$sql = “DELETE FROM times WHERE employeeID=’$name’ AND date>’$date1′ AND date<='$date2'";
$query = mysqli_query($conn, $sql);
//echo $sql;
if ($query === false || $query == null) {
$_SESSION['sql'] = $_SESSION['sql'] . "Error description: " . mysqli_error($conn);
//header("location: http://sustech.net.au/approval?fail");
echo 'Error. Please try again.';
} else {
//header("location: http://sustech.net.au/approval?reject=success");
//echo 'Successfully rejected.';
}
// echo ('success!');
rejectTimes($name, $date1, $date2);
}
if (!isset($_GET['success']) && !isset($_GET['fail']) && isset($_GET['toapprovecost'])) {
approveCost($name, $date1);
}
if (!isset($_GET['success']) && !isset($_GET['fail']) && isset($_GET['torejectcost'])) {
rejectCost($name, $date1);
}
[/insert_php]
[insert_php]
$v = 0;
if (!isset( $_SESSION[‘login_user’]) || $_SESSION[‘login_user’] == “”) {
header(“location: http://www.sustech.net.au/log-in”);
}
if (isset($_GET[‘fail’])) {
echo ‘Error with the database. Please try again.’;
$v = 1;
}
if (isset($_GET[‘already’])) {
echo ‘Already approved.’;
$v = 1;
}
if(isset($_GET[’employee’])) {
$name = $_GET[’employee’];
if (isset($_GET[‘date1’])) {
$date1 = $_GET[‘date1’];
$date2 = $_GET[‘date2’];
} else if (!isset($_GET[‘approve’]) && !isset($_GET[‘reject’]) && !isset($_GET[‘fail’]) && !isset($_GET[‘already’])) {
echo ‘Error: you must use a link from an e-mail.’;
echo “\n”;
}
} else if (!isset($_GET[‘approve’]) && !isset($_GET[‘reject’]) && !isset($_GET[‘fail’])) {
echo ‘Error: you must use a link from an e-mail.’;
echo “\n”;
$v = 1;
}
if (isset($_GET[‘approve’])) {
if (isset($_GET[‘cost’])) {
echo ‘Expense successfully approved.’;
echo “\n”;
}
else {
echo ‘Times successfully approved.’;
echo “\n”;
}
} else if (isset($_GET[‘reject’])) {
if (isset($_GET[‘cost’])) {
echo ‘Expense successfully rejected.’;
echo “\n”;
}
else {
echo ‘Times successfully rejected.’;
echo “\n”;
}
}
if (isset($_GET[‘fail’])) {
echo ‘Error.’;
echo “\n”;
}
[/insert_php]