Файл: groups/handler/edit_goods.php
Строк: 29
<?php
if (!empty($_POST['name']))
{
$name = check($_POST['name']);
$about = check($_POST['about']);
$price = abs(intval($_POST['price']));
$price_v = check($_POST['price_v']);
$marka = check($_POST['marka']);
$country = check($_POST['country']);
$delivery = check($_POST['delivery']);
$pays = check($_POST['pays']);
$guarantee = check($_POST['guarantee']);
$material = check($_POST['material']);
$regions = check($_POST['regions']);
$back = check($_POST['back']);
$name = substr($name, 0, 500);
$about = substr($about, 0, 10000);
$price = substr($price, 0, 11);
$price_v = substr($price_v, 0, 1000);
$marka = substr($marka, 0, 500);
$country = substr($country, 0, 500);
$delivery = substr($delivery, 0, 500);
$pays = substr($pays, 0, 500);
$guarantee = substr($guarantee, 0, 500);
$material = substr($material, 0, 500);
$regions = substr($regions, 0, 500);
$back = substr($back, 0, 500);
if (empty($name)) $err = true;
if ($err != true)
{
DB::$dbs->query("UPDATE groups_shop_goods SET
`name` = ?,
`about` = ?,
`price` = ?,
`price_v` = ?,
`marka` = ?,
`country` = ?,
`delivery` = ?,
`pays` = ?,
`guarantee` = ?,
`material` = ?,
`regions` = ?,
`back` = ?
WHERE `id` = ? ", array(
$name,
$about,
$price,
$price_v,
$country,
$marka,
$delivery,
$pays,
$guarantee,
$material,
$regions,
$back,
$gid));
echo ok(lang('Изменения сохранены','Зміни збережені'));
}
}
?>