01.
if
(
$_POST
[
"action"
]==
"add"
)
02.
{
03.
04.
$strResultOrderID
=select(
"orderid"
,
"where 1"
);
05.
$strOrderID
=
"ORDER-"
.
substr
(
"000000000$strResultOrderID[OrderID]"
, -6);
06.
07.
08.
$strMemberID
=select(
"member"
,
"where 1 and Email='"
.
$_SESSION
[
"strEmail"
].
"'"
);
09.
10.
11.
$sql
=
"insert into cusorder (OrderNo,MemberID,Total,Date) Values ('$strOrderID','$strMemberID[MemberID]','$_POST[txtTotal]','"
.
date
(
"Y-m-d"
).
"')"
;
12.
$dbquery
= mysql_query(
$sql
);
13.
14.
15.
16.
for
(
$i
=0;
$i
<=
count
(
$_SESSION
[
"strProductID"
]);
$i
++)
17.
{
18.
$result
=select(
"product"
,
"where 1=1 and ProductID='"
.
$_SESSION
[
"strProductID"
][
"$i"
].
"' "
);
19.
if
(
$result
)
20.
{
21.
$Proid
=
$_SESSION
[
"strProductID"
][
"$i"
];
22.
$Quanlity
=
$_SESSION
[
"strQuanlity"
][
"$i"
];
23.
$sql
=
"update product set Stock=Stock-$Quanlity where ProductID='$Proid'"
;
24.
$dbquery
= mysql_query(
$sql
);
25.
26.
$sql
=
"insert into order_detail (OrderNo,ProductID,Quanlity) Values ('$strOrderID','"
.
$_SESSION
[
"strProductID"
][
"$i"
].
"','"
.
$_SESSION
[
"strQuanlity"
][
"$i"
].
"')"
;
27.
$dbquery
= mysql_query(
$sql
);
28.
}
29.
}
30.
31.
32.
update(
"orderid"
,
"OrderID=OrderID+1"
,
"where 1"
);
33.
34.
$_SESSION
[
"strP"
]=
""
;
35.
$_SESSION
[
"strProductID"
]=
""
;
36.
$_SESSION
[
"strQuanlity"
]=
""
;
37.
session_write_close();
38.
39.
header(
"location:ordercomplete.php?OrderID=$strOrderID"
);
40.
}