include("include/session.php");
function is_whole_number($var){
return (is_numeric($var)&&(intval($var)==floatval($var)));
}
if ($_POST['id']>0 || $_POST['rating']>0)
{
$Pid=$_POST['id'];
$Prating=$_POST['rating'];
$query = mysql_query("SELECT * FROM rating WHERE id=$Pid");
$result = mysql_fetch_array($query);
if ($Prating>10 || $Prating<1 || is_whole_number($Prating) == false)
{
print "ERROR: Rating must be a whole number between 1 and 10.
";
}
else if(is_whole_number($Pid) == false)
{
print "ERROR: An error occured processing the last rating.
";
}
else if($session->userlevel == 0)
{
print "ERROR: Must be logged in to vote.";
}
else if($result['username']==$session->username)
{
print "ERROR: Cannot rate you own images.
";
}
else
{
mysql_query("UPDATE rating SET overallrating = overallrating + $Prating WHERE id = $Pid") or die('Error, insert query failed');
mysql_query("UPDATE rating SET ratingcount = ratingcount + 1 WHERE id = $Pid") or die('Error, insert query failed');
}
}
?>