1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
|
if($action=="guthaben_send") {
$guthaben_move=intval($_POST['Betrag']);
$guthaben_move=str_replace("-","",$guthaben_move);
// Guthaben überweisen
$control=$db->query_first("SELECT userid FROM bb".$n."_users WHERE userid='".$_POST['user']."'");
if(isset($_POST['send'])){
if($guthaben_move > $wbbuserdata['guthaben'] OR $guthaben_move <= 0 OR $wbbuserdata[userid] == $_POST['user'] OR $control==""){
eval("\$tpl->output(\"".$tpl->get("usercp_guthaben_send_error1")."\");");
exit;
}
$name=$db->query_first("SELECT userid,username FROM bb".$n."_users WHERE userid='".$_POST['user']."'");
$db->query("INSERT INTO bb".$n."_guthaben_konto (userid,begruendung,wieviel,date) VALUES ($wbbuserdata[userid], 'Guthaben für $name[username]', '-$guthaben_move','".time()."')");
$db->query("INSERT INTO bb".$n."_guthaben_konto (userid,begruendung,wieviel,date) VALUES (".$_POST['user'].", 'Guthaben von $wbbuserdata[username]', '+$guthaben_move','".time()."')");
$db->query("UPDATE bb".$n."_users SET guthaben=guthaben-".$guthaben_move." WHERE userid='".$wbbuserdata['userid']."'");
$db->query("UPDATE bb".$n."_users SET guthaben=guthaben+".$guthaben_move." WHERE userid='".$_POST['user']."'");
header("Location: usercp.php?action=shop&sid=$session[hash]");
exit();
}
$user=$db->query("SELECT userid, username FROM bb".$n."_users ORDER BY username DESC");
while($row=$db->fetch_array($user)){
$user_options.=makeoption($row[userid],$row[username],"",0);
}
eval("\$tpl->output(\"".$tpl->get("usercp_guthaben_send")."\");");
} |