|
@@ -104,7 +104,7 @@ $act = empty($id) || !is_numeric($id) ? 'addSave' : 'editSave';
|
|
|
|
|
|
if ($act === 'editSave') {
|
|
|
// Verify customer ownership
|
|
|
- $stmt = $conn->prepare("SELECT cs_belong FROM Customer WHERE id = ?");
|
|
|
+ $stmt = $conn->prepare("SELECT cs_belong FROM customer WHERE id = ?");
|
|
|
$stmt->bind_param("i", $id);
|
|
|
$stmt->execute();
|
|
|
$result = $stmt->get_result();
|
|
@@ -127,7 +127,7 @@ if (empty($cs_code)) {
|
|
|
}
|
|
|
|
|
|
// Check for duplicate customer information
|
|
|
-$checkStr = "SELECT * FROM Customer WHERE cs_belong != " . $_SESSION['employee_id'] . " AND (id = 0 ";
|
|
|
+$checkStr = "SELECT * FROM customer WHERE cs_belong != " . $_SESSION['employee_id'] . " AND (id = 0 ";
|
|
|
|
|
|
$Dupli = "";
|
|
|
|
|
@@ -219,7 +219,7 @@ if ($act == "editSave" || $allowedit == 1) {
|
|
|
"&fliterDeal=" . $fliterDeal . "&Page=" . $page;
|
|
|
|
|
|
// 直接使用SQL拼接,与ASP版本保持一致
|
|
|
- $updateSql = "UPDATE Customer SET
|
|
|
+ $updateSql = "UPDATE customer SET
|
|
|
cs_code='" . $conn->real_escape_string($cs_code) . "',
|
|
|
cs_company='" . $conn->real_escape_string($cs_company) . "',
|
|
|
cs_name='" . $conn->real_escape_string($cs_name) . "',
|
|
@@ -267,7 +267,7 @@ if ($act == "editSave" || $allowedit == 1) {
|
|
|
echo "<script>location.href='$hrefstr';</script>";
|
|
|
} else {
|
|
|
// Insert new customer using direct SQL
|
|
|
- $insertSql = "INSERT INTO Customer (
|
|
|
+ $insertSql = "INSERT INTO customer (
|
|
|
cs_code, cs_company, cs_name, cs_country, cs_from, cs_tel, cs_wechat,
|
|
|
cs_whatsapp, cs_email, cs_linkedin, cs_facebook, cs_alibaba, cs_address,
|
|
|
cs_telBu, cs_wechatBu, cs_whatsappBu, cs_emailBu, cs_linkedinBu,
|