diff --git a/ashop.php b/ashop.php index d03d23f..e1fd2b4 100644 --- a/ashop.php +++ b/ashop.php @@ -17,9 +17,6 @@ if ($user['battle'] != 0) { $bank = db::c()->query('SELECT `ekr` FROM `bank` WHERE `id`=?i', $_SESSION['uid'])->fetch_assoc(); -//$set = isset($_POST['set']) ? $_POST['set'] : ''; -//$var = $value ?: "Другое значение"; - if (isset($_GET['set']) OR isset($_POST['set'])) { $set = empty($_GET['set']) ?: $_GET['set']; diff --git a/upgrade_items.php b/upgrade_items.php index f3ee898..1c7ab77 100644 --- a/upgrade_items.php +++ b/upgrade_items.php @@ -2,367 +2,324 @@ session_start(); if ($_SESSION['uid'] == null) header("Location: index.php"); include "config.php"; -$user = mysql_fetch_array(mysql_query("SELECT * FROM `users` WHERE `id` = '".$_SESSION['uid']."' LIMIT 1;")); include "functions.php"; -if ($user['room'] != 50) { header("Location: main.php"); die(); } -$d = mysql_fetch_array(mysql_query("SELECT sum(`massa`) FROM `inventory` WHERE `owner`='".$_SESSION['uid']."' AND `dressed`=0 AND `setsale`=0;")); -if ($user['battle'] != 0) { header('location: fbattle.php'); die(); } +if ($user['room'] != 50) { + header("Location: main.php"); + die(); +} +$itemWeight = db::c()->query('SELECT sum(`massa`) AS `m` FROM `inventory` WHERE `owner` = ?i AND `dressed` = 0 AND `setsale` = 0', $user['id'])->fetch_assoc(); +if ($user['battle'] != 0) { + header('location: fbattle.php'); + die(); +} //$_GET['otdel'] = 1; -if(isset($_GET['up'])){ - $ids = $_GET['up']; - $cur = mysql_fetch_assoc(mysql_query("select `id`,`name`,`nlevel` from `inventory` where `owner`='".$user['id']."' and `id`='".$ids."' and `artefact`='1'")); - if($cur['id']){ - $up_level = $cur['nlevel'] + 1; -$cur_up = mysql_fetch_assoc(mysql_query("select * from `ashop_up` where `name`='".$cur['name']."' and `level_up`='".$up_level."'")); -if($cur_up['id']){ - -mysql_query("update `inventory` set `upgrade`='".$cur_up['level_up']."',`nlevel`='".$cur_up['level_up']."',`minu`='".$cur_up['minu']."',`maxu`='".$cur_up['maxu']."',`gsila`='".$cur_up['gsila']."',`glovk`='".$cur_up['glovk']."',`ginta`='".$cur_up['ginta']."',`gintel`='".$cur_up['gintel']."',`ghp`='".$cur_up['ghp']."',`mfkrit`='".$cur_up['mfkrit']."',`mfakrit`='".$cur_up['mfakrit']."',`mfuvorot`='".$cur_up['mfuvorot']."',`mfauvorot`='".$cur_up['mfauvorot']."',`gnoj`='".$cur_up['gnoj']."',`gtopor`='".$cur_up['gtopor']."',`gdubina`='".$cur_up['gdubina']."',`gmech`='".$cur_up['gmech']."',`bron1`='".$cur_up['bron1']."',`bron2`='".$cur_up['bron2']."',`bron3`='".$cur_up['bron3']."',`bron4`='".$cur_up['bron4']."' where `owner`='".$user['id']."' and `id`='".$cur['id']."'"); - echo"Артефакт успешно улучшен!"; - -}else{ - echo"Эта вещь дальше не улучшается!"; -} - } +if (isset($_GET['up'])) { + $ids = $_GET['up']; + $cur = mysql_fetch_assoc(mysql_query("SELECT `id`,`name`,`nlevel` FROM `inventory` WHERE `owner`='" . $user['id'] . "' AND `id`='" . $ids . "' AND `artefact`='1'")); + if ($cur['id']) { + $up_level = $cur['nlevel'] + 1; + $cur_up = mysql_fetch_assoc(mysql_query("SELECT * FROM `ashop_up` WHERE `name`='" . $cur['name'] . "' AND `level_up`='" . $up_level . "'")); + if ($cur_up['id']) { + + mysql_query("UPDATE `inventory` SET `upgrade`='" . $cur_up['level_up'] . "',`nlevel`='" . $cur_up['level_up'] . "',`minu`='" . $cur_up['minu'] . "',`maxu`='" . $cur_up['maxu'] . "',`gsila`='" . $cur_up['gsila'] . "',`glovk`='" . $cur_up['glovk'] . "',`ginta`='" . $cur_up['ginta'] . "',`gintel`='" . $cur_up['gintel'] . "',`ghp`='" . $cur_up['ghp'] . "',`mfkrit`='" . $cur_up['mfkrit'] . "',`mfakrit`='" . $cur_up['mfakrit'] . "',`mfuvorot`='" . $cur_up['mfuvorot'] . "',`mfauvorot`='" . $cur_up['mfauvorot'] . "',`gnoj`='" . $cur_up['gnoj'] . "',`gtopor`='" . $cur_up['gtopor'] . "',`gdubina`='" . $cur_up['gdubina'] . "',`gmech`='" . $cur_up['gmech'] . "',`bron1`='" . $cur_up['bron1'] . "',`bron2`='" . $cur_up['bron2'] . "',`bron3`='" . $cur_up['bron3'] . "',`bron4`='" . $cur_up['bron4'] . "' WHERE `owner`='" . $user['id'] . "' AND `id`='" . $cur['id'] . "'"); + echo "Артефакт успешно улучшен!"; + + } else { + echo "Эта вещь дальше не улучшается!"; + } + } } -if($_POST['enter'] && $_POST['pass']) { - $data = mysql_query("SELECT * FROM `bank` WHERE `id`='".$_POST['id']."' AND `pass`='".md5($_POST['pass'])."';"); - echo mysql_error(); - $data = mysql_fetch_array($data); - if($data) { - $_SESSION['bankid'] = $_POST['id']; - err('Удачный вход.'); - } - else { - err('Ошибка входа.'); - } -} +$bank = db::c()->query('SELECT `ekr` FROM `bank` WHERE `id`=?i', $_SESSION['uid'])->fetch_assoc(); -$bank = mysql_fetch_array(mysql_query("SELECT * FROM `bank` WHERE `id`='".$_SESSION['bankid']."';")); +if (isset($_GET['set']) OR isset($_POST['set'])) { -if (($_GET['set'] OR $_POST['set'])) { - if ($_GET['set']) { $set = $_GET['set']; } - if ($_POST['set']) { $set = $_POST['set']; } - if(!$_POST['count']) { $_POST['count']=1; } - if(!is_numeric($_POST['count']) || $_POST['count']!=((int)$_POST['count'])) { - $_POST['count']=0; - $count_ok=0; - } - elseif ($_POST['count'] < 1) { - $_POST['count'] =1; - } - else $count_ok=1; + $set = empty($_GET['set']) ?: $_GET['set']; + $set = empty($_POST['set']) ?: $_POST['set']; - $dress = mysql_fetch_array(mysql_query("SELECT * FROM `ashop` WHERE `id`='".$set."' LIMIT 1;")); - if ($count_ok==0) { - echo "Неправильно введено количество"; - //$good = 0; - } - elseif (($dress['massa']*$_POST['count']+$d[0]) > (get_meshok())) { - echo "Недостаточно места в рюкзаке."; - //$good = 0; - } - elseif($count_ok==1 && ($bank['ekr']>= ($dress['ecost']*$_POST['count'])) && ($dress['count'] >= $_POST['count'])) { - for($k=1;$k<=$_POST['count'];$k++) { - if(mysql_query("INSERT INTO `inventory` + $count = isset($_POST['count']) && is_numeric($_POST['count']) ? $_POST['count'] : 0; + + if ($count < 1) { + $count = 0; + $count_ok = 0; + } else $count_ok = 1; + + $dress = db::c()->query('SELECT * FROM `ashop` WHERE `id`=?i', $set)->fetch_assoc(); + if ($count_ok == 0) { + err('Неправильно введено количество.'); + } elseif (($dress['massa'] * $_POST['count'] + $itemWeight['m']) > (get_meshok())) { + err('Недостаточно места в рюкзаке.'); + } elseif ($count_ok == 1 && ($bank['ekr'] >= ($dress['ecost'] * $_POST['count'])) && ($dress['count'] >= $_POST['count'])) { + for ($k = 1; $k <= $_POST['count']; $k++) { + if (mysql_query("INSERT INTO `inventory` (`prototype`,`owner`,`name`,`type`,`massa`,`cost`,`img`,`maxdur`,`isrep`, `gsila`,`glovk`,`ginta`,`gintel`,`ghp`,`gnoj`,`gtopor`,`gdubina`,`gmech`,`gfire`,`gwater`,`gair`,`gearth`,`glight`,`ggray`,`gdark`,`needident`,`nsila`,`nlovk`,`ninta`,`nintel`,`nmudra`,`nvinos`,`nnoj`,`ntopor`,`ndubina`,`nmech`,`nfire`,`nwater`,`nair`,`nearth`,`nlight`,`ngray`,`ndark`, `mfkrit`,`mfakrit`,`mfuvorot`,`mfauvorot`,`bron1`,`bron2`,`bron3`,`bron4`,`maxu`,`minu`,`magic`,`nlevel`,`nalign`,`dategoden`,`goden`,`otdel`) VALUES ('{$dress['id']}','{$_SESSION['uid']}','{$dress['name']}','{$dress['type']}',{$dress['massa']},{$dress['cost']},'{$dress['img']}',{$dress['maxdur']},{$dress['isrep']},'{$dress['gsila']}','{$dress['glovk']}','{$dress['ginta']}','{$dress['gintel']}','{$dress['ghp']}','{$dress['gnoj']}','{$dress['gtopor']}','{$dress['gdubina']}','{$dress['gmech']}','{$dress['gfire']}','{$dress['gwater']}','{$dress['gair']}','{$dress['gearth']}','{$dress['glight']}','{$dress['ggray']}','{$dress['gdark']}','{$dress['needident']}','{$dress['nsila']}','{$dress['nlovk']}','{$dress['ninta']}','{$dress['nintel']}','{$dress['nmudra']}','{$dress['nvinos']}','{$dress['nnoj']}','{$dress['ntopor']}','{$dress['ndubina']}','{$dress['nmech']}','{$dress['nfire']}','{$dress['nwater']}','{$dress['nair']}','{$dress['nearth']}','{$dress['nlight']}','{$dress['ngray']}','{$dress['ndark']}', - '{$dress['mfkrit']}','{$dress['mfakrit']}','{$dress['mfuvorot']}','{$dress['mfauvorot']}','{$dress['bron1']}','{$dress['bron3']}','{$dress['bron2']}','{$dress['bron4']}','{$dress['maxu']}','{$dress['minu']}','{$dress['magic']}','{$dress['nlevel']}','{$dress['nalign']}','".(($dress['goden'])?($dress['goden']*24*60*60+time()):"")."','{$dress['goden']}','{$dress['razdel']}');")) - { - $good = 1; - } - else { - $good = 0; - } - } - if ($good) { - mysql_query("UPDATE `ashop` SET `count`=`count`-".$_POST['count']." WHERE `id`='".$set."' LIMIT 1;"); - $limit=$_POST['count']; - $invdb = mysql_query("SELECT `id` FROM `inventory` WHERE `name` = '".$dress['name']."' ORDER by `id` DESC LIMIT ".$limit.";" ); - if ($limit == 1) { - $dressinv = mysql_fetch_array($invdb); - $dressid = "cap".$dressinv['id']; - $dresscount=" "; - } - else { - $dressid=""; - while ($dressinv = mysql_fetch_array($invdb)) { - $dressid .= "cap".$dressinv['id'].","; + '{$dress['mfkrit']}','{$dress['mfakrit']}','{$dress['mfuvorot']}','{$dress['mfauvorot']}','{$dress['bron1']}','{$dress['bron3']}','{$dress['bron2']}','{$dress['bron4']}','{$dress['maxu']}','{$dress['minu']}','{$dress['magic']}','{$dress['nlevel']}','{$dress['nalign']}','" . (($dress['goden']) ? ($dress['goden'] * 24 * 60 * 60 + time()) : "") . "','{$dress['goden']}','{$dress['razdel']}');")) { + $good = 1; + } else { + $good = 0; + } } - $dresscount="(x".$_POST['count'].") "; - } - $allcost=$_POST['count']*$dress['ecost']; - mysql_query("INSERT INTO `delo` (`id` , `author` ,`pers`, `text`, `type`, `date`) VALUES ('','0','{$_SESSION['uid']}','\"".$user['login']."\" купил товар: \"".$dress['name']."\" ".$dresscount."id:(".$dressid.") [0/".$dress['maxdur']."] за ".$allcost." екр. ',1,'".time()."');"); - echo "Вы купили {$_POST['count']} шт. \"{$dress['name']}\"."; - mysql_query("UPDATE `bank` set `ekr`=`ekr`-'".($allcost)."' WHERE `id`='".$_SESSION['bankid']."';"); - $bank['ekr'] -=$allcost; + if ($good) { + mysql_query("UPDATE `ashop` SET `count`=`count`-" . $_POST['count'] . " WHERE `id`='" . $set . "' LIMIT 1;"); + $limit = $_POST['count']; + $invdb = mysql_query("SELECT `id` FROM `inventory` WHERE `name` = '" . $dress['name'] . "' ORDER BY `id` DESC LIMIT " . $limit . ";"); + if ($limit == 1) { + $dressinv = mysql_fetch_array($invdb); + $dressid = "cap" . $dressinv['id']; + $dresscount = " "; + } else { + $dressid = ""; + while ($dressinv = mysql_fetch_array($invdb)) { + $dressid .= "cap" . $dressinv['id'] . ","; + } + $dresscount = "(x" . $_POST['count'] . ") "; + } + $allcost = $_POST['count'] * $dress['ecost']; + mysql_query("INSERT INTO `delo` (`id` , `author` ,`pers`, `text`, `type`, `date`) VALUES ('','0','{$_SESSION['uid']}','\"" . $user['login'] . "\" купил товар: \"" . $dress['name'] . "\" " . $dresscount . "id:(" . $dressid . ") [0/" . $dress['maxdur'] . "] за " . $allcost . " екр. ',1,'" . time() . "');"); + echo "Вы купили {$_POST['count']} шт. \"{$dress['name']}\"."; + mysql_query("UPDATE `bank` SET `ekr`=`ekr`-'" . ($allcost) . "' WHERE `id`='" . $_SESSION['bankid'] . "';"); + $bank['ekr'] -= $allcost; + } + } else { + echo "Недостаточно денег или нет вещей в наличии."; } - } - else { - echo "Недостаточно денег или нет вещей в наличии."; - } } ?> -
- - - - - - + + + + + - -Магазин Берёзка | - - |