@@ -9,8 +9,27 @@
$userid = $_SESSION['userID'];
$logouttime = $_SESSION['LogoutTime'];

$sql = "INSERT INTO `timetable`(`timeIn`, `timeOut`, `userID`)
VALUES ('$logintime','$logouttime','$userid')";
// $hoursAchieved = date_diff($logintime, $logouttime);
//$start = DateTime::createFormFormat('Y-m-d H:i:s');
//$end = DateTime::createFormFormat('Y-m-d H:i:s');
// $start = date_create_from_format('Y-m-d H:i:s', $logintime);
// $end = date_create_from_format('Y-m-d H:i:s', $logouttime);
$start = new DateTime($logintime);
$end = new DateTime($logouttime);

$interval = $end->diff($start);



$time = sprintf(
'%d:%02d:%02d',
($interval->d * 24) + $interval->h,
$interval->i,
$interval->s
);

$sql = "INSERT INTO `timetable`(`timeIn`, `timeOut`,`HoursMade` ,`userID`)
VALUES ('$logintime','$logouttime','$time','$userid')";

if(mysqli_query($conn,$sql)){
session_destroy();
@@ -0,0 +1,9 @@
<?php
if($_POST){
include("DBconnect.php");
session_start();
$_SESSION["employeeID"] = $_POST["userID"];
$_SESSION["firstname"] = $_POST["firstname"];
$_SESSION["lastname"] = $_POST["lastname"];
}
?>
@@ -0,0 +1,21 @@
<?php
if($_POST){

include("DBconnect.php");
$userID = mysqli_real_escape_string($conn, $_POST['userID']);
//echo "$userID";

//add user existence verification
$sql = "UPDATE `user` SET `active`= 0 WHERE `userID` = $userID";

if(mysqli_query($conn,$sql)){
echo "successfully deleted the user!";
}else{
echo "yous a hacker bruh?";
}

mysqli_close($conn);
}else{
echo "POST error";
}
?>
@@ -0,0 +1,22 @@
<?php
if($_POST){
include("DBconnect.php");
$userID = mysqli_real_escape_string($conn, $_POST['txt_userID']);
$firstname = mysqli_real_escape_string($conn, $_POST['txt_firstname']);
$lastname = mysqli_real_escape_string($conn, $_POST['txt_lastname']);
$emailaddress = mysqli_real_escape_string($conn, $_POST['txt_signUpEmail']);

$sql = "UPDATE `user`
SET `firstname` = '$firstname', `lastname` = '$lastname', `emailadd` = '$emailaddress'
WHERE `userID` = '$userID'";

if(mysqli_query($conn, $sql)){
echo "user successfully edited";
}else{
echo "yous a hacker bruh?";
}
mysqli_close($conn);
}else{
echo "POST error";
}
?>
@@ -9,11 +9,12 @@
<meta name="description" content="">
<meta name="author" content="">

<script src="//code.jquery.com/jquery-1.12.4.js"></script>

</head>

<body id="page-top">

<script src="HomePageBootStrap/vendor/jquery/jquery.min.js"></script>
<script>

$(document).ready(function(){
@@ -0,0 +1,19 @@
<?php
include("DBconnect.php");
$query = 'SELECT `userID`, `firstname`, `lastname`, `emailadd` FROM `user` WHERE `active` = 0';

$result = mysqli_query($conn,$query);


while($row = mysqli_fetch_array($result)){

echo '<tr id='.$row[0].'>
<td>'.$row[0].'</td>
<td>'.$row[1].'</td>
<td>'.$row[2].'</td>
<td>'.$row[3].'</td>
<td><button id="resurrectButton" type="button" class="btn btn-sm btn-primary">Resurrect</button></td>
</tr>';
}
?>
@@ -0,0 +1,21 @@
<?php
if($_POST){

include("DBconnect.php");
$userID = mysqli_real_escape_string($conn, $_POST['userID']);
//echo "$userID";

//add user existence verification
$sql = "UPDATE `user` SET `active`= 1 WHERE `userID` = $userID";

if(mysqli_query($conn,$sql)){
echo "successfully resurrected the user!";
}else{
echo "yous a hacker bruh?";
}

mysqli_close($conn);
}else{
echo "POST error";
}
?>

Large diffs are not rendered by default.

This file was deleted.

@@ -0,0 +1,29 @@
<?php
include("DBconnect.php");
$query = 'SELECT `userID`, `firstname`, `lastname`, `emailadd` FROM `user` WHERE 1';

$result = mysqli_query($conn,$query);
if(mysqli_num_rows($result) > 0){
$data_array = array();

while($row=mysqli_fetch_assoc($result)){
/* echo '<tr id='.$row[0].'>
<td>'.$row[0].'</td>
<td>'.$row[1].'</td>
<td>'.$row[2].'</td>
<td>'.$row[3].'</td>
<td><button id='.$row[0].' type="button" class="btn btn-sm btn-danger">Delete</button>
</tr>';
*/
$data_array[] = array(
'userID' => $row['userID'],
'firstname' => $row['firstname'],
'lastname' => $row['lastname'],
'emailadd' => $row['emailadd']
);
}
$json = json_encode($data_array);
echo $json;
}

?>