SESSION['bal1'] - $payment; // Refer to line 299 $id = $_SESSION['id']; try { $stmt = $db->prepare('SELECT * FROM history WHERE attendeeid = :id ORDER BY historyid DESC LIMIT 1'); $stmt->bindParam(':id', $id, PDO::PARAM_INT); $stmt->execute(); //$row_count = $stmt->rowCount(); $result = $stmt->fetchAll(); foreach($result as $row) { $amount = $row[1]; $subsidy = $row[2]; $last_pymt = $row[3]; $groupid = $row[7]; $attid = $row[9]; $memid = $row[10]; } $id = $_SESSION['id']; if($payment > 0) { // Obviously the attendee was present (we hope) $attend = "Y"; // Set the attend flag to reflect they attended the meeting /* Since $payment is greater than 0, the attendee made a payment and in attendance for the meeting. Therefore, last_payment and attendance are set to CURDATE(). */ $stmt = $db->prepare('INSERT INTO history(amount, subsidy, last_payment, amount_paid, balance, attend, attend_date, groupid, attendeeid, memberid) VALUES(:amt, :sub, CURDATE(), :amt_paid, :newbal, :attend, CURDATE(), :groupid, :attid, :memid)'); $stmt->bindParam(':amt', $amount, PDO::PARAM_STR); $stmt->bindParam(':sub', $subsidy, PDO::PARAM_STR); $stmt->bindParam(':amt_paid', $payment, PDO::PARAM_STR); $stmt->bindParam(':newbal', $newbal, PDO::PARAM_STR); // Refer to line 333 $stmt->bindParam(':attend', $attend, PDO::PARAM_STR); $stmt->bindParam(':groupid', $groupid, PDO::PARAM_STR); $stmt->bindParam(':attid', $attid, PDO::PARAM_STR); $stmt->bindParam(':memid', $memid, PDO::PARAM_STR); $stmt->execute(); } else { $attend = "Y"; // Set the attend flag to reflect they attended the meeting /* Since $payment equals 0, the attendee didn't make a payment but was present for the meeting. Therefore, last_payment will reflect the last_payment made and attendance is set to CURDATE(). */ $stmt = $db->prepare('INSERT INTO history(amount, subsidy, last_payment, amount_paid, balance, attend, attend_date, groupid, attendeeid, memberid) VALUES(:amt, :sub, :last, :amt_paid, :newbal, :attend, CURDATE(), :groupid, :attid, :memid)'); $stmt->bindParam(':amt', $amount, PDO::PARAM_STR); $stmt->bindParam(':sub', $subsidy, PDO::PARAM_STR); $stmt->bindParam(':last', $last_pymt, PDO::PARAM_STR); $stmt->bindParam(':amt_paid', $payment, PDO::PARAM_STR); $stmt->bindParam(':newbal', $newbal, PDO::PARAM_STR); // Refer to line 333 $stmt->bindParam(':attend', $attend, PDO::PARAM_STR); $stmt->bindParam(':groupid', $groupid, PDO::PARAM_STR); $stmt->bindParam(':attid', $attid, PDO::PARAM_STR); $stmt->bindParam(':memid', $memid, PDO::PARAM_STR); $stmt->execute(); } $stmt = $db->prepare('UPDATE balances SET balance = :newbal WHERE attendeeid = :id'); $stmt->bindParam(':newbal', $newbal, PDO::PARAM_STR); $stmt->bindParam(':id', $id, PDO::PARAM_STR); $stmt->execute(); // Delete the attendee from the flush Table $stmt = $db->prepare('DELETE FROM flush WHERE attendeeid = :attid'); $stmt->bindParam(':attid', $attid, PDO::PARAM_STR); $stmt->execute(); $stmt = $db->prepare('SELECT fname, lname, amount, subsidy, last_payment, amount_paid, balance, a.groupid, a.attendeeid, h.historyid FROM history AS h INNER JOIN attendees AS a ON a.attendeeid = h.attendeeid where h.attendeeid = :id ORDER BY h.historyid DESC LIMIT 1'); $stmt->bindValue(':id', $id, PDO::PARAM_INT); $stmt->execute(); $result = $stmt->fetchAll(); ?>
0) { ?> ' ?>
*** ACCOUNT UPDATED ***
F-Name L-Name Group ID Weekly Amt Subsidy Last Payment Amount Paid Balance
' ?> alert("There was an unforeseen database error."+"\\n"+"The database administrator has been contacted."+"\\n"+"\\n"+"Please try again later. Thank you"); '; mail_error($ex); } } } if($_POST['flush']) { try { $stmt = $db->prepare('SELECT attendeeid, memberid FROM flush WHERE memberid = :memberid'); $stmt->bindValue(':memberid', $_SESSION['memberid'], PDO::PARAM_INT); $stmt->execute(); $result = $stmt->fetchAll(); foreach($result as $row) { $one = $row[0]; $stmt = $db->prepare('SELECT amount, subsidy, last_payment, amount_paid, balance, attend_date, groupid, attendeeid, memberid FROM history WHERE attendeeid = :attendeeid ORDER BY historyid DESC LIMIT 1 '); $stmt->bindValue(':attendeeid', $one, PDO::PARAM_INT); $stmt->execute(); $result = $stmt->fetchAll(); foreach($result as $row) { $amount = $row[0]; $subsidy = $row[1]; $last_pymt = $row[2]; $amtpaid = $row[3]; $balance = $row[0] + $row[4]; $groupid = $row[6]; $attid = $row[7]; $memid = $row[8]; $stmt = $db->prepare('INSERT INTO history(amount, subsidy, last_payment, amount_paid, balance, attend_date, groupid, attendeeid, memberid) VALUES(:amt, :sub, :lastpayment, :amt_paid, :bal, CURDATE(), :groupid, :attid, :memid)'); $stmt->bindParam(':amt', $amount, PDO::PARAM_STR); $stmt->bindParam(':sub', $subsidy, PDO::PARAM_STR); $stmt->bindParam(':lastpayment', $last_pymt, PDO::PARAM_STR); $stmt->bindParam(':amt_paid', $amtpaid, PDO::PARAM_STR); $stmt->bindParam(':bal', $balance, PDO::PARAM_STR); $stmt->bindParam(':groupid', $groupid, PDO::PARAM_STR); $stmt->bindParam(':attid', $attid, PDO::PARAM_STR); $stmt->bindParam(':memid', $memid, PDO::PARAM_STR); $stmt->execute(); } } // Delete the attendees from flush Table via the memberid as the history Table is now updated for attendees // who were not present $stmt = $db->prepare('DELETE FROM flush where memberid = :memberid'); $stmt->bindParam(':memberid', $memid, PDO::PARAM_STR); $stmt->execute(); $_SESSION['flush'] = 0; } catch (PDOException $ex) { echo ''; mail_error($ex); } } }// Last Brace function failed_fetch() { echo ''; exit; } function test_input($data) { $data = trim($data); $data = stripslashes($data); $data = htmlspecialchars($data); return $data; } function getbgc($trcount) { // Nice way to alternate table row colors $blue="background-color: #191970;"; // Midnight Blue $black="background-color: #000;"; $odd= $trcount % 2; if($odd == 1){ return $blue; } else{ return $black; } } function mail_error($ex) { $from = "registererror@dfwit.co"; // this is the sender's Email address $to = "error@dfwit.co"; $subject = "ERROR!"; $message = "An ERROR occured in wspostpayments.php: ".$ex."\n\nwith user: ".$_SESSION['uname']."\n\n"."Upon resolution, email them."; $headers = "From:" . $from; mail($to,$subject,$message,$headers); header("Location: error.html"); } ?>