<?php
include('database.php');
if (isset($_POST["addtocart"])) {
// Connect to the database
// Check connection
// Escape user inputs for security
$cartid = $_SESSION["email"];
$title = mysqli_real_escape_string($con, $_POST['title']);
$vendor_id = mysqli_real_escape_string($con, $_POST['vendor_id']);
$description = mysqli_real_escape_string($con, $_POST['description']);
$insert_category = mysqli_real_escape_string($con, $_POST['insert_category']);
$location = mysqli_real_escape_string($con, $_POST['location']);
$price = mysqli_real_escape_string($con, $_POST['price']);
$image = mysqli_real_escape_string($con, $_POST['image']);
$sql = "INSERT INTO cart (cart_id,vendor_id,title, description, category, location, price,image)
VALUES ('$cartid','$vendor_id','$title', '$description', '$insert_category', '$location', '$price','$image')";
if (mysqli_query($con, $sql)) {
// echo "record added";
header("Location: " . $_SERVER['REQUEST_URI']);
} else {
echo "ERROR: Could not able to execute $sql. " . mysqli_error($con);
}
// Close connection
mysqli_close($con);
}
?>
Modify code:
<?php
include('database.php');
if (isset($_POST["addtocart"])) {
// Connect to the database
// Check connection
// Escape user inputs for security
$cartid = $_SESSION["email"];
$title = mysqli_real_escape_string($con, $_POST['title']);
$vendor_id = mysqli_real_escape_string($con, $_POST['vendor_id']);
$description = mysqli_real_escape_string($con, $_POST['description']);
$insert_category = mysqli_real_escape_string($con, $_POST['insert_category']);
$location = mysqli_real_escape_string($con, $_POST['location']);
$price = mysqli_real_escape_string($con, $_POST['price']);
$image = mysqli_real_escape_string($con, $_POST['image']);
$sql = "INSERT INTO cart (cart_id,vendor_id,title, description, category, location, price,image)
VALUES ('$cartid','$vendor_id','$title', '$description', '$insert_category', '$location', '$price','$image')";
if (mysqli_query($con, $sql)) {
// echo "record added";
//header("Location: " . $_SERVER['REQUEST_URI']);
echo "<script>window.location.href = window.location.href;</script>";
exit;
} else {
echo "ERROR: Could not able to execute $sql. " . mysqli_error($con);
}
// Close connection
mysqli_close($con);
}
?>
Add javascript to rediret url.
No comments:
Post a Comment