query("SELECT * FROM inbox WHERE inbox_id = '".$page."' LIMIT 1"); if ($mysqli_page->num_rows > 0){ // keep query value in array $row_page = $mysqli_page->fetch_array(MYSQLI_ASSOC) ; $submit_type = 'edit' ; } // update database if ( isset($type) && ( $type == 'new' || $type == 'edit' ) && $_POST['hide'] == 1 ){ $title = escapeString($_POST['title']) ; $description = escapeString($_POST['description']) ; if ( $page == '' ){ $mysqli->query("INSERT INTO inbox ( user_id, created_at ) VALUES ( '".$row_user['user_id']."', '".TODAYDATE."' )") ; $page = $mysqli->insert_id ; } // resize image // set image in variable $image = $_FILES["image"]["name"] ; $image_query = '' ; $remove_photo = $_POST['remove_photo'] ; if ( $remove_photo == 1 ){ $image = '' ; $image_query = "file = '', file_type = ''," ; }else{ if ( $image != '' ){ $get_image = pathinfo($image) ; if ( $get_image['extension'] == 'pdf' ){ $file_name = $page.'-'.time().'.pdf' ; copy($_FILES["image"]["tmp_name"], 'uploads/Inbox/'.$file_name) ; $image_query= "file = '".$file_name."', file_type = 'pdf'," ; }else{ $create_image = reCreateImage('Inbox', $page, $page, '', $image, $_FILES["image"]["type"], $_FILES['image']['tmp_name']) ; // Image uploads when exists if ($create_image['result'] && is_array($create_image['crop']) && count($create_image['result']) > 0){ $resizeObj = new resize($create_image['original']) ; // Initialise load image foreach($create_image['crop'] as $value){ // Resize image (options: exact, portrait, landscape, auto, crop) $resizeObj -> resizeImage($value['width'], $value['height'], $value['type']) ; $resizeObj -> saveImage($value['source'], 70) ; // Save image } $get_image = pathinfo($create_image['image']) ; $image_query = "file = '".$create_image['image']."', file_type = '".$create_image['extension']."'," ; } } } } // delete all department & receiver $receiver_type = dataFilter($_POST['receiver_type']) ; $receiver_to = $_POST['receiver_to'] ; $receiver_to_dept = $_POST['receiver_to_dept'] ; $selected_staff = [] ; $selected_depart = [] ; if ( $receiver_type == '1' ){ if( !empty( $receiver_to ) ){ for ( $i = 0 ; $i < count($receiver_to) ; $i++ ){ if ( $receiver_to[$i] != '' ){ $reset_staff = $receiver_to[$i] ; $selected_staff[$reset_staff] = $reset_staff ; } } } }else{ if( !empty( $receiver_to_dept ) ){ $array_depart = [] ; for ( $i = 0 ; $i < count($receiver_to_dept) ; $i++ ){ $department_id = $receiver_to_dept[$i] ; if ( $department_id != '' ){ // save into department $selected_depart[]= $department_id ; // check department staff $reset_depart = str_replace( ['(', ')'], '', $department_id ) ; $get_depart_staff = $mysqli->query( "SELECT staff_id FROM staff_department WHERE deleted_at IS NULL AND department_id = '".$reset_depart."'") ; if ( $get_depart_staff->num_rows > 0 ){ while ( $row_depart_staff = $get_depart_staff->fetch_assoc() ){ if ( !in_array($row_depart_staff['staff_id'], $array_depart) ){ $array_depart[] = $row_depart_staff['staff_id'] ; $selected_staff[$row_depart_staff['staff_id']] = $row_depart_staff['staff_id'] ; } } } } } } } $related_staff = $selected_staff ; $selected_staff = ( arrayCheck($selected_staff) ? '/'.implode( '/', $selected_staff ).'/' : '' ) ; $selected_depart = ( arrayCheck($selected_depart) ? '/'.implode( '/', $selected_depart ).'/' : '' ) ; // update database $mysqli->query("UPDATE inbox SET ".$image_query." staff_id = '".$selected_staff."', department_id = '".$selected_depart."', receiver_type = '".escapeString($_POST['receiver_type'])."', view_format = '".escapeString($_POST['view_format'])."', title = '".$title."', description = '".$description."', content = '".escapeString($_POST['content'])."', video_url = '".escapeString($_POST['video_url'])."' WHERE inbox_id = '".$page."'") ; $mysqli->query( "UPDATE `staff_inbox_view` SET deleted_at = '".TODAYDATE."' WHERE inbox_id = '".$page."'" ) ; foreach ( $related_staff as $k => $v ){ pushToUserCron( 'inbox', $page, $v, $title, $description, $page ) ; $mysqli->query( "INSERT INTO staff_inbox_view ( inbox_id, staff_id, is_read ) VALUES ( '".$page."', '".$v."', '0' )" ) ; } // refresh page header("Location:inbox.php?page_mode=edit&page=".$page."&success=1") ; $_SESSION['system_result'] = 'success-updated' ; exit ; } // get all requires // get all staff $staff_list = [] ; $mysqli_staff = $mysqli->query("SELECT staff_id, staff_name, staff_idno FROM staff WHERE ( staff_date_resigned IS NULL || staff_date_resigned = '0000-00-00' || staff_date_resigned >= '".TODAYDATE."' ) AND deleted_at IS NULL ".$user_branch_permission_sql . ( $get_user_tier['check'] ? " AND staff_tier IN ( ".implode(', ', $get_user_tier['tiers'])." )" : '' ) ) ; if ( $mysqli_staff->num_rows > 0 ){ while ( $row_staff = $mysqli_staff->fetch_assoc() ){ $staff_list[$row_staff['staff_id']] = dataFilter($row_staff['staff_name']) . ' ( ' . dataFilter($row_staff['staff_idno']) . ' )' ; } } // get all requires $department_list = [] ; $mysqli_department = $mysqli->query("SELECT a.department_id, b.department_desc FROM setting_department a LEFT JOIN setting_department_translation b ON ( a.department_id = b.department_id ) WHERE a.deleted_at IS NULL AND b.lang = 'en'") ; if ( $mysqli_department->num_rows > 0 ){ while ( $row_department = $mysqli_department->fetch_assoc() ){ $department_list[$row_department['department_id']] = dataFilter($row_department['department_desc']) ; } } // get all selected staff & department $receiver_staff = ( $row_page['staff_id'] != '' ? explode('/', $row_page['staff_id']) : [] ) ; $receiver_depart = ( $row_page['department_id'] != '' ? explode('/', $row_page['department_id']) : [] ) ; // start header here include 'requires/page_header.php'; include 'requires/page_top.php'; ?>