<?php include ("connect.php");?>
<?php
// Update Account
if ((isset($_POST["Account"])) && ($_POST["Account"] == "Yes")) {
$Practice = mysqli_real_escape_string($SMB, $_POST["practice"]);
$Dentist = mysqli_real_escape_string($SMB, $_POST["dentist"]);
$Address = mysqli_real_escape_string($SMB, $_POST["address"]);
$City = mysqli_real_escape_string($SMB, $_POST["city"]);
$State = $_POST["state"];
$Zip = $_POST["zip"];
$Phone = $_POST["phone_number"];
$Email = $_POST["email_address"];
$FirstName = mysqli_real_escape_string($SMB, $_POST["first_name"]);
$LastName = mysqli_real_escape_string($SMB, $_POST["last_name"]);
$ID = $_POST["id"];
// Connects to your Database
//Writes the information to the database
mysqli_query($SMB, "UPDATE School_Users SET practice='$Practice', Dentist='$Dentist', address='$Address', city='$City', state='$State', zip='$Zip', first_name='$FirstName', last_name='$LastName', phone_number='$Phone', email_address='$Email' WHERE id='$ID'");
$AddGoTo = "../my-account.php?account=update";
header("Location: $AddGoTo");
}
// Update Account Password
if ((isset($_POST["Password"])) && ($_POST["Password"] == "Yes")) {
$Current = $_POST["current"];
$New = $_POST["new"];
$Confirm = $_POST["confirm"];
$ID = $_POST["id"];
$query_Check_Password = "SELECT * FROM School_Users WHERE id='$ID' AND password='$Current'";
$Check_Password = mysqli_query($SMB, $query_Check_Password);
$row_Check_Password = mysqli_fetch_assoc($Check_Password);
$totalRows_Check_Password = mysqli_num_rows($Check_Password);
if($totalRows_Check_Password > 0){
// Connects to your Database
//Writes the information to the database
mysqli_query($SMB, "UPDATE School_Users SET password='$New' WHERE id='$ID'");
$AddGoTo = "../my-account.php?password=update";
header("Location: $AddGoTo");
}
else {
$AddGoTo = "../my-account.php?password=fail";
header("Location: $AddGoTo");
}
}
?> |