#################################
# 新增資料
#
#################################
function op_insert() {
global $mysqli;
#資料過濾
#http://php.net/manual/en/mysqli.real-escape-string.php
$_POST['title'] = $mysqli->real_escape_string($_POST['title']);
$_POST['target'] = intval($_POST['target']);
$_POST['enable'] = intval($_POST['enable']);
$_POST['sort'] = intval($_POST['sort']);
$_POST['url'] = $mysqli->real_escape_string($_POST['url']);
$_POST['kind'] = $mysqli->real_escape_string($_POST['kind']);
$sql = "insert into `creative_nav`
(`title`, `target`, `enable`, `sort`,`url`,`kind`)
values
('{$_POST['title']}', '{$_POST['target']}', '{$_POST['enable']}', '{$_POST['sort']}', '{$_POST['url']}', '{$_POST['kind']}')";
$mysqli->query($sql) or die(printf("Error: %s
" . $sql, $mysqli->sqlstate));
$sn = $mysqli->insert_id; //傳回insert 指令所產生之流水號
return $sn;
}
```
2. 編輯 ```
#################################
# 更新資料
#
#################################
function op_update($sn = "") {
global $mysqli;
if (!$sn) {
redirect_header("index.php", 3000, "更新記錄錯誤!!");
}
#資料過濾
$_POST['sn'] = intval($_POST['sn']);
$_POST['title'] = $mysqli->real_escape_string($_POST['title']);
$_POST['target'] = intval($_POST['target']);
$_POST['enable'] = intval($_POST['enable']);
$_POST['sort'] = intval($_POST['sort']);
$_POST['url'] = $mysqli->real_escape_string($_POST['url']);
$sql = "update `creative_nav` set
`title` = '{$_POST['title']}' ,
`target` = '{$_POST['target']}',
`enable` = '{$_POST['enable']}',
`url` = '{$_POST['url']}',
`sort` = '{$_POST['sort']}'
where sn='{$_POST['sn']}'";
$mysqli->query($sql) or die(printf("Error: %s
" . $sql, $mysqli->sqlstate));
return $sn;
}
```
3. 刪除 ```
#################################
# 刪除資料
#
#################################
function op_delete($sn = "") {
global $mysqli;
if (!$sn) {
redirect_header("index.php", 3000, "刪除記錄錯誤!!");
}
#
$sql = "delete
from `creative_nav`
where `sn`='{$sn}'"; //die($sql);
$mysqli->query($sql) or die(printf("Error: %s
" . $sql, $mysqli->sqlstate));
return;
}
```
4. 列表 ```
#################################
# 列表程式
#
#################################
function op_list() {
global $mysqli, $smarty;
#取得所有記錄
$sql = "select *
from `creative_nav`
where `kind`='nav_home'
order by `sort` "; //die($sql);
$result = $mysqli->query($sql) or die(printf("Error: %s
" . $sql, $mysqli->sqlstate));
$rows = array();
while ($row = $result->fetch_assoc()) {
#過濾撈出資料
$row['sn'] = intval($row['sn']);
//http://www.w3school.com.cn/php/func_string_htmlspecialchars.asp
$row['title'] = htmlspecialchars($row['title'], ENT_QUOTES); // 轉換雙引號和單引號
$row['url'] = htmlspecialchars($row['url'], ENT_QUOTES); // 轉換雙引號和單引號
$row['sort'] = intval($row['sort']);
$row['enable'] = intval($row['enable']);
$row['target'] = intval($row['target']);
$rows[] = $row;
}
$smarty->assign("rows", $rows);
return;
}
```
5. 取得單筆記錄 ```
########################################
#取得單筆記錄
########################################
function get_creative_nav($sn = "") {
global $mysqli;
if (!$sn) {
redirect_header("index.php", 3000, "查詢選單資料錯誤!!");
}
$sql = "select *
from `creative_nav`
where `sn`='{$sn}' and `kind`= 'nav_home'";
$result = $mysqli->query($sql) or die(printf("Error: %s
" . $sql, $mysqli->sqlstate));
$row = $result->fetch_assoc();
#過濾撈出資料
$row['sn'] = intval($row['sn']);
//http://www.w3school.com.cn/php/func_string_htmlspecialchars.asp
$row['title'] = htmlspecialchars($row['title'], ENT_QUOTES); // 轉換雙引號和單引號
$row['url'] = htmlspecialchars($row['url'], ENT_QUOTES); // 轉換雙引號和單引號
$row['sort'] = intval($row['sort']);
$row['enable'] = intval($row['enable']);
$row['target'] = intval($row['target']);
return $row;
}
```
三、樣板
1. theme.html ```
<{if $WEB.file_name =="index.php"}>
<{include file="tpl/admin_index.html"}>
<{/if}>
```
2. tpl/admin\_index.html 列表 ```
<{if $op == "op_list"}>
<{/if}>
```
3. admin/admin\_index.html 表單 ```
<{if $op == "op_form"}>
選單管理 - <{$row.form_title}>
<{/if}>
```
4.