bindTag.php 1.1 KB

1234567891011121314151617181920212223242526272829303132333435
  1. <?php
  2. require_once 'conn.php';
  3. checkLogin();
  4. $cid = $_GET['cid'] ?? '';
  5. $eid = $_GET['eid'] ?? '';
  6. if (!is_numeric($cid) || !is_numeric($eid)) {
  7. echo "<script>alert('参数错误');</script>";
  8. exit;
  9. }
  10. $tagvalue = urldecode($_GET['tagvalue'] ?? '');
  11. $sql = "SELECT * FROM tagtable WHERE customerId = " . $conn->real_escape_string($cid) .
  12. " AND employeeId = " . $conn->real_escape_string($eid) .
  13. " AND tagName = '" . $conn->real_escape_string($tagvalue) . "'";
  14. $result = $conn->query($sql);
  15. if ($result && $result->num_rows > 0) {
  16. // Tag exists, delete it
  17. $sql = "DELETE FROM tagtable WHERE customerId = " . $conn->real_escape_string($cid) .
  18. " AND employeeId = " . $conn->real_escape_string($eid) .
  19. " AND tagName = '" . $conn->real_escape_string($tagvalue) . "'";
  20. } else {
  21. // Tag doesn't exist, add it
  22. $sql = "INSERT INTO tagtable (tagName, employeeId, customerId) VALUES ('" .
  23. $conn->real_escape_string($tagvalue) . "', " .
  24. $conn->real_escape_string($eid) . ", " .
  25. $conn->real_escape_string($cid) . ")";
  26. }
  27. $conn->query($sql);
  28. ?>