Fix the SQL for reservations class modification.
[Project_webapp.git] / includes / formreservations.php
index 479489b335452a4a35d9dec6d4390b95fdd76e7f..e8a162c254e9e286d093f3f8107327130a949ca4 100644 (file)
@@ -1,13 +1,17 @@
 <?php
 $form_flight_id = filter_input(INPUT_POST, "flight_id", FILTER_SANITIZE_STRING);
 $form_class_name = filter_input(INPUT_POST, "class_name", FILTER_SANITIZE_STRING);
-$form_modify = filter_input(INPUT_POST, "modify", FILTER_SANITIZE_STRING);
 $form_cancel = filter_input(INPUT_POST, "cancel", FILTER_SANITIZE_STRING);
 
-if (isset($form_modify) && isset($form_flight_id) && isset($form_class_name)) {
-    echo $form_modify;
-} elseif (isset($form_cancel) && isset($form_flight_id) && isset($form_class_name)) {
-    //FIXME: Add a confirmation step
+global $is_logged_in;
+if (!$is_logged_in) {
+    echo "Please login first. <br>";
+    $_SESSION['login_referer'] = $_SERVER['HTTP_REFERER'];
+    redirect("index.php?page=login", 2);
+}
+
+if (isset($form_cancel) && isset($form_flight_id) && isset($form_class_name) &&
+    $is_logged_in) {
     $client_id = get_client_id($_SESSION['email']);
     global $connection;
     $sql_pquery = "delete from RESERVATIONS
@@ -20,6 +24,7 @@ if (isset($form_modify) && isset($form_flight_id) && isset($form_class_name)) {
     redirect("index.php?page=reservations", 3);
 } else {
     echo "Make an error message. <br>";
+    echo "<a href=\"javascript:history.go(-1)\">Retour</a>";
 }
 
 ?>