= '" . mysqli_real_escape_string($conn, $fliterFromDate) . "'"; $urlStr .= "&fliterFromDate=" . urlencode($fliterFromDate); } if (!empty($fliterToDate)) { $fliterStr .= " AND o.order_date <= '" . mysqli_real_escape_string($conn, $fliterToDate) . " 23:59:59'"; $urlStr .= "&fliterToDate=" . urlencode($fliterToDate); } // 搜索和排序 $keys = $_GET['Keys'] ?? ''; $keyscode = mysqli_real_escape_string($conn, $keys); $page = $_GET['Page'] ?? 1; $ord = $_GET['Ord'] ?? ''; $ordStr = !empty($ord) ? "$ord," : ""; // 构建查询SQL $employee_id = $_SESSION['employee_id']; $isAdmin = checkIfAdmin(); $sqlStr = "SELECT o.*, c.cs_company, c.cs_code FROM orders o LEFT JOIN customer c ON o.customer_id = c.id WHERE 1=1"; // 非管理员只能查看自己的订单 if (!$isAdmin) { $sqlStr .= " AND o.employee_id = $employee_id"; } if (!empty($keyscode)) { $sqlStr .= " AND (o.order_code LIKE '%$keyscode%' OR c.cs_company LIKE '%$keyscode%' OR c.cs_code LIKE '%$keyscode%')"; } $sqlStr .= " $fliterStr ORDER BY {$ordStr}o.created_at DESC"; ?>