query("SELECT a.password_id, a.content FROM app_password a LEFT JOIN app_password_translation b ON ( a.password_id = b.password_id ) WHERE a.deleted_at IS NULL AND a.password_type = 'nomination' AND b.lang = 'en'"); if ($mysqli_ck_password->num_rows > 0) { $row_ck_password = $mysqli_ck_password->fetch_array(); } if ($_SESSION['nomination_password'] == '' ){ echo ''; } if($_SESSION['nomination_password'] != $row_ck_password['content']) { unset($_SESSION['nomination_password']); echo ''; } // keep parameter in value $page = escapeString($_GET['page']) ; $page_mode = escapeString($_GET['page_mode']) ; $type = escapeString($_GET['type']) ; $search = escapeString($_GET['search']) ; // active menu bar $active_main_menu = 'service' ; $active_sub_menu = 'form-submission' ; $active_menu = 'form-nomination-list' ; // check permission if ( !permissionCheck($row_user, 'form-nomination-view') ){ header('Location: index.php') ; exit ; } // mode type | all list | new | edit switch($page_mode){ // edit formnomination case 'new' : case 'edit' : // check query exsits $submit_type = 'new' ; $mysqli_page = $mysqli->query("SELECT * FROM formnomination WHERE formnomination_id = '".$page."' LIMIT 1"); if ($mysqli_page->num_rows > 0){ // keep query value in array $row_page = $mysqli_page->fetch_array(MYSQLI_ASSOC) ; $submit_type = 'edit' ; } // update database if ( isset($type) && ( $type == 'new' || $type == 'edit' ) && $_POST['hide'] == 1 ){ // update database $mysqli->query( "UPDATE formnomination SET comment = '".escapeString($_POST['comment'])."', status = '".escapeString($_POST['status'])."' WHERE formnomination_id = '".$page."'" ) ; if ( $row_page['status'] != $_POST['status'] ){ pushToUserCron( 'formnomination', $page, $row_page['staff_id'], 'Nomination', 'Nomination has been update.' ) ; } // refresh page header("Location:app-form-nomination.php?page_mode=edit&page=".$page."&success=1") ; $_SESSION['system_result'] = 'success-updated' ; exit ; } if ( ( $page_mode == 'new' && !permissionCheck($row_user, 'form-nomination-new') ) || ( $page_mode == 'edit' && !permissionCheck($row_user, 'form-nomination-edit') ) ){ header('Location: app-form-nomination.php') ; exit ; } // get all media $media_list = [] ; $mysqli_media = $mysqli->query( "SELECT file, filetype FROM formnomination_media WHERE deleted_at IS NULL AND formnomination_id = '".$page."'" ) ; if ( $mysqli_media->num_rows > 0 ){ while ( $row_media = $mysqli_media->fetch_assoc() ){ $media_list[] = $row_media ; } } // get all staff $staff_list = [] ; $mysqli_staff = $mysqli->query( "SELECT staff_id, staff_name, staff_idno FROM staff WHERE deleted_at IS NULL ".$user_branch_permission_sql) ; if ( $mysqli_staff->num_rows > 0 ){ while ( $row_staff = $mysqli_staff->fetch_assoc() ){ $staff_list[$row_staff['staff_id']] = dataFilter($row_staff['staff_name']) . ' ( ' . dataFilter($row_staff['staff_idno']) . ' )' ; } } // start header here include 'requires/page_header.php'; include 'requires/page_top.php'; ?>