diff --git a/schoolaccess.php b/schoolaccess.php index 1e5b4c3..6eb6ddf 100644 --- a/schoolaccess.php +++ b/schoolaccess.php @@ -33,17 +33,17 @@ if($_SESSION['schoolid'] && $_SESSION['schoolaccesscode']) { if($_POST['action']=="save") { - mysql_query("UPDATE schools SET - school='".mysql_escape_string(stripslashes($_POST['school']))."', - address='".mysql_escape_string(stripslashes($_POST['address']))."', - city='".mysql_escape_string(stripslashes($_POST['city']))."', - province_code='".mysql_escape_string(stripslashes($_POST['province_code']))."', - postalcode='".mysql_escape_string(stripslashes($_POST['postalcode']))."', - phone='".mysql_escape_string(stripslashes($_POST['phone']))."', - fax='".mysql_escape_string(stripslashes($_POST['fax']))."', - sciencehead='".mysql_escape_string(stripslashes($_POST['sciencehead']))."', - scienceheademail='".mysql_escape_string(stripslashes($_POST['scienceheademail']))."', - scienceheadphone='".mysql_escape_string(stripslashes($_POST['scienceheadphone']))."' + mysql_query("UPDATE schools SET + school='".mysql_escape_string(stripslashes($_POST['school']))."', + address='".mysql_escape_string(stripslashes($_POST['address']))."', + city='".mysql_escape_string(stripslashes($_POST['city']))."', + province_code='".mysql_escape_string(stripslashes($_POST['province_code']))."', + postalcode='".mysql_escape_string(stripslashes($_POST['postalcode']))."', + phone='".mysql_escape_string(stripslashes($_POST['phone']))."', + fax='".mysql_escape_string(stripslashes($_POST['fax']))."', + sciencehead='".mysql_escape_string(stripslashes($_POST['sciencehead']))."', + scienceheademail='".mysql_escape_string(stripslashes($_POST['scienceheademail']))."', + scienceheadphone='".mysql_escape_string(stripslashes($_POST['scienceheadphone']))."' WHERE id='$school->id'"); if(mysql_error()) @@ -60,10 +60,10 @@ if($_SESSION['schoolid'] && $_SESSION['schoolaccesscode']) /* if($_POST['action']=="numbers") { - mysql_query("UPDATE schools SET - junior='".$_POST['junior']."', - intermediate='".$_POST['intermediate']."', - senior='".$_POST['senior']."' + mysql_query("UPDATE schools SET + junior='".$_POST['junior']."', + intermediate='".$_POST['intermediate']."', + senior='".$_POST['senior']."' WHERE id='$school->id'"); echo mysql_error(); @@ -77,38 +77,40 @@ if($_SESSION['schoolid'] && $_SESSION['schoolaccesscode']) if($_POST['action']=="feedback") { $body=""; - $body.=$_SERVER['REMOTE_ADDR']." (".$_SERVER['REMOTE_HOST'].")\n"; $body.=date("r")."\n"; + $body.=$_SERVER['REMOTE_ADDR']." (".$_SERVER['REMOTE_HOST'].")\n"; $body.="School ID: $school->id\n"; $body.="School Name: $school->school\n"; - $body.="Feedback:\n".$_POST['feedbacktext']."\n"; - echo "mailing ".$config['fairmanageremail']; - mail($config['fairmanageremail'],"School Feedback",$body,"From: webpage@".$_SERVER['SERVER_NAME']); - echo happy(i18n("Thanks for your feedback!")); - + if($school->sciencehead) $body.="Science Teacher: $school->sciencehead\n"; + if($school->scienceheadphone) $body.="Science Teacher Phone: $school->scienceheadphone\n"; + if($school->scienceheademail) $body.="Science Teacher Email: $school->scienceheademail\n"; + $body.="\nFeedback:\n".stripslashes($_POST['feedbacktext'])."\n"; + $returnEmailAddress = $school->scienceheademail; + mail($config['fairmanageremail'],"School Feedback",$body,"From: ". $returnEmailAddress."\nReply-To: ".$returnEmailAddress."\nReturn-Path: ".$returnEmailAddress); + echo happy(i18n("Your feedback has been sent")); } echo "