|
- <?php
-
- require_once 'config.php';
- require_once 'dbh.inc.php';
- require_once 'checkLogin.php';
-
-
-
-
-
-
-
- if(isset($_POST['newExperience'])) {
-
-
-
- $title = mysqli_real_escape_string($connection, trim($_POST['title']));
- $description = mysqli_real_escape_string($connection, trim($_POST['description']));
- $type = mysqli_real_escape_string($connection, trim($_POST['type']));
-
- $start_date = mysqli_real_escape_string($connection, trim($_POST['start']));
- $end_date = mysqli_real_escape_string($connection, trim($_POST['end']));
- $institution = mysqli_real_escape_string($connection, trim($_POST['institution']));
- $expiry_time = mysqli_real_escape_string($connection, trim($_POST['expiry_time']));
-
-
- $typeOfExperience = mysqli_real_escape_string($connection, trim($_POST['typeOfExperience']));
- $typeOfProject = mysqli_real_escape_string($connection, trim($_POST['typeOfProject']));
- $projectID = mysqli_real_escape_string($connection, trim($_POST['projectID']));
- $projectName = mysqli_real_escape_string($connection, trim($_POST['projectName']));
- $projectDescription = mysqli_real_escape_string($connection, trim($_POST['projectDescription']));
-
-
-
-
-
- if($title === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify experience title."));
- exit();
- } else if(mb_strlen($title) > 60) {
- http_response_code(400);
- echo json_encode(array("error" => "Experience title too long (max. is 60 characters)."));
- exit();
- }
-
-
-
-
- if($description === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify experience description."));
- exit();
- } else if(mb_strlen($description) > 100) {
- http_response_code(400);
- echo json_encode(array("error" => "Experience description too long (max. is 100 characters)."));
- exit();
- }
-
-
-
-
-
-
-
-
-
-
- if(mb_strlen($type) > 60) {
- http_response_code(400);
- echo json_encode(array("error" => "Experience type too long (max. is 60 characters)."));
- exit();
- }
-
-
-
-
-
-
-
- function validDate($date) {
- $d = date_create_from_format("Y-m-d", $date);
- return $d && date_format($d, "Y-m-d") === $date;
- }
-
- if($start_date === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify experience's start date."));
- exit();
- } else if(!validDate($start_date)) {
- http_response_code(400);
- echo json_encode(array("error" => "Experience's start date ($start_date) given in wrong format (use YYYY-MM-DD instead)."));
- exit();
- }
-
-
-
-
-
-
- if($end_date === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify experience's end date."));
- exit();
- } else if(!validDate($end_date)) {
- http_response_code(400);
- echo json_encode(array("error" => "Experience's end date ($end_date) given in wrong format (use YYYY-MM-DD instead)."));
- exit();
- }
-
-
-
- $duration_seconds = strtotime($end_date) - strtotime($start_date);
-
-
-
- if($duration_seconds <= 0) {
- http_response_code(400);
- echo json_encode(array("error" => "Experience's end date ($end_date) must occur at least a day after the start date ($start_date)."));
- exit();
- }
-
-
-
- $duration_weeks = round($duration_seconds / 604800);
-
-
-
-
- if($institution === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify institution ID."));
- exit();
- } else if(mysqli_query($connection, "SELECT * FROM institution WHERE id = '$institution';")->num_rows !== 1) {
- http_response_code(400);
- echo json_encode(array("error" => "Given institution ID not in database."));
- exit();
- }
-
-
-
- $permittedExpiryTimes = array("30", "60", "120", "180", "360", "720", "1080", "1440");
- if(!in_array($expiry_time, $permittedExpiryTimes, TRUE)) {
- http_response_code(400);
- echo json_encode(array("error" => "Expiry time given is not permitted (use only 30, 60, 120, 180, 360, 720, 1080 or 1440)."));
- exit();
- }
-
-
-
-
-
-
- if($typeOfExperience !== "Standalone" && $typeOfExperience !== "Part of a Project") {
- http_response_code(400);
- echo json_encode(array("error" => "Invalid type of experience."));
- exit();
- }
-
-
- if($typeOfExperience === "Part of a Project") {
-
-
-
- if($typeOfProject === "Existing") {
-
- if(mysqli_query($connection, "SELECT * FROM project WHERE id = '$projectID';")->num_rows !== 1) {
- http_response_code(400);
- echo json_encode(array("error" => "Given project ID ($projectID) not in database."));
- exit();
- }
-
- } else if($typeOfProject === "New") {
-
- if($projectName === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify project name."));
- exit();
- } else if(mb_strlen($projectName) > 256) {
- http_response_code(400);
- echo json_encode(array("error" => "Project name too long (max. is 256 characters)."));
- exit();
- }
-
- if($projectDescription === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify project description."));
- exit();
- } else if(mb_strlen($projectDescription) > 256) {
- http_response_code(400);
- echo json_encode(array("error" => "Project description too long (max. is 256 characters)."));
- exit();
- }
-
- }
-
- }
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- $queryInsert = "INSERT INTO `experience` (`title`, `description`, `type`, `duration_weeks`, `start_date`, `end_date`, `expiry_time`) VALUES ('$title', '$description', '$type', '$duration_weeks', '$start_date', '$end_date', '$expiry_time');";
- if(!mysqli_query($connection, $queryInsert)) die("Error: ".mysqli_error($connection));
-
-
-
- $id_experience = mysqli_insert_id($connection) or die('Error: '.mysqli_error($connection));
-
-
-
- $hash = substr(sha1($id_experience), 0, 40);
- $queryHash = "UPDATE experience SET hash_id = '$hash' WHERE id = '$id_experience';";
- if(!mysqli_query($connection, $queryHash)) die("Error: ".mysqli_error($connection));
-
-
-
- $queryHookExperienceToInstitution = "INSERT INTO `institution_experience` (`id_institution`, `id_experience`) VALUES ('$institution', '$id_experience');";
- if(!mysqli_query($connection, $queryHookExperienceToInstitution)) die("Error: ".mysqli_error($connection));
-
-
-
- $queryHookExperienceToUser = "INSERT INTO `researcher_experience` (`id_researcher`, `id_experience`) VALUES ('" . $_SESSION['dbUserData']['id_researcher'] . "', '$id_experience')";
- if(!mysqli_query($connection, $queryHookExperienceToUser)) die("Error: ".mysqli_error($connection));
-
-
-
-
-
-
-
-
-
- if($typeOfExperience === "Part of a Project") {
-
-
-
- if($typeOfProject === "New") {
-
- $queryProject = "INSERT INTO project (`name`, `description`) VALUES ('$projectName', '$projectDescription');";
- if(!mysqli_query($connection, $queryProject)) die("Error: ".mysqli_error($connection));
-
-
- $projectID = mysqli_insert_id($connection) or die('Error: '.mysqli_error($connection));
-
- }
-
- $queryHookExperienceToProject = "INSERT INTO project_experience (`id_experience`, `id_project`) VALUES ('$id_experience', '$projectID');";
- if(!mysqli_query($connection, $queryHookExperienceToProject)) die("Error: ".mysqli_error($connection));
-
- }
-
-
-
-
-
-
-
- }
-
-
-
|