MINI Sh3ll
<?php
class company {
private $objdb;
public function __construct(){
$this->objdb=new database;
return true;
}
public function getCompanyIdByName($company){
$sql = "select id from companies c where status = 1 and name = '".$company."'";
$result = $this->objdb->get_records($sql);
if($result == false)
return false;
else
return $result[0];
}
public function addCompany($company){
$sql = "insert into companies(name, address, city, state, country, pincode, domain, created_by) values(
'".mysql_escape($this->objdb->connection, $company['name'])."',
'".mysql_escape($this->objdb->connection, $company['address'])."',
'".mysql_escape($this->objdb->connection, $company['city'])."',
'".mysql_escape($this->objdb->connection, $company['state'])."',
'".mysql_escape($this->objdb->connection, $company['country'])."',
'".mysql_escape($this->objdb->connection, $company['pincode'])."',
'".mysql_escape($this->objdb->connection, $company['domain'])."',
'".mysql_escape($this->objdb->connection, $company['created_by'])."'
)";
$result = $this->objdb->saveRecords($sql);
return $result;
}
public function getCompanies($status){
$sql = "select * from companies c where c.status in (".$status.")";
$result = $this->objdb->get_records($sql);
return $result;
}
public function getCompanyDetailsById($id){
$sql = "select * from companies c";
if($id != ""){
$sql.=" where c.id = ".$id;
}
$result = $this->objdb->get_records($sql);
return $result;
}
public function updateCompanyDetails($request){
$sql = "UPDATE companies SET name = '".$request['name']."', address='".$request['address']."', city='".$request['city']."', domain='".$request['domain']."' Where id = ".$request['company_id'];
$result = $this->objdb->saveRecords($sql);
return $result;
}
public function updateCompanyStatus($request){
$sql = "update companies SET status = ".$request['status']." WHERE id = '".$request['id']."'";
//print $sql; die;
$result = $this->objdb->saveRecords($sql);
return $result;
}
}
OHA YOOOO