Файл: bag.php
Строк: 60
<?php
# Заказчик: ST34RT
# Исполнитель: TJerry
# Контакты: 4play.IN
# Спасибо за обращение TJCompany.
$title = 'Мой рюкзак';
require_once 'system/connect.php';
require_once 'system/head.php';
no_auth(); //Закроем от незарегистрированных
if(isset($_REQUEST['thingUse'])){
$thingID = abs(intval($_POST['thingID']));
$checkThing = mysql_fetch_array(mysql_query("SELECT * FROM `user_things` WHERE `id` = '".$thingID."' "));
if(mysql_result(mysql_query("SELECT COUNT(*) FROM `user_things` WHERE `id` = '".$thingID."' AND `id_user` = '".$user['id']."' "),0) == '0') error('У вас нет такой вещи');
elseif(mysql_result(mysql_query("SELECT COUNT(*) FROM `user_things` WHERE `id` = '".$thingID."' AND `id_user` = '".$user['id']."' AND `used` = '1' "),0) != '0') error('Вещь уже одета');
else {
mysql_query("UPDATE `user_things` SET `used` = '0' WHERE `type` = '".$checkThing['type']."' and `id_user` = '".$user['id']."'");
mysql_query("UPDATE `user_things` SET `used` = '1' WHERE `id` = '".$thingID."'"); // Одеваем вещь
error('Вещь одета');
}
}
$k_post = mysql_result(mysql_query("SELECT COUNT(*) FROM `user_things` WHERE `id_user` = '".$user['id']."' AND `used` = '0' "),0);
$k_page = k_page($k_post,10);
$page = page($k_page);
$start = 10*$page-10;
$ms = mysql_query("SELECT * FROM `user_things` WHERE `id_user` = '".$user['id']."' AND `used` = '0' ORDER BY `id` DESC LIMIT $start, 10");
while($fine = mysql_fetch_assoc($ms)){
$things = mysql_fetch_array(mysql_query("SELECT * FROM `things` WHERE `id` = '".$fine['id_things']."' "));
echo '<div class="razd55">';
echo '<table width="100%">';
echo '<tr>';
echo '<td valign="top" width="70px">';
echo '<img src="'.$things['img'].'" width="64px;" alt="'.$things['name'].'" title="'.$things['name'].'" />';
echo '</td>';
echo '<td valign="top">';
echo '<div class="sh"> '.$things['name'].' </div>';
echo '<p class="tj">';
echo '<img src="/system/css/ico/power.png" alt="*" height="14"/> '.intval($fine['power']).' ';
echo '<img src="/system/css/ico/protection.png" alt="*" height="14"/> '.intval($fine['protection']).' ';
echo '<img src="/system/css/ico/agility.png" alt="*" height="14"/> '.intval($fine['agility']).' <br/>';
echo '</p>';
echo '</td>';
echo '</tr>';
echo '</table>';
echo '<form action="" method="POST">';
echo '<input type="hidden" name="thingID" value="'.$fine['id'].'" />';
echo '<input type="submit" name="thingUse" value="Одеть">';
echo '</form>';
echo '</div>';
}
if($k_post == '0') error('Ваш рюкзак пуст');
require_once 'system/foot.php';
?>