alert('两次密码输入不一致');history.back();";
exit;
}
if($isEdit) {
$query = "SELECT * FROM employee WHERE id=$id";
$result = $conn->query($query);
if($result->num_rows > 0) {
$password_sql = $nullPwd ? "" : ",em_password='".md5($em_password)."'";
$sql = "UPDATE employee SET em_user='$em_user'$password_sql,em_role=$em_role,
em_code='$em_code',em_email='$em_email',em_tel='$em_tel' WHERE id=$id";
$conn->query($sql);
}
$page = $_GET['Page'] ?? '';
$keys = urlencode($_GET['Keys'] ?? '');
$ord = urlencode($_GET['Ord'] ?? '');
header("Location: ?keys=$keys&Ord=$ord&Page=$page");
exit;
} else {
if($nullPwd) {
$em_password = "MTB".$em_code;
}
$sql = "INSERT INTO employee(em_user,em_password,em_role,em_code,em_email,em_tel)
VALUES('$em_user','".md5($em_password)."',$em_role,'$em_code','$em_email','$em_tel')";
$conn->query($sql);
header("Location: ?");
exit;
}
}
if($act == "add" || $act == "edit") {
$id = $_GET['id'] ?? '';
$isEdit = false;
if($id != '' && is_numeric($id)) {
$isEdit = true;
}
if($isEdit) {
$query = "SELECT * FROM employee WHERE id=$id";
$result = $conn->query($query);
if($result->num_rows > 0) {
$row = $result->fetch_assoc();
$em_user = textUncode($row['em_user']);
$em_role = $row['em_role'];
$em_code = textUncode($row['em_code']);
$em_email = textUncode($row['em_email']);
$em_tel = textUncode($row['em_tel']);
} else {
$isEdit = false;
}
}
$page = $_GET['Page'] ?? '';
$keys = urlencode($_GET['Keys'] ?? '');
$ord = urlencode($_GET['Ord'] ?? '');
$hrefstr = "?keys=$keys&Ord=$ord&Page=$page";
?>