// Ïîäêëþ÷åíèå include_once($_SERVER['DOCUMENT_ROOT']."/account/admin/autorizator.php"); // ============================== // ======== Îáðàáîòêà =========== // ============================== if ((isset($_POST["send"])) && ($_POST["send"] == "ok")) { // Äîáàâëÿåì ïîëüçîâàòåëÿ $sql = sprintf("INSERT INTO zlo_users_message (`date`, `from`, `to`, `text`, `status`) VALUES (NOW(), %s, %s, %s, 3) ", GetSQLValueString($_SESSION['admin']['id'], "text"), GetSQLValueString($_GET['user'], "text"), GetSQLValueString($_POST['text'], "text")); $result = mysql_query($sql) or die(mysql_error()); // Øëåì ïèñüìà eMailing('MessageToUser', $_GET['user']); echo ""; } if ((isset($_GET["action"])) && ($_GET["action"] == "del")) { $sql = "DELETE FROM zlo_users_message WHERE id='".$_GET['message']."'"; $result = mysql_query($sql) or die(mysql_error()); echo ""; } // ============================== // ========== Âûâîä ============= // ============================== // ============= // ==== All ==== // ============= if (!isset($_GET["action"])) { echo"
"; } // ============= // ====show ==== // ============= if ((isset($_GET["action"])) && ($_GET["action"] == "show")) { // Èçìåíÿåì ñòàòóñ íà "ïðî÷èòàíî" $sql = "SELECT `from` FROM zlo_users_message WHERE id='".$_GET['message']."'"; $result = mysql_query($sql) or die(mysql_error()); if (mysql_affected_rows()!=0) { $i=0; $j=0; $message_from=mysql_fetch_assoc($result); } if ($message_from['from']!=1) { // $_SESSION['admin']['id'] â áóäóþùåì áóäåò $sql = "UPDATE zlo_users_message SET status=2 WHERE id='".$_GET['message']."'"; $result = mysql_query($sql) or die(mysql_error()); } echo" "; } // ============= // ==== add ==== // ============= if ((isset($_GET["action"])) && ($_GET["action"] == "add")) { echo" "; } ?>