function php orig code
function php orig code
php
include("config.php");
use PHPMailer\PHPMailer\PHPMailer;
use PHPMailer\PHPMailer\Exception;
function generateRandomPassword($length = 8) {
$characters = '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
$charactersLength = strlen($characters);
$randomPassword = '';
for ($i = 0; $i < $length; $i++) {
$randomPassword .= $characters[rand(0, $charactersLength - 1)];
}
return $randomPassword;
}
if (isset($_POST['bulk_import'])) {
if (!isset($_FILES['csv_file']) || $_FILES['csv_file']['error'] !==
UPLOAD_ERR_OK) {
echo "<script>alert('Please select a valid CSV file.');
window.location.href='../your_page.php';</script>";
exit();
}
$file = $_FILES['csv_file']['tmp_name'];
$handle = fopen($file, "r");
if (!$handle) {
echo "<script>alert('Error opening file.');
window.location.href='../your_page.php';</script>";
exit();
}
date_default_timezone_set('Asia/Manila');
if ($number_of_rows > 0) {
$row = mysqli_fetch_assoc($result);
$newID = (intval($row['maxid']) + 1);
} else {
$newID = 1;
}
$length = 8;
$characters =
'0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
$randomPassword = '';
for ($i = 0; $i < $length; $i++) {
$randomPassword .= $characters[rand(0, strlen($characters) - 1)];
}
echo $randomPassword;
// Insert into userdata (Default credentials)
$query5 = "INSERT INTO userdata (userid, username, password, user_pos,
user_stat, pass_change, OTP)
VALUES ('$user_id', '$gov_email', '$randomPassword', '',
'Disabled', 'No', '')";
fclose($handle);
echo "<script>alert('CSV file successfully imported!');
window.location.href='../HR/master_list.php';</script>";
}
if(isset($_POST['changepassadmin'])){
$query = "update userdata set password = '".$_POST['password']."' where userid
= '".$_POST['id']."'";
mysqli_query($con,$query);
$date = date("Y-m-d");
$time = date("H:i:s A");
$action = "Change passsword of user: " . $_POST['id'];
$query = "insert into audit_trail values('','".
$_SESSION['userid']."','$action','$date','$time')";
mysqli_query($con,$query);
echo "<script>
alert('Password has been updated successfully!');
window.location.href = '../s_admin/a_list_view_emp.php'; // Replace with
your desired page
</script>";
if (isset($_POST['update_attendance'])) {
// Retrieve values from the form
$id = $_POST['id'];
$t_date = $_POST['t_date'];
$am_time_in = $_POST['am_time_in'];
$am_time_out = $_POST['am_time_out'];
$pm_time_in = $_POST['pm_time_in'];
$pm_time_out = $_POST['pm_time_out'];
// Calculate AM working hours
$am_in = strtotime($am_time_in);
$am_out = strtotime($am_time_out);
$am_hours = ($am_out - $am_in) / 3600; // Convert seconds to hours
echo "<script>
alert('Attendance record updated successfully!');
window.location.href = '../HR/timesheet.php'; // Replace with your
desired page
</script>";
} else {
// Error message
echo "<script>
alert('Error updating record: " . mysqli_error($con) . "');
</script>";
}
}
if(isset($_POST['apply_leave_emp'])){
$query = "SELECT * FROM tbl_employee_info WHERE user_id = '" .
$_SESSION['userid'] . "'";
$res = mysqli_query($con, $query);
$row = mysqli_fetch_assoc($res);
$fullname = $row['first_name'] . ' ' . $row['last_name'];
}
if(isset($_POST['cancel_leave_emp'])){
$query = "update tbl_leave set leave_status = 'Canceled' where id = '".
$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/leave.php' </script>";
}
if(isset($_POST['req_head_approve'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "update tbl_request set req_status = 'Pending', approve_date = '".
$date."', approve_time = '".$time."' where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../head/cert_req.php' </script>";
}
if(isset($_POST['req_head_declined'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "update tbl_request set req_status = 'Declined', approve_date = '".
$date."', approve_time = '".$time."' where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../head/cert_req.php' </script>";
}
if(isset($_POST['req_hr_declined'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "update tbl_request set req_status = 'Declined', approve_date = '".
$date."', approve_time = '".$time."',approve_by='".$_SESSION['userid']."' where id
= '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../hr/cert_req.php' </script>";
}
if(isset($_POST['csr_head'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_SESSION['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending Head','".$_POST['head']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
if(isset($_POST['cna_head'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_SESSION['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending Head','".$_POST['head']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
if(isset($_POST['clb_head'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_SESSION['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending Head','".$_POST['head']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
if(isset($_POST['coe_head'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_SESSION['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending Head','".$_POST['head']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
if(isset($_POST['coec_head'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_SESSION['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending Head','".$_POST['head']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
if (isset($_POST['uploadleave'])) {
// Database connection
// Get form inputs
$id = $_POST['id'];
$uploadDirectory = "upload/"; // Path to the upload folder
$uploadedFiles = [];
$errorsOccurred = false;
if (isset($_POST['uploadleave2'])) {
// Database connection
// Get form inputs
$id = $_POST['id'];
$uploadDirectory = "upload/"; // Path to the upload folder
$uploadedFiles = [];
$errorsOccurred = false;
if(isset($_POST['hr_approve'])){
$yquery = "select * from tbl_employee_info where user_id = '".
$_SESSION['userid']."'";
$yres = mysqli_query($con,$yquery);
$yrow = mysqli_fetch_assoc($yres);
$yfullname = $yrow['first_name'] . ' ' . $yrow['last_name'];
}
if(isset($_POST['head_approve'])){
}
if(isset($_POST['otp'])){
$query = "select * from userdata where username = '".$_SESSION['email']."' and
OTP = '".$_POST['OTP']."'";
$res = mysqli_query($con,$query);
if(mysqli_num_rows($res)<>0){
echo "<script language='javascript' type='text/javascript'>
location.href='../changepassword.php' </script>";
}
else{
// Define the characters to choose from
$characters = '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
$randomString = '';
<div class="footer">
<p>© SDO-GO | Administrator</p>
</div>
</body>
</html>
';
$mail->send();
echo 'Message has been sent';
} catch (Exception $e) { // handle error.
echo 'Message could not be sent. Mailer Error: ', $mail->ErrorInfo;
}
echo "<script>alert('Invalid OTP. Please try again');</script>";
echo "<script language='javascript' type='text/javascript'>
location.href='../OTP.php' </script>";
}
}
if(isset($_POST['forget_password'])){
}
else{
// Define the characters to choose from
$characters = '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
$randomString = '';
<div class="footer">
<p>© SDO-GO | Administrator</p>
</div>
</body>
</html>
';
$mail->send();
echo 'Message has been sent';
} catch (Exception $e) { // handle error.
echo 'Message could not be sent. Mailer Error: ', $mail->ErrorInfo;
}
$_SESSION['email'] = $_POST['email'];
echo "<script language='javascript' type='text/javascript'>
location.href='../OTP.php' </script>";
}
}
if(isset($_POST["add_emp"])){
date_default_timezone_set('Asia/Manila');
$current_date_time = date('Y-m-d');
$x = date('Y');
$date = "SDOGO-". $x . "-";
$query = "SELECT MAX(RIGHT(user_id,4)) as maxid FROM tbl_employee_info where
Left(user_id,11)='$date' order by user_id";
$result = mysqli_query($con,$query);
$number_of_rows = mysqli_num_rows($result);
if($number_of_rows > 0){
$row = mysqli_fetch_assoc($result);
$newID = (intval($row['maxid']) + 1);
$empid1 = $newID;
}
else{
$empid1 = 1;
}
if($empid1<10){
$empid1 = '000' . $empid1;
$empid2 = $date . $empid1;
}
elseif($empid1<100){
$empid1 = '00' . $empid1;
$empid2 = $date . $empid1;
}
elseif($empid1<1000){
$empid1 = '0' . $empid1;
$empid2 = $date . $empid1;
}
$query = "insert into tbl_employee_info values('$empid2','".
$_POST['last_name']."','".$_POST['first_name']."','".$_POST['middle_name']."','".
$_POST['ex_name']."','".$_POST['gender']."','".$_POST['birthdate']."','".
$_POST['place_of_birth']."','".$_POST['contact_num']."','".
$_POST['gov_email']."','".$_POST['employee_no']."' ,'".$_POST['philhealth']."','".
$_POST['pagibig']."','".$_POST['TIN']."','','".$_POST['street_brgy']."','".
$_POST['municipality']."','".$_POST['province']."','".$_POST['region']."','".
$_POST['disability']."','','','$current_date_time')";
mysqli_query($con,$query);
$query = "insert into tbl_employment_info
values('$empid2','','','','','','','','','','','','','','','','','','','')";
mysqli_query($con,$query);
$query = "insert into tbl_eligibility values('$empid2','','','')";
mysqli_query($con,$query);
$mail->send();
} catch (Exception $e) { // handle error.
echo 'Message could not be sent. Mailer Error: ', $mail->ErrorInfo;
}
//end email
$fullname = $_POST['first_name'] . ' ' . $_POST['last_name'];
$action = "Added New Employee | Name: $fullname";
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/a_list_view_emp.php' </script>";
if(isset($_POST['edit_employee'])){
if($_SESSION['user_pos']=='HR'){
$query = "select * from tbl_employment_info where user_id = '".
$_GET['id']."'";
$res = mysqli_query($con,$query);
$row = mysqli_fetch_array($res);
if($row['position']==""){
$query = "insert into tbl_service_rec values('','".$_GET['id']."','".
$_POST['date_orig_appoint']."','Up to date','".
$_POST['designated_to']."','Permanent','".$_POST['salary_step']."','".
$_POST['salary_grade']."','','Tayabas','','".$_POST['position']."')";
mysqli_query($con,$query);
}
$query = "update tbl_employment_info set position = '".
$_POST['position']."',sub_position = '".$_POST['subpos']."', date_orig_appoint='".
$_POST['date_orig_appoint']."', salary_grade='".$_POST['salary_grade']."',
salary_step='".$_POST['salary_step']."', vice='".$_POST['vice']."',vice_reason='".
$_POST['vice_reason']."', nature_appoint='".$_POST['nature_appoint']."',
status_appoint='".$_POST['status_appoint']."', plantilla_item_no='".
$_POST['plantilla_item_no']."', plantilla_inclu='".$_POST['plantilla_inclu']."',
school_office_assign='".$_POST['school_office_assign']."',
school_detailed_office_assign='".$_POST['school_detailed_office_assign']."',
designated_from='".$_POST['designated_from']."', designated_to='".
$_POST['designated_to']."', separation='".$_POST['separation']."',
separation_date='".$_POST['separation_date']."' where user_id='".$_GET['id']."'";
mysqli_query($con,$query);
$query = "update tbl_eligibility set type_eligibility='".
$_POST['type_eligibility']."', date_issue='".$_POST['date_issue']."', validity='".
$_POST['validity']."' where user_id = '".$_GET['id']."'";
mysqli_query($con,$query);
if (isset($_POST['login_stat'])) {
$status = 'Enabled';
}
else{
$status = 'Disabled';
}
$query = "update userdata set user_stat = 'Enabled' where userid = '".
$_GET['id']."'";
mysqli_query($con,$query);
}
}
if(isset($_POST["delete_emp"])){
$query = "select * from tbl_employee_info where user_id = '".$_POST['id']."'";
$res = mysqli_query($con,$query);
$row = mysqli_fetch_array($res);
$id=$_POST['id'];
}
else{
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/salary.php' </script>";
}
}
if(isset($_POST["edit_salary"])){
$query = "update tbl_salary set step_1 = '".$_POST['step_1']."' ,step_2 = '".
$_POST['step_2']."' ,step_4 = '".$_POST['step_4']."',step_5 = '".
$_POST['step_5']."',step_6 = '".$_POST['step_6']."',step_7 = '".
$_POST['step_7']."',step_8 = '".$_POST['step_8']."' where id = '".$_POST['id']."'";
mysqli_query($con,$query);
$id = $_POST['id'];
}
else{
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/salary.php' </script>";
}}
if(isset($_POST["delete_salary"])){
$query = "delete from tbl_salary where id = '".$_POST['id']."'";
mysqli_query($con,$query);
$id = $_POST['id'];
$dateTime = (new DateTime("now", new DateTimeZone("Asia/Manila")))->format("Y-
m-d h:i:s A");
$query = "insert into audit_trail values('','".$_SESSION['userid']."','Remove
Salary: $id','$dateTime')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/c_salary.php' </script>";
}
if(isset($_POST["add_train"])){
}
if (isset($_POST['promote'])) {
$query = "update userdata set user_pos = '".$_POST['position']."' where userid
= '".$_GET['id']."'";
mysqli_query($con,$query);
$query = "update tbl_employment_info set position = '".$_POST['position']."'
where user_id = '".$_GET['id']."'";
mysqli_query($con,$query);
$id = $row['id'];
mysqli_query( $con,$query);
$id = $_GET['id'];
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/emp_service_rec.php?id=$id' </script>";
}
if(isset($_POST['post_admin'])){
$query = "select * from userdata where userid = '".$_SESSION['userid']."'";
$res = mysqli_query($con, $query);
$row = mysqli_fetch_array($res);
date_default_timezone_set('Asia/Manila');
$date = date('m-d-Y h:i:s A');
$query = "insert into tbl_board values('','".$_SESSION['userid']."','".
$row['user_pos']."','".$_POST['title']."','".$_POST['description']."','$date')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/i_notice_board.php' </script>";
}
if(isset($_POST['post_hr'])){
$query = "select * from userdata where userid = '".$_SESSION['userid']."'";
$res = mysqli_query($con, $query);
$row = mysqli_fetch_array($res);
date_default_timezone_set('Asia/Manila');
$date = date('m-d-Y h:i:s A');
$query = "insert into tbl_board values('','".$_SESSION['userid']."','".
$row['user_pos']."','".$_POST['title']."','".$_POST['description']."','$date')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/i_notice_board.php' </script>";
}
if (isset($_POST["apply_leave"])) {
// Fetch user details
$query = "SELECT * FROM tbl_employee_info WHERE user_id = '" .
$_SESSION['userid'] . "'";
$res = mysqli_query($con, $query);
$row = mysqli_fetch_assoc($res);
$fullname = $row['first_name'] . ' ' . $row['last_name'];
if($_SESSION['role_cat']=='Teaching'){
$query = "INSERT INTO tbl_leave VALUES ('', '" . $_SESSION['userid'] . "',
'$fullname', '$position', '" . $_POST['leavetype'] . "', NOW(), '" .
$_POST['start_date'] . "', '" . $_POST['end_date'] . "', '$total_days', '',
'Pending HR','', 'HR','','')";
}
elseif($_POST['role_cat']=='Non-Teaching'){
if($_SESSION['user_pos']=="HR"){
$query = "INSERT INTO tbl_leave VALUES ('', '" . $_SESSION['userid'] .
"', '$fullname', '$position', '" . $_POST['leavetype'] . "', NOW(), '" .
$_POST['start_date'] . "', '" . $_POST['end_date'] . "', '$total_days', '',
'Pending SDS','', '".$_POST['dept_head']."','','')";
}
else{
$query = "INSERT INTO tbl_leave VALUES ('', '" . $_SESSION['userid'] .
"', '$fullname', '$position', '" . $_POST['leavetype'] . "', NOW(), '" .
$_POST['start_date'] . "', '" . $_POST['end_date'] . "', '$total_days', '',
'Pending Head','', '".$_POST['dept_head']."','','')";
}
mysqli_query($con, $query);
$action = '';
if($_SESSION['user_pos']=='HR'){
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/myleave.php' </script>";
}
elseif($_SESSION['user_pos']=='Super Administrator'){
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/leave.php' </script>";
}
else{
$query = "select * from tbl_role where role_desc ='".
$_SESSION['user_pos']."'";
$res = mysqli_query($con,$query);
$row = mysqli_fetch_array($res);
if($row['role_type']=='Department Head'){
echo "<script language='javascript' type='text/javascript'>
location.href='../head/myleave.php' </script>";
}
else{
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/leave.php' </script>";
}
}
}
$empid = $_POST['id'];
$dateTime = (new DateTime("now", new DateTimeZone("Asia/Manila")))->format("Y-
m-d h:i:s A");
$query = "insert into audit_trail values('','".$_SESSION['userid']."','Approve
Leave| Employee ID: $empid','$dateTime')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/leave.php' </script>";
}
if(isset($_POST["decline"])){
$query = "update tbl_leave set leave_status = 'Declined' where id = '".
$_POST['id']."'";
mysqli_query($con,$query);
$empid = $_POST['id'];
$dateTime = (new DateTime("now", new DateTimeZone("Asia/Manila")))->format("Y-
m-d h:i:s A");
$query = "insert into audit_trail values('','".$_SESSION['userid']."','Approve
Leave| Employee ID: $empid','$dateTime')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/leave.php' </script>";
}
if(isset($_POST["boradel_hr"])){
$query = "delete from tbl_board where id = '".$_POST['id']."'";
mysqli_query( $con,$query);
$empid = $_POST['id'];
$dateTime = (new DateTime("now", new DateTimeZone("Asia/Manila")))->format("Y-
m-d h:i:s A");
$query = "insert into audit_trail values('','".$_SESSION['userid']."','Deleted
post','$dateTime')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/i_notice_board.php' </script>";
}
if(isset($_POST["boradel_admin"])){
$query = "delete from tbl_board where id = '".$_POST['id']."'";
mysqli_query( $con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/i_notice_board.php' </script>";
}
if(isset($_POST['csr'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_POST['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending','')";
mysqli_query($con,$query);
$type = $_POST['type'];
}
if(isset($_POST['head_csr'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_POST['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending','')";
mysqli_query($con,$query);
$type = $_POST['type'];
}
if(isset($_POST['coe'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_POST['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending','')";
mysqli_query($con,$query);
if($_SESSION['user_pos']=='Super Administrator'){
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/emp_service_rec.php' </script>";
}
elseif($_SESSION['user_pos']<>'Super Administrator'){
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
}
if(isset($_POST['head_coe'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_POST['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending','')";
mysqli_query($con,$query);
if(isset($_POST['coec'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_POST['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending','')";
mysqli_query($con,$query);
if(isset($_POST['head_cna'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
mysqli_query($con,$query);
if(isset($_POST['cna'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
mysqli_query($con,$query);
if($_SESSION['user_pos']=='Super Administrator'){
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/emp_service_rec.php' </script>";
}
elseif($_SESSION['user_pos']<>'Super Administrator'){
echo "<script language='javascript' type='text/javascript'>
location.href='../employee/emp_service_rec.php' </script>";
}
}
if(isset($_POST['head_clb'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d');
$time = date('h:i:s A');
$query = "insert into tbl_request values('','".$_POST['userid']."','".
$_POST['type']."','".$date."','$time','','','Pending')";
mysqli_query($con,$query);
if(isset($_POST['req_decline'])){
date_default_timezone_set('Asia/Manila');
$date = date('Y-m-d h:i:s A');
$query = "update tbl_request set req_status = 'Declined' , approve_date =
'$date', approve_time = '$time' where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/cert_req.php' </script>";
}
if(isset($_POST["add_train_emp"])){
if (isset($_POST['message'])) {
date_default_timezone_set('Asia/Manila');
$currentDateTime = date('Y/m/d h:i A');
// Bind parameters
$stmt->bind_param("sssss", $row['gov_email'], $_POST['receiver'],
$_POST['messages'], $_POST['subject'], $currentDateTime);
// Bind parameters
$stmt->bind_param("sssss", $row['gov_email'], $_POST['receiver'],
$_POST['messages'], $_POST['subject'], $currentDateTime);
// Bind parameters
$stmt->bind_param("sssss", $row['gov_email'], $_POST['receiver'],
$_POST['messages'], $_POST['subject'], $currentDateTime);
if (isset($_POST['change_pass'])) {
// Get the user ID from the session
$userid = $_SESSION['userid'];
// Step 2: Compare the input old password with the password in the database
(plain-text comparison)
if ($old_password === $db_password) {
// Step 3: If passwords match, update the password in the database (new
password)
$update_stmt = $con->prepare("UPDATE userdata SET password = ? WHERE userid
= ?");
$update_stmt->bind_param("ss", $new_password, $userid);
if ($update_stmt->execute()) {
echo '<div class="alert alert-success">Password changed successfully!
</div>';
} else {
echo '<div class="alert alert-danger">Error updating password. Please
try again.</div>';
}
$update_stmt->close();
} else {
// If old password does not match
echo '<div class="alert alert-danger">Old password is incorrect.</div>';
}
}
if ($updateStmt->execute()) {
// On success, send a response to show the success message
echo '<br><div class="alert alert-success"
id="successMessage">Photo updated successfully!</div>';
} else {
echo '<div class="alert alert-danger">Error updating photo. Please
try again.</div>';
}
$updateStmt->close();
} else {
echo '<div class="alert alert-danger">Sorry, there was an error
uploading your photo.</div>';
}
} else {
echo '<div class="alert alert-danger">File is not an image.</div>';
}
}
if(isset($_POST['update_prof'])) {
$query = "update tbl_employee_info set last_name = '".$_POST['last_name']."',
first_name='".$_POST['first_name']."', middle_name='".$_POST['middle_name']."',
ex_name='".$_POST['ex_name']."', gender='".$_POST['gender']."', birthdate='".
$_POST['birthdate']."', place_of_birth='".$_POST['place_of_birth']."',
contact_num='".$_POST['contact_num']."', gov_email='".$_POST['gov_email']."',
employee_no='".$_POST['employee_no']."', philhealth='".$_POST['philhealth']."',
pagibig='".$_POST['pagibig']."', TIN='".$_POST['TIN']."', street_brgy='".
$_POST['street_brgy']."', municipality='".$_POST['municipality']."', province='".
$_POST['province']."', region='".$_POST['region']."', disability = '".
$_POST['disability']."' where user_id = '".$_SESSION['userid']."'";
mysqli_query($con,$query);
echo $_SESSION['user_pos'];
if($_SESSION['user_pos'] == 'HR'){
echo "<script>alert('Successfully updated');
location.href='../HR/profile.php';</script>";
}
elseif($_SESSION['user_pos'] == 'Employee'){
echo "<script>alert('Successfully updated');
location.href='../empoyee/profile.php';</script>";
}
elseif($_SESSION['user_pos'] == 'Super Administrator'){
}
if(isset($_POST["leave"])) {
$query = "insert into tbl_leavepoints values('','".$_POST['day']."','".
$_POST['day_leave']."','".$_POST['month']."','".$_POST['month_leave']."','".
$_POST['vacation_leave']."','".$_POST['leave_earn_wop']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/leave_points.php' </script>";
}
if(isset($_POST["delete_finger"])) {
$query = "delete from finger_print where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/fingerprint.php' </script>";
}
if(isset($_POST["del_salary"])) {
$query = "delete from tbl_salary where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/salary.php' </script>";
}
if(isset($_POST['edit_leave'])){
$query = "update tbl_leavepoints set leave_day = '".$_POST['leave_day']."',
point_equi = '".$_POST['point_equi']."', month = '".$_POST['month']."', leave_earn
= '".$_POST['leave_earn']."', vacation_leave = '".$_POST['vacation_leave']."',
leave_earn_wop = '".$_POST['leave_earn_wop']."' where id = '".$_POST['id']."'";
mysqli_query($con,$query);
}
if(isset($_POST["delete_leavepts"])) {
$query = "delete from tbl_leavepoints where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/leave_points.php' </script>";
}
if(isset($_POST['edit_leavetype'])){
$query = "update tbl_leavetype set leavetype = '".$_POST['leavetype']."' where
id = '".$_POST['id']."'";
mysqli_query($con,$query);
}
if(isset($_POST['del_leave'])){
$query = "delete from tbl_leavetype where id = '".$_POST['id']."'";
mysqli_query($con,$query);
}
if(isset($_POST['add_leavetype'])){
$query = "insert into tbl_leavetype value('','".$_POST['leavetype']."')";
mysqli_query($con,$query);
$action = "Added Leave | Leave Type: '".$_POST['leavetype']."'";
echo "<script language='javascript' type='text/javascript'>
location.href='../s_admin/leave_type.php' </script>";
}
if(isset($_POST['new_pass'])){
}
if(isset($_POST['delete_eli'])){
$query = "delete from eligibility_list where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/eligibility.php' </script>";
}
if(isset($_POST['edit_eli'])){
$query = "update eligibility_list set description = '".$_POST['description']."'
where id = '".$_POST['id']."'";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/eligibility.php' </script>";
}
if(isset($_POST['add_eli'])){
$query = "insert into eligibility_list value('','".$_POST['description']."')";
mysqli_query($con,$query);
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/eligibility.php' </script>";
}
if(isset($_POST['add_subpos'])){
$query = "insert into sub_position values('','".$_POST['mainpos']."','".
$_POST['subpos']."','')";
mysqli_query($con,$query);
$id = $_POST['mainpos'];
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/role_employee_list.php?id=$id' </script>";
}
if(isset($_POST['del_subpos'])){
$query = "delete from sub_position where id = '".$_POST['subpos']."'";
mysqli_query($con,$query);
$id = $_POST['mainpos'];
echo "<script language='javascript' type='text/javascript'>
location.href='../HR/role_employee_list.php?id=$id' </script>";
}
$date = date("Y-m-d");
$time = date("H:i:s A");
//$query = "insert into audit_trail values('','".
$_SESSION['userid']."','$action','$date','$time')";
//echo $query;
//mysqli_query($con,$query);
mysqli_close($con);
?>