Path : /var/www/html/smart_kpp2_bk17 มีค 69/modules/idocument/
File Upload :
Current File : /var/www/html/smart_kpp2_bk17 มีค 69/modules/idocument/update.php

<?php 
/** ensure this file is being included by a parent file */
defined( '_VALID_' ) or die( 'Direct Access to this location is not allowed.' );
?>
<?php
//print_r($_REQUEST);
//print_r($_FILES);
//print_r($_SESSION);
foreach($_REQUEST as $key=>$value)
{
  $$key=$value;
}

//$predoc_id ="";
$workgroup = "";//$_SESSION['workgroup'];
$content1 = htmlspecialchars($content1);
$content2 = htmlspecialchars($content2);
$content3 = htmlspecialchars($content3);


//เช็คบุคลากร
$sql_person = "select * from person_main where person_id='$officer'";
$dbquery_person = mysqli_query($connect,$sql_person);
$result_person = mysqli_fetch_array($dbquery_person);
$total_pid = mysqli_num_rows($dbquery_person);
$position_code = $result_person['position_code'];
$department = $result_person['department'];
$fullname=$result_person['prename'].$result_person['name']." ".$result_person['surname'];

$book_year = $_SESSION['bookregister_year'];
$book_number = $id;
$book_no = $book_number ."/". $book_year;
$book_date = date("Y-m-d");
//$book_status = $book_status;
$sql = "UPDATE `idocument_main` SET
	`workgroup` = '$department', 
	`workgroup_txt` = '$workgroup_txt', 
	`book_year` = '$book_year',
	`book_number` = '$book_number',
	`book_no` = '$book_no',
	`book_date` = '$book_date',
	`subject` = '$subject',
	`pre_doc_id` = '1',
	`book_to` = '$book_to', 
	`content1` = '$content1', 
	`content2` = '$content2',  
	`content3`= '$content3',
	`officer` = '$officer', 
	`officer_name` = '$officer_name',
	`officer_position`= '$officer_position',
	`book_status` = '1',
	`book_type` = '$book_type' 
	WHERE id = $id ";

//echo $sql."<br>";

$dbquery = mysqli_query($connect,$sql);
if ($dbquery){
	$last_id = mysqli_insert_id($connect);
	$sqlSento = "UPDATE idocument_sendto SET rec_id = md5('$last_id'), person_id = '$bookto_id',document_from = '$officer', status = 1  Where document_id = '$id' ";
	mysqli_query($connect, $sqlSento);
//echo $sqlSento."<br>";
	
//if($predoc_id == 1){ //ถ้าบันทึกเสนอให้ส่ง line
//แจ้งเตือน line ///
/*
$officer_name;	//เจ้าของเรื่อง
$officer_position //ตำแหน่งเจ้าของเรื่อง
$predoc_id	//สถานะบันทึก 0=ร่าง 1=เสนอ
$subject  //ชื่อเรื่อง
$book_type  //ความเร่งด่วน 0=ปกติ 1=ด่วน	2=ด่วนที่สุด 3=ลับ
$book_no	//เลขที่
$book_date	//ลงวันที่
$workgroup_txt	//กลุ่ม
*/
$person_id=$bookto_id; 	//เลข ปชช. ของ ผอ.กลุ่มหรือรอง หรือผู้ที่เราจะเสนอบันทึก

if($book_type==0){
	$book_type_name ="ปกติ";
}elseif($book_type==1){
	$book_type_name ="ด่วน";
}elseif($book_type==2){
	$book_type_name ="ด่วนที่สุด";
}elseif($book_type==3){
	$book_type_name ="ลับ";
}

$message = "มีบันทึกข้อความ ($book_type_name)\n เสนอคุณ : $booktotxt \n"; 
 //   $subject = "$subject"." [$fullname"." $posi_sch]";
$subject = "เรื่อง: $subject \nเลขที่: $book_no \nลงวันที่: $book_date \nเสนอโดย: $officer_name $officer_position \n$workgroup_txt ";
//require_once "linenotify.php";	 //นำเข้าคำสั่งส่งไลน์
//require_once "./modules/".$_GET['option']."/linenotify.php";

//จบแจ้งเตือน line ///

//} //จบการเช็คสถานะบันทึก
//Upload file Ref Doc.
//Check Ref doc
$sql = "Select * From idocument_files Where document_id = '$id' and docType = 'ref' ";
$result = mysqli_query($connect,$sql);
$row = $result->fetch_assoc();
            $file_name = $row['file_name'];
            $file_des = $row['file_des'];

			$target_dir = "./modules/".$_GET['option']."/upload_files/";
			$file_no = 0;
         	//for($j=0;$j<count($_FILES['UploadedFile']['tmp_name']);$j++) {
         	
         		$commentFile = $UploadedFileComment1;

				if(!empty($_FILES['UploadedFile1']['tmp_name'])) {
					++$file_no;
					$target_file = $target_dir . basename($_FILES["UploadedFile1"]["name"]);
					$uploadOk = 1;
					$imageFileType = pathinfo($target_file,PATHINFO_EXTENSION);
					
					$rename_file = $target_dir . $id . '-ref-' . round(microtime(true)) . '_'.$file_no.'.'. strtolower($imageFileType);

			    if (move_uploaded_file($_FILES["UploadedFile1"]["tmp_name"], $rename_file)) {
			        //echo "The file ". basename( $_FILES["UploadedFile"]["name"][$j]). " has been uploaded.";

				}else{
					$rename_file = "";
					$imageFileType = "";
				}	
				if($commentFile != $file_des){
			        $sql = "INSERT INTO idocument_files(id, document_id, file_name,file_des,filetype, docType) VALUE('', $id,'$rename_file', '$commentFile', '$imageFileType', 'ref')";			       
					$result = mysqli_query($connect,$sql);
					echo $sql."<br>";
				}
				if($file_name != $rename_file){
			        $sql = "UPDATE idocument_files SET file_name = '$rename_file', file_des = '$commentFile', filetype = '$imageFileType' Where document_id = '$id' and docType = 'ref' ";			       
					$result = mysqli_query($connect,$sql);
				}
			        echo $sql."<br>";
			 }
//Upload file
//Upload file Attach Doc.
$sql = "Select * From idocument_files Where document_id = '$id' and docType = 'attach' ";
$result = mysqli_query($connect,$sql);
$row = $result->fetch_assoc();
            $file_name = $row['file_name'];
            $file_des = $row['file_des'];

			$target_dir = "./modules/".$_GET['option']."/upload_files/";
			$file_no = 0;
        
         		$commentFile = $UploadedFileComment2;

				if(!empty($_FILES['UploadedFile2']['tmp_name'])) {
					++$file_no;
					$target_file = $target_dir . basename($_FILES["UploadedFile2"]["name"]);
					$uploadOk = 1;
					$imageFileType = pathinfo($target_file,PATHINFO_EXTENSION);
					
					$rename_file = $target_dir . $id . '-attach-' . round(microtime(true)) . '_'.$file_no.'.'. strtolower($imageFileType);

			    if (move_uploaded_file($_FILES["UploadedFile2"]["tmp_name"], $rename_file)) {
			        //echo "The file ". basename( $_FILES["UploadedFile"]["name"][$j]). " has been uploaded."

				}else{
					$rename_file = "";
					$imageFileType = "";
				}
				if($commentFile != $file_des){
			        $sql = "INSERT INTO idocument_files(id, document_id, file_name,file_des,filetype, docType) VALUE('', $id,'$rename_file', '$commentFile', '$imageFileType', 'attach')";			       
					$result = mysqli_query($connect,$sql);
					echo $sql."<br>";
				}
				if($file_name != $rename_file){
			        $sql = "UPDATE idocument_files SET file_name = '$rename_file', file_des = '$commentFile', filetype = '$imageFileType' Where document_id = '$id' and docType = 'attach' ";			       
					$result = mysqli_query($connect,$sql);
				}
					//echo $sql."<br>";
			}

//Upload file ร่าง Doc.
//Upload file Attach Doc.
$sql = "Select * From idocument_files Where document_id = '$id' and docType = 'sent' ";
$result = mysqli_query($connect,$sql);
$row = $result->fetch_assoc();
            $file_name = $row['file_name'];
            $file_des = $row['file_des'];

			$target_dir = "./modules/".$_GET['option']."/upload_files/";
			$file_no = 0;
        
         		$commentFile = $UploadedFileComment3;

				if(!empty($_FILES['UploadedFile3']['tmp_name'])) {
					++$file_no;
					$target_file = $target_dir . basename($_FILES["UploadedFile3"]["name"]);
					$uploadOk = 1;
					$imageFileType = pathinfo($target_file,PATHINFO_EXTENSION);
					
					$rename_file = $target_dir . $id . '-sent-' . round(microtime(true)) . '_'.$file_no.'.'. strtolower($imageFileType);

			    if (move_uploaded_file($_FILES["UploadedFile3"]["tmp_name"], $rename_file)) {
			        //echo "The file ". basename( $_FILES["UploadedFile"]["name"][$j]). " has been uploaded."

				}else{
					$rename_file = "";
					$imageFileType = "";
				}
				if($commentFile != $file_des){
			        $sql = "INSERT INTO idocument_files(id, document_id, file_name,file_des,filetype, docType) VALUE('', $id,'$rename_file', '$commentFile', '$imageFileType', 'sent')";			       
					$result = mysqli_query($connect,$sql);
					echo $sql."<br>";
				}
				if($file_name != $rename_file){
			        $sql = "UPDATE idocument_files SET file_name = '$rename_file', file_des = '$commentFile', filetype = '$imageFileType' Where document_id = '$id' and docType = 'sent' ";			       
					$result = mysqli_query($connect,$sql);
				}
					//echo $sql."<br>";
			}//for	

//Upload file
}
echo "<script language='javascript'>window.location.href ='?option=".$option."&task=view'</script>";
?>