save_product.php 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161
  1. <?php
  2. require_once('conn.php');
  3. // Check login status
  4. checkLogin("信息管理");
  5. // Initialize all variables to avoid undefined warnings
  6. $id = isset($_POST['id']) ? $_POST['id'] : '';
  7. $product_name = isset($_POST['ProductName']) ? htmlspecialcharsFix($_POST['ProductName']) : '';
  8. $product_img = isset($_POST['ProductImg']) ? htmlspecialcharsFix($_POST['ProductImg']) : '';
  9. $unit = isset($_POST['unit']) ? htmlspecialcharsFix($_POST['unit']) : '';
  10. $moq = isset($_POST['moq']) ? htmlspecialcharsFix($_POST['moq']) : '';
  11. $category_id = isset($_POST['category_id']) ? intval($_POST['category_id']) : 0;
  12. $nosale = isset($_POST['nosale']) ? $_POST['nosale'] : array();
  13. $note = isset($_POST['note']) ? htmlspecialcharsFix($_POST['note']) : '';
  14. $tips = isset($_POST['tips']) ? htmlspecialcharsFix($_POST['tips']) : '';
  15. $keys = isset($_POST['keys']) ? $_POST['keys'] : '';
  16. $page = isset($_POST['page']) ? $_POST['page'] : 1;
  17. // Initialize specification variables
  18. $spec_name = isset($_POST['spec_name']) ? $_POST['spec_name'] : array();
  19. $spec_value = isset($_POST['spec_value']) ? $_POST['spec_value'] : array();
  20. $spec_price = isset($_POST['spec_price']) ? $_POST['spec_price'] : array();
  21. $spec_moq = isset($_POST['spec_moq']) ? $_POST['spec_moq'] : array();
  22. $spec_code = isset($_POST['spec_code']) ? $_POST['spec_code'] : array();
  23. $spec_sort = isset($_POST['spec_sort']) ? $_POST['spec_sort'] : array();
  24. // Redirect URL
  25. $redirect_url = "products.php?Keys=" . $keys . "&Page=" . $page;
  26. if ($category_id) {
  27. $redirect_url .= "&category_id=" . $category_id;
  28. }
  29. // Determine if this is an edit or a new record
  30. $is_edit = (!empty($id) && is_numeric($id));
  31. // Process nosale array into comma-separated string
  32. $nosale_str = '';
  33. if (is_array($nosale) && !empty($nosale)) {
  34. $nosale_clean = array_map('intval', $nosale); // Ensure all values are integers
  35. $nosale_str = implode(',', $nosale_clean);
  36. }
  37. // Validate form data
  38. if (empty($product_name)) {
  39. // You could add error handling here
  40. header("Location: " . $redirect_url);
  41. exit();
  42. }
  43. // Validate specifications - at least one specification is required with all fields filled
  44. $has_valid_specs = false;
  45. if (is_array($spec_name) && !empty($spec_name)) {
  46. foreach ($spec_name as $key => $name) {
  47. if (!empty($name) && isset($spec_price[$key]) && !empty($spec_price[$key]) &&
  48. isset($spec_moq[$key]) && !empty($spec_moq[$key])) {
  49. $has_valid_specs = true;
  50. break;
  51. }
  52. }
  53. }
  54. if (!$has_valid_specs) {
  55. // Redirect back with error message
  56. header("Location: " . $redirect_url . "&error=missing_specs");
  57. exit();
  58. }
  59. if ($is_edit) {
  60. // Update existing product
  61. $sql = "UPDATE products SET
  62. ProductName = '" . mysqli_real_escape_string($conn, $product_name) . "',
  63. ProductImg = '" . mysqli_real_escape_string($conn, $product_img) . "',
  64. Addtime = NOW(),
  65. moq = '" . mysqli_real_escape_string($conn, $moq) . "',
  66. unit = '" . mysqli_real_escape_string($conn, $unit) . "',
  67. nosale = '" . $nosale_str . "',
  68. note = '" . mysqli_real_escape_string($conn, $note) . "',
  69. tips = '" . mysqli_real_escape_string($conn, $tips) . "',
  70. category_id = " . $category_id . "
  71. WHERE id = " . (int)$id;
  72. mysqli_query($conn, $sql);
  73. // Clear existing specifications for this product
  74. mysqli_query($conn, "DELETE FROM product_specifications WHERE product_id = " . (int)$id);
  75. // Add new specifications
  76. if (is_array($spec_name) && !empty($spec_name)) {
  77. foreach ($spec_name as $key => $name) {
  78. if (!empty($name) && isset($spec_price[$key]) && !empty($spec_price[$key])) {
  79. $spec_price_value = isset($spec_price[$key]) && is_numeric($spec_price[$key]) ? (float)$spec_price[$key] : 0;
  80. $spec_moq_value = isset($spec_moq[$key]) && is_numeric($spec_moq[$key]) ? (int)$spec_moq[$key] : 1;
  81. $spec_code_value = isset($spec_code[$key]) ? mysqli_real_escape_string($conn, $spec_code[$key]) : '';
  82. $spec_sort_value = isset($spec_sort[$key]) && is_numeric($spec_sort[$key]) ? (int)$spec_sort[$key] : 0;
  83. $spec_value_value = isset($spec_value[$key]) ? mysqli_real_escape_string($conn, $spec_value[$key]) : '';
  84. $sql = "INSERT INTO product_specifications
  85. (product_id, spec_name, spec_value, price, min_order_quantity, spec_code, addtime, sort_order)
  86. VALUES (
  87. " . (int)$id . ",
  88. '" . mysqli_real_escape_string($conn, $name) . "',
  89. '" . $spec_value_value . "',
  90. " . $spec_price_value . ",
  91. " . $spec_moq_value . ",
  92. '" . $spec_code_value . "',
  93. NOW(),
  94. " . $spec_sort_value . "
  95. )";
  96. mysqli_query($conn, $sql);
  97. }
  98. }
  99. }
  100. } else {
  101. // Insert new product
  102. $sql = "INSERT INTO products (ProductName, ProductImg, Addtime, moq, unit, nosale, note, tips, category_id)
  103. VALUES (
  104. '" . mysqli_real_escape_string($conn, $product_name) . "',
  105. '" . mysqli_real_escape_string($conn, $product_img) . "',
  106. NOW(),
  107. '" . mysqli_real_escape_string($conn, $moq) . "',
  108. '" . mysqli_real_escape_string($conn, $unit) . "',
  109. '" . $nosale_str . "',
  110. '" . mysqli_real_escape_string($conn, $note) . "',
  111. '" . mysqli_real_escape_string($conn, $tips) . "',
  112. " . $category_id . "
  113. )";
  114. mysqli_query($conn, $sql);
  115. $id = mysqli_insert_id($conn);
  116. // Add specifications for new product
  117. if (is_array($spec_name) && !empty($spec_name)) {
  118. foreach ($spec_name as $key => $name) {
  119. if (!empty($name) && isset($spec_price[$key]) && !empty($spec_price[$key])) {
  120. $spec_price_value = isset($spec_price[$key]) && is_numeric($spec_price[$key]) ? (float)$spec_price[$key] : 0;
  121. $spec_moq_value = isset($spec_moq[$key]) && is_numeric($spec_moq[$key]) ? (int)$spec_moq[$key] : 1;
  122. $spec_code_value = isset($spec_code[$key]) ? mysqli_real_escape_string($conn, $spec_code[$key]) : '';
  123. $spec_sort_value = isset($spec_sort[$key]) && is_numeric($spec_sort[$key]) ? (int)$spec_sort[$key] : 0;
  124. $spec_value_value = isset($spec_value[$key]) ? mysqli_real_escape_string($conn, $spec_value[$key]) : '';
  125. $sql = "INSERT INTO product_specifications
  126. (product_id, spec_name, spec_value, price, min_order_quantity, spec_code, addtime, sort_order)
  127. VALUES (
  128. " . (int)$id . ",
  129. '" . mysqli_real_escape_string($conn, $name) . "',
  130. '" . $spec_value_value . "',
  131. " . $spec_price_value . ",
  132. " . $spec_moq_value . ",
  133. '" . $spec_code_value . "',
  134. NOW(),
  135. " . $spec_sort_value . "
  136. )";
  137. mysqli_query($conn, $sql);
  138. }
  139. }
  140. }
  141. }
  142. // Redirect after save
  143. mysqli_close($conn);
  144. header("Location: " . $redirect_url);
  145. exit();