Файл: elik.php
Строк: 81
<?php
include ("niz/head.php");
include ("db_bse/bssest.php");
$g=mysql_query("SELECT * FROM `turaga_pers` WHERE `nick`='$nick' AND `pass`='$pass' LIMIT 1");
if(mysql_num_rows($g)==1){
include ("niz/verh.php");
switch($_GET[mod]){
default:
$req = mysql_query("SELECT * FROM `turaga_res` WHERE `usr` = '$nick' and `tip`='elexir' ");
////////////////////////////
$avto=mysql_num_rows($req);
if($avto>=1){
While($mag = mysql_fetch_array($req))
{
echo"<img src="pictures/eleksir/$mag[name].png" height=32 width=32> <a href="elik.php?mod=info&act=elik&id=$mag[id]">$mag[name]</a>
($mag[kol] штук) [<a href="elik.php?mod=ok&id=$mag[id]">выпить</a>]<br/>";
}
}else{
echo"У вас нет эликсиров!<br/>";
}
break;
case 'info':
if($_GET[act]==elik){
$req = mysql_query("SELECT * FROM `turaga_res` WHERE `usr` = '$nick' and `id`='".mysql_real_escape_string($_GET['id'])."'");
$avto=mysql_num_rows($req);
if($avto==0){
echo'Ошибка!';
include ("niz/niz.php");
exit;
}
$mag = mysql_fetch_array($req);
switch($mag[tip]){
case 'elexir':
$tip='Эликсир';
break;
}
if($mag[what]==hp){
$tips='<img src="/pictures/icons/hp.png" alt="*"/>';
}else{
$tips='<img src="/pictures/icons/energy.gif" alt="*"/>';}
echo"<b>$mag[name]</b><br/>
<img src="pictures/eleksir/$mag[name].png" height=32 width=32><br/>
Тип: $tip<br/>
Восстанавливает: $mag[give] $tips<br/>
Количество: $mag[kol]<br/>
";
}
break;
case 'ok':
$req = mysql_query("SELECT * FROM `turaga_res` WHERE `usr` = '$nick' and `id`='".mysql_real_escape_string($_GET['id'])."'");
$avto=mysql_num_rows($req);
if($avto==0){
echo'Такого эликсира нет!';
include ("niz/niz.php");
exit;
}
$mag = mysql_fetch_array($req);
if($mag[tip]!='elexir'){
echo'Ошибка!';
include ("niz/niz.php");
exit;
}
switch($mag[what]){
case 'hp':
$newp=$mag[give]+$hp;
if($newp>$hp2s){$newp=$hp2s;}
mysql_query("UPDATE `turaga_pers` SET `hp` = '$newp' WHERE nick = '$nick'");
if($mag[kol]==1){
mysql_query("DELETE FROM `turaga_res` WHERE `usr` = '$nick' and `id`='".mysql_real_escape_string($_GET['id'])."'");
}else{
$mag[kol]--;
mysql_query("UPDATE turaga_res SET kol = '$mag[kol]' WHERE `usr` = '$nick' and `id`='".mysql_real_escape_string($_GET['id'])."'");
}
echo"Вы успешно выпили: <font color=red>$mag[name]</font>, вам восстановлено +$mag[give] <img src='/pictures/icons/hp.png' alt='*'/><br/>";
break;
case 'mp':
$newp=$mag[give]+$energy;
if($newp>50){$newp=50;}
mysql_query("UPDATE `turaga_pers` SET `energy` = '$newp' WHERE nick = '$nick'");
if($mag[kol]==1){
mysql_query("DELETE FROM `turaga_res` WHERE `usr` = '$nick' and `id`='".mysql_real_escape_string($_GET['id'])."'");
}else{
$mag[kol]--;
mysql_query("UPDATE turaga_res SET kol = '$mag[kol]' WHERE `usr` = '$nick' and `id`='".mysql_real_escape_string($_GET['id'])."'");
}
echo"Вы успешно выпили: <font color=red>$mag[name]</font>, вам восстановлено +$mag[give] <img src='/pictures/icons/energy.gif' alt='*'/><br/>";
break;
}
}
}else{
echo "Пройдите авторизацию!";
echo "<hr><a href="index.php">На главную</a>";
}
include ("niz/niz.php");
?>