Path : /var/www/html/smart_kpp2_bk17 มีค 69/modules/idocument/
File Upload :
Current File : /var/www/html/smart_kpp2_bk17 มีค 69/modules/idocument/save_10 มิย 68.php

<?php 
/** ensure this file is being included by a parent file */
defined( '_VALID_' ) or die( 'Direct Access to this location is not allowed.' );
require_once "time_inc.php";
?>
<?php
//print_r($_REQUEST);
//print_r($_FILES);
//print_r($_SESSION);
foreach($_REQUEST as $key=>$value)
{
  $$key=$value;
}

//$predoc_id ="";
$workgroup = "";//$_SESSION['workgroup'];
$content1 = htmlspecialchars($content1);
$content2 = htmlspecialchars($content2);
$content3 = htmlspecialchars($content3);

//เช็คบุคลากร
$sql_person = "select * from person_main where person_id='$officer'";
$dbquery_person = mysqli_query($connect,$sql_person);
$result_person = mysqli_fetch_array($dbquery_person);
$total_pid = mysqli_num_rows($dbquery_person);
$position_code = $result_person['position_code'];
$department = $result_person['department'];
$fullname=$result_person['prename'].$result_person['name']." ".$result_person['surname'];

//Get book no.
//$sqlBookNo = "Select MAX(book_number) as MaxBookNo From idocument_main Where book_year = (".$_SESSION['bookregister_year'].")";
$sqlBookNo = "Select COUNT(book_number) as MaxBookNo From idocument_main Where book_year = (".$_SESSION['bookregister_year'].")";

$query_BookNo=mysqli_query($connect,$sqlBookNo);
$result_BookNo=mysqli_fetch_array($query_BookNo);

$book_number = $result_BookNo['MaxBookNo']+1;
//$book_number = ($result_BookNo['MaxBookNo'] == NULL)?1:$result_BookNo['MaxBookNo'];
$book_year = $_SESSION['bookregister_year'];
$book_no = $book_number ."/". $book_year;
$book_date = date("Y-m-d");

//$book_status = $book_status;
$sql = "INSERT INTO `idocument_main` (
	`id`, 
	`workgroup`, 
	`workgroup_txt`, 
	`book_year`, 
	`book_number`, 
	`book_no`, 
	`book_date`, 
	`subject`, 
	`pre_doc_id`,
	`book_to`, 
	`content1`, 
	`content2`, 
	`content3`, 
	`officer`, 
	`officer_name`, 
	`officer_position`,
	`book_status`, 
	`book_type`)
	 VALUES 
	 (NULL, 
	 	'$department', 
	 	'$workgroup_txt', 
	 	'$book_year', 
	 	'$book_number', 
	 	'$book_no', 
	 	'$book_date', 
	 	'$subject', 
	 	'$predoc_id', 
	 	'$book_to', 
	 	'$content1', 
	 	'$content2', 
	 	'$content3', 
	 	'$officer', 
	 	'$officer_name', 
	 	'$officer_position',
	 	'$book_status',
	 	'$book_type');";
	//echo $bookto_id;
	//echo $sql;
	$dbquery = mysqli_query($connect,$sql);
	if ($dbquery){
		$last_id = mysqli_insert_id($connect);
		$sqlSento = "Insert INTO idocument_sendto(document_id, rec_id, person_id,document_from,status) 
		Values('$last_id', md5('$last_id'), '$bookto_id', '$officer','1');";
		mysqli_query($connect, $sqlSento);


//Upload file Ref Doc.
			$target_dir = "./modules/".$_GET['option']."/upload_files/";
			$file_no = 0;
         	//for($j=0;$j<count($_FILES['UploadedFile']['tmp_name']);$j++) {
         	for($j=0;$j<count($UploadedFileComment);$j++) {
         		
         		$commentFile = $UploadedFileComment[$j];

				if(!empty($_FILES['UploadedFile']['tmp_name'][$j])) {
					++$file_no;
					$target_file = $target_dir . basename($_FILES["UploadedFile"]["name"][$j]);
					$uploadOk = 1;
					$imageFileType = pathinfo($target_file,PATHINFO_EXTENSION);
					
					$rename_file = $target_dir . $last_id . '-ref-' . round(microtime(true)) . '_'.$file_no.'.'. strtolower($imageFileType);

			    if (move_uploaded_file($_FILES["UploadedFile"]["tmp_name"][$j], $rename_file)) {
			        //echo "The file ". basename( $_FILES["UploadedFile"]["name"][$j]). " has been uploaded.";
			    }

				}else{
					$rename_file = "";
					$imageFileType = "";
				}	
				if($commentFile<>""){
			        $sql = "INSERT INTO idocument_files(document_id, file_name,file_des,filetype, docType) VALUE($last_id,'$rename_file', '$commentFile', '$imageFileType', 'ref')";			       
					$result = mysqli_query($connect,$sql);
				}
			       // echo $sql."<br>";
			}//for	
//Upload file
//Upload file Attach Doc.
			$target_dir = "./modules/".$_GET['option']."/upload_files/";
			$file_no = 0;
         	for($j=0;$j<count($UploadedFileComment2);$j++) {
         		
         		$commentFile = $UploadedFileComment2[$j];

				if(!empty($_FILES['UploadedFile2']['tmp_name'][$j])) {
					++$file_no;
					$target_file = $target_dir . basename($_FILES["UploadedFile2"]["name"][$j]);
					$uploadOk = 1;
					$imageFileType = pathinfo($target_file,PATHINFO_EXTENSION);
					
					$rename_file = $target_dir . $last_id . '-attach-' . round(microtime(true)) . '_'.$file_no.'.'. strtolower($imageFileType);

			    if (move_uploaded_file($_FILES["UploadedFile2"]["tmp_name"][$j], $rename_file)) {
			        //echo "The file ". basename( $_FILES["UploadedFile"]["name"][$j]). " has been uploaded.";
			    }

				}else{
					$rename_file = "";
					$imageFileType = "";
				}							
				if($commentFile<>""){
			        $sql = "INSERT INTO idocument_files(document_id, file_name,file_des,filetype, docType) VALUE($last_id,'$rename_file', '$commentFile', '$imageFileType', 'attach')";			       
					$result = mysqli_query($connect,$sql);
			        //echo $sql."<br>";
				}
			}//for	

//Upload file ร่าง Doc.
			$target_dir = "./modules/".$_GET['option']."/upload_files/";
			$file_no = 0;
         	for($j=0;$j<count($UploadedFileComment3);$j++) {
         		
         		$commentFile = $UploadedFileComment3[$j];

				if(!empty($_FILES['UploadedFile3']['tmp_name'][$j])) {
					++$file_no;
					$target_file = $target_dir . basename($_FILES["UploadedFile3"]["name"][$j]);
					$uploadOk = 1;
					$imageFileType = pathinfo($target_file,PATHINFO_EXTENSION);
					
					$rename_file = $target_dir . $last_id . '-sent-' . round(microtime(true)) . '_'.$file_no.'.'. strtolower($imageFileType);

			    if (move_uploaded_file($_FILES["UploadedFile3"]["tmp_name"][$j], $rename_file)) {
			        //echo "The file ". basename( $_FILES["UploadedFile"]["name"][$j]). " has been uploaded.";
			    }

				}else{
					$rename_file = "";
					$imageFileType = "";
				}							
				if($commentFile<>""){
			        $sql = "INSERT INTO idocument_files(document_id, file_name,file_des,filetype, docType) VALUE($last_id,'$rename_file', '$commentFile', '$imageFileType', 'sent')";			       
					$result = mysqli_query($connect,$sql);
			       // echo $sql."<br>";
				}
			}//for	
//Upload file

if($predoc_id == 1){ //ถ้าบันทึกเสนอให้ส่ง line
	//แจ้งเตือน line ///
	/*
	$officer_name;	//เจ้าของเรื่อง
	$officer_position //ตำแหน่งเจ้าของเรื่อง
	$predoc_id	//สถานะบันทึก 0=ร่าง 1=เสนอ
	$subject  //ชื่อเรื่อง
	$book_type  //ความเร่งด่วน 0=ปกติ 1=ด่วน	2=ด่วนที่สุด 3=ลับ
	$book_no	//เลขที่
	$book_date	//ลงวันที่
	$workgroup_txt	//กลุ่ม
	*/
	$person_id=$officer; 	//เลข ปชช. ของ ผอ.กลุ่มหรือรอง หรือผู้ที่เราจะเสนอบันทึก
	
	if($book_type==0){
		$book_type_name ="ปกติ";
	}elseif($book_type==1){
		$book_type_name ="ด่วน";
	}elseif($book_type==2){
		$book_type_name ="ด่วนที่สุด";
	}elseif($book_type==3){
		$book_type_name ="ลับ";
	}
	$book_date1 = thai_date($book_date);
	$message = "มีบันทึกข้อความ ($book_type_name) เสนอคุณ : $booktotxt \n"; 
	 //   $subject = "$subject"." [$fullname"." $posi_sch]";
	$subject = "เรื่อง: $subject \nเลขที่: $book_no \nลงวันที่: $book_date1 \nเสนอโดย: $officer_name $officer_position \n$workgroup_txt ";
	//require_once "linenotify.php";	 //นำเข้าคำสั่งส่งไลน์
	//require_once "./modules/".$_GET['option']."/linenotify.php";
	//require_once "./modules/".$_GET['option']."/linenotify.php";
	
	//จบแจ้งเตือน line ///
	} //จบการเช็คสถานะบันทึก
	
//Upload file
}
echo "<script language='javascript'>window.location.href ='?option=idocument&task=view'</script>";
?>