-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathDeleteReservation.php
More file actions
138 lines (105 loc) · 3.42 KB
/
DeleteReservation.php
File metadata and controls
138 lines (105 loc) · 3.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
<?php
/*|-------------------------------------------------------------------------
*| CMPS 460 Spring 2015
*| Ryan Adair
*| 4/28/15
*|
*| The following code is the work of the author named above.
*|-----------------------------------------------------------------------
*| This script generates a webpage with the appropriate fields
*| displayed to allow an admin to delete a reservation from the
*| Reservation table in the database.
*|-----------------------------------------------------------------------*/
include "login.php";
if(isset($_SESSION["userType"]) == false)
{
echo "Not logged in!";
echo '<br><br>';
echo '<a href ="LoginPage.php">Go Log In</a>';
die();
}
?>
<html>
<head>
<title>
Delete a Reservation
</title>
</head>
<h3>
Delete a Reservation
</h3>
<body>
<?php
$sessionUser = $_SESSION['userType'];
// restrict access only to certain userTypes
if($sessionUser != "admin")
{
echo 'You do not have permission to view this page.';
echo '<br><br>';
echo '<a href ="LoginPage.php">Go Log In</a>';
die();
}
echo "Logged in as: $sessionUser";
$date = $_SESSION["today"];
echo "<br>";
echo "Today's date: $date";
?>
<br>
<br>
<?php
if(isset($_POST['reservationToDelete']))
{
$reservationID = $_POST['reservationToDelete'];
$deleteReservationQuery = "delete from Reservation where ID=$reservationID";
if(mysql_query($deleteReservationQuery) or die(mysql_error()))
{
echo "Reservation number $reservationID has been canceled.<br>";
}
else
{
echo "<br>Could not delete reservation.";
echo '<br><a href ="DeleteReservation.php">Go Back</a>';
}
}
else
{
$reservationQueryResult = mysql_query("select * from Reservation order by MembershipID, MemberID;") or die(mysql_error());
if(mysql_num_rows($reservationQueryResult))
{
echo "<form action='DeleteReservation.php' method='post'>";
echo "Delete Reservation: ";
echo "<select name='reservationToDelete'>";
while($reservationRow = mysql_fetch_array($reservationQueryResult))
{
$reservationID = $reservationRow['ID'];
$movieShowingID = $reservationRow['MovieShowingID'];
$membershipID = $reservationRow['MembershipID'];
$memberID = $reservationRow['MemberID'];
$movieShowingResult = mysql_fetch_array(mysql_query("select * from MovieShowing where ID=$movieShowingID;"));
$cinemaID = $movieShowingResult['CinemaID'];
$movieID = $movieShowingResult['MovieID'];
$date = $movieShowingResult['ShowDate'];
$time = $movieShowingResult['ShowTime'];
$titleQuery = mysql_fetch_array(mysql_query("Select Title from Movie where ID=$movieID;"));
$title = $titleQuery['Title'];
$cinemaQuery = mysql_fetch_array(mysql_query("Select Name from Cinema where ID=$cinemaID;"));
$cinemaName = $cinemaQuery['Name'];
echo "<option value='$reservationID'>Member: ($membershipID-$memberID) \"$title\" at $cinemaName on $date $time</option>";
}
echo "</select>";
echo "<br><br>";
echo "<input type='submit' value='Delete Reservation'>";
echo "</form>";
}
else
{
echo "No existing reservations.<br>";
}
}
echo "<br>";
echo "<form action ='index.php'>";
echo "<input type ='submit' value = 'Go back to index' >";
echo "</form>";
?>
</body>
</html>