require('bbs/inc/conn.php');
require('bbs/inc/config.php');
require('bbs/inc/func.php');
session_save_path("bbs/session");//session的存取路径
session_start();
if(isset($_REQUEST['page'])){$page=$_REQUEST['page'];}else{$page="";}
if(isset($_REQUEST['work'])){$work=$_REQUEST['work'];}else{$work="";}
if(isset($_REQUEST['id'])){$id=$_REQUEST['id'];}else{$id="";}
if(isset($_SESSION['session_users_nick'])){$session_users_nick=$_SESSION['session_users_nick'];}else{$session_users_nick="";}
if(isset($_SESSION['session_users_pass'])){$session_users_pass=$_SESSION['session_users_pass'];}else{$session_users_pass="";}
if(isset($_REQUEST['author'])){$author=$_REQUEST['author'];}else{$author="";}
if(isset($_REQUEST['title'])){$title=$_REQUEST['title'];}else{$title="";}
if(isset($_REQUEST['msg'])){$msg=$_REQUEST['msg'];}else{$msg="";}
$userip=$_ENV["REMOTE_ADDR"];
$admin=0;
$bordercolordark="blue";
$bordercolorlight="blue";
if($session_users_nick=="chuckliu")$admin=1;
if($session_users_nick=="明亮")$admin=1;
if($work=='del')
{
$sql="select * from users where users_name='$session_users_nick' and userpass='$session_users_pass'";
$result=@mysql_query($sql,$db);
if(($admin=0)&&(!$myrow=@mysql_fetch_array($result)))errorview("您没有管理权限!");
$sql = "delete from notebook where id=$id";
$result = @mysql_query($sql);
?>
朱朱和大头的留言板-删除成功
删除成功
3秒钟自动返回!
exit;
}
if($work=="add"){
?>
朱朱和大头的留言板
}
if($work=="saveadd"){
$dateandtime=time();
$author=str_replace(">",">",$author);
$author=str_replace("<","<",$author);
if($session_level<8)
{
$msg =str_replace(">",">",$msg);
$msg =str_replace("<","<",$msg);
$title =str_replace(">",">",$title);
$title =str_replace("<","<",$title);
}
$category="zzbook";
$boardid=0;
$sql = "Insert into notebook(date,author,title,msg,ip,board,email,category)
values($dateandtime,'$author','$title','$msg','$userip',$boardid,'$email','$category')";
$result = @mysql_query($sql);
Header("Location: zzbook.php");
}
if($work=="")
{
if($ziduan=="all")
{
$ziduan1="all";
$ziduan="author like '%$key%' or title like '%$key%' or msg";
}else{$ziduan1=$ziduan;}
?>
朱朱和大头的留言板
$limit=20;
if($action=="search"){
$sql="select count(*) as count from notebook where $ziduan like '%$key%' and category='zzbook'";
}else{$sql="select count(*) as count from notebook where category='zzbook'";
}
$result=@mysql_query($sql);
$count=@mysql_result($result,0,"count");
$allpages=ceil($count/$limit); //取得页数
if ($page<1) $page=1;
if ($page>$allpages) $page=$allpages;
$prepage=$page-1;
$nextpage=$page+1;
$prepage=($prepage<1) ? 1 : $prepage; //如果上一页小于1,则为1,否则为上一页
if ($nextpage>$allpages) $nextpage=$allpages;
$offset=($page-1)*$limit;
if($action=="search"){
$sql="select * from notebook where $ziduan like '%$key%' and category='zzbook' order by date desc limit $offset,$limit";
}else{
$sql="select * from notebook where category='zzbook' order by date desc limit $offset,$limit";
}
if(!$result = @mysql_query($sql, $db))
die("错误-无法连接数据库!");
if($myrow=@mysql_fetch_array($result)) {
$i=0;
echo"