Ejemplo n.º 1
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     teaName       = TextBox1.Text.ToString().Trim();
        String     teaInfo1      = TextBox2.Text.ToString().Trim();
        String     teaInfo2      = TextBox4.Text.ToString().Trim();
        String     picUrl        = Common.getUrl("/images/upload_files/teachers/", teacherPic);
        int        teaOrder      = Convert.ToInt32(TextBox3.Text.ToString().Trim());
        String     detail_bottom = FCKeditor_bottom.Value.ToString().Trim();
        String     detail_right  = FCKeditor_right.Value.ToString().Trim();
        sqlManager dbmanager     = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("INSERT INTO teachers ([name],[info1],[info2],[picpath],[t_order],[detail_bottom],[detail_right])"
                                          + "VALUES(@name,@info1,@info2,@picpath,@t_order,@detail_bottom,@detail_right)");

        cmd.Parameters.AddWithValue("@name", teaName);
        cmd.Parameters.AddWithValue("@info1", teaInfo1);
        cmd.Parameters.AddWithValue("@info2", teaInfo2);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@t_order", teaOrder);
        cmd.Parameters.AddWithValue("@detail_bottom", detail_bottom);
        cmd.Parameters.AddWithValue("@detail_right", detail_right);
        if (picUrl != "")
        {
            lastteacherPic.ImageUrl = picUrl;
            lastteacherPic.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("teachers_edit.aspx");
    }
Ejemplo n.º 2
0
    //ÐÞ¸ÄÃÜÂë
    public bool modifyPasswordByeid(string newPassword, int eid)
    {
        newPassword = Common.getMD5Code(newPassword);
        sqlManager dbmanager = sqlManager.createInstance();

        try
        {
            dbmanager.connectDB();
            //SqlCommand cmd = dbmanager.getcmd("UPDATE projects SET [newsTitle]=@newstitle,[newsContent]=@NewsContent,[typeid]=@typeid,[version]=@version,[author]=@author,[addtime]= #" + dtNow + "# WHERE [newsid]=" + newsid);
            string     sql = "UPDATE admin SET [password]=@password where id= " + eid;
            SqlCommand cmd = dbmanager.getcmd(sql);
            cmd.Parameters.AddWithValue("@password", newPassword);
            //cmd.ExecuteNonQuery();
            cmd.ExecuteNonQuery();
            cmd.Connection.Close();
            cmd.Connection.Dispose();
            cmd.Dispose();
            return(true);
        }
        catch
        {
            dbmanager.closeDB();
            return(false);
        }
    }
Ejemplo n.º 3
0
    private void showDetail()
    {
        stu_id = int.Parse(Request.QueryString["id"]);

        if (!IsPostBack)
        {
            sqlManager dbmanager = sqlManager.createInstance();
            dbmanager.connectDB();
            SqlCommand    cmd    = dbmanager.getcmd("select * from students where id=" + stu_id);
            SqlDataReader reader = cmd.ExecuteReader();
            while (reader.Read())
            {
                StringBuilder sb_bottom = new StringBuilder("");
                StringBuilder sb_right  = new StringBuilder("");
                sb_bottom.Append(reader["detail_bottom"].ToString().Trim());
                sb_right.Append(reader["detail_right"].ToString().Trim());
                ltlbottom.Text = sb_bottom.ToString();
                ltlright.Text  = sb_right.ToString();
                String picUrl = reader["picpath"].ToString().Trim();
                if (picUrl != "")
                {
                    laststudentPic.ImageUrl = picUrl;
                    laststudentPic.Visible  = true;
                }
            }
            reader.Close();
            cmd.Connection.Close();
            cmd.Connection.Dispose();
            dbmanager.closeDB();
        }
    }
Ejemplo n.º 4
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     courseName    = TextBox1.Text.ToString().Trim();
        String     courseFit     = TextBox2.Text.ToString().Trim();
        String     courseIntro   = TextBox3.Text.ToString().Trim();
        String     courseContent = TextBox4.Text.ToString().Trim();
        String     courseCtime   = TextBox5.Text.ToString().Trim();
        String     picUrl        = Common.getUrl("/images/upload_files/coursegroup/", coursegroupPic);
        int        type          = Convert.ToInt32(DropDownList1.SelectedValue);
        sqlManager dbmanager     = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("INSERT INTO course_group ([name],[fit],[intro],[content],[ctime],[picpath],[type])"
                                          + "VALUES(@name,@fit,@intro,@content,@ctime,@picpath,@type)");

        cmd.Parameters.AddWithValue("@name", courseName);
        cmd.Parameters.AddWithValue("@fit", courseFit);
        cmd.Parameters.AddWithValue("@intro", courseIntro);
        cmd.Parameters.AddWithValue("@content", courseContent);
        cmd.Parameters.AddWithValue("@ctime", courseCtime);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@type", type);
        if (picUrl != "")
        {
            lastcoursegroupPic.ImageUrl = picUrl;
            lastcoursegroupPic.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("students_edit.aspx");
    }
Ejemplo n.º 5
0
    public bool Check(string managerName, string managerPsw)
    {
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand    cmd    = dbmanager.getcmd("SELECT * FROM admin WHERE UserName='******'and Password='******'");
        SqlDataReader reader = cmd.ExecuteReader();

        if (reader.HasRows)
        {
            reader.Read();
            _id       = int.Parse(reader["id"].ToString().Trim());
            _IsValid  = true;
            _roleId   = int.Parse(reader["roleId"].ToString().Trim());
            _adder    = reader["adder"].ToString();
            _roleName = reader["rolename"].ToString().Trim();
            _username = reader["username"].ToString().Trim();
            //UserId = int.Parse(reader["id"].ToString().Trim());
            //nroleid = int.Parse(reader["roleId"].ToString().Trim());
            reader.Close();
            cmd.Connection.Close();
            cmd.Connection.Dispose();
            cmd.Dispose();
            return(true);
        }
        else
        {
            return(false);
        }
    }
Ejemplo n.º 6
0
 public static sqlManager createInstance()
 {
     if (p == null)
     {
         p = new sqlManager();
     }
     return(p);
 }
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     picUrl    = Common.getUrl("/images/upload_files/news/", courseitemPic);
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand    cmd    = dbmanager.getcmd("select [picpath] from course_item where [id]=" + course_item_id);
        SqlDataReader reader = cmd.ExecuteReader();

        while (reader.Read())
        {
            string _picpath = reader["picpath"].ToString().Trim();
            if (picUrl == "")
            {
                picUrl = _picpath;
            }
            else
            {
                deletePic(reader["picpath"].ToString().Trim());
            }
        }
        reader.Close();


        String courseName = TextBox1.Text.ToString().Trim();
        String cTime      = TextBox2.Text.ToString().Trim();
        String eTime      = TextBox3.Text.ToString().Trim();
        String duration   = TextBox4.Text.ToString().Trim();
        int    locationID = int.Parse(DropDownList1.SelectedValue);
        String circum     = TextBox5.Text.ToString().Trim();
        bool   isFull     = CheckBox1.Checked;
        int    type       = Convert.ToInt32(DropDownList2.SelectedValue);
        string filter     = DDL_a.SelectedValue + DDL_b.SelectedValue + DDL_c.SelectedValue + DDL_d.SelectedValue + DDL_e.SelectedValue + DDL_f.SelectedValue;

        cmd = dbmanager.getcmd("UPDATE course_item SET  [name]=@name,[ctime]=@ctime,[etime]=@etime,[duration]=@duration,[location]=@location,[circum]=@circum,[isfull]=@isfull,[picpath]=@picpath,[type]=@type,[filter]=@filter WHERE [id]=" + course_item_id);
        cmd.Parameters.AddWithValue("@name", courseName);
        cmd.Parameters.AddWithValue("@ctime", cTime);
        cmd.Parameters.AddWithValue("@etime", eTime);
        cmd.Parameters.AddWithValue("@duration", duration);
        cmd.Parameters.AddWithValue("@location", locationID);
        cmd.Parameters.AddWithValue("@circum", circum);
        cmd.Parameters.AddWithValue("@isfull", isFull);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@type", type);
        cmd.Parameters.AddWithValue("@filter", filter);
        if (picUrl != "")
        {
            lastcourseitemPic.ImageUrl = picUrl;
            lastcourseitemPic.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("course_item_edit.aspx");
    }
Ejemplo n.º 8
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     teaName       = TextBox1.Text.ToString().Trim();
        String     teaInfo1      = TextBox2.Text.ToString().Trim();
        String     teaInfo2      = TextBox4.Text.ToString().Trim();
        String     picUrl        = Common.getUrl("/images/upload_files/teachers/", teacherPic);
        int        teaOrder      = Convert.ToInt32(TextBox3.Text.ToString().Trim());
        String     detail_bottom = FCKeditor_bottom.Value.ToString().Trim();
        String     detail_right  = FCKeditor_right.Value.ToString().Trim();
        sqlManager dbmanager     = sqlManager.createInstance();

        dbmanager.connectDB();



        SqlCommand    cmd    = dbmanager.getcmd("select [picpath] from teachers where [id]=" + tea_id);
        SqlDataReader reader = cmd.ExecuteReader();

        while (reader.Read())
        {
            string _picpath = reader["picpath"].ToString().Trim();
            if (picUrl == "")
            {
                picUrl = _picpath;
            }
            else
            {
                deletePic(reader["picpath"].ToString().Trim());
            }
        }
        reader.Close();



        cmd = dbmanager.getcmd("UPDATE teachers SET [name]=@name,[info1]=@info1,[info2]=@info2,[picpath]=@picpath,[t_order]=@t_order,[detail_bottom]=@detail_bottom,[detail_right]=@detail_right WHERE [id]=" + tea_id);
        cmd.Parameters.AddWithValue("@name", teaName);
        cmd.Parameters.AddWithValue("@info1", teaInfo1);
        cmd.Parameters.AddWithValue("@info2", teaInfo2);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@t_order", teaOrder);
        cmd.Parameters.AddWithValue("@detail_bottom", detail_bottom);
        cmd.Parameters.AddWithValue("@detail_right", detail_right);
        if (picUrl != "")
        {
            lastteacherPic.ImageUrl = picUrl;
            lastteacherPic.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("teachers_edit.aspx");
    }
Ejemplo n.º 9
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     picUrl    = Common.getUrl("/images/upload_files/coursegroup/", coursegroupPic);
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand    cmd    = dbmanager.getcmd("select [picpath] from course_group where [id]=" + course_group_id);
        SqlDataReader reader = cmd.ExecuteReader();

        while (reader.Read())
        {
            string _picpath = reader["picpath"].ToString().Trim();
            if (picUrl == "")
            {
                picUrl = _picpath;
            }
            else
            {
                deletePic(reader["picpath"].ToString().Trim());
            }
        }
        reader.Close();



        String courseName    = TextBox1.Text.ToString().Trim();
        String courseFit     = TextBox2.Text.ToString().Trim();
        String courseIntro   = TextBox3.Text.ToString().Trim();
        String courseContent = TextBox4.Text.ToString().Trim();
        String courseCtime   = TextBox5.Text.ToString().Trim();
        int    type          = Convert.ToInt32(DropDownList1.SelectedValue);

        cmd = dbmanager.getcmd("UPDATE course_group SET [name]=@name,[fit]=@fit,[intro]=@intro,[content]=@content,[ctime]=@ctime,[picpath]=@picpath,[type]=@type WHERE [id]=" + course_group_id);
        cmd.Parameters.AddWithValue("@name", courseName);
        cmd.Parameters.AddWithValue("@fit", courseFit);
        cmd.Parameters.AddWithValue("@intro", courseIntro);
        cmd.Parameters.AddWithValue("@content", courseContent);
        cmd.Parameters.AddWithValue("@ctime", courseCtime);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@type", type);
        if (picUrl != "")
        {
            lastcoursegroupPic.ImageUrl = picUrl;
            lastcoursegroupPic.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("course_group_edit.aspx");
    }
Ejemplo n.º 10
0
 private void updateHit()
 {
     if (!IsPostBack)
     {
         sqlManager dbmanager = sqlManager.createInstance();
         dbmanager.connectDB();
         SqlCommand cmd = dbmanager.getcmd("UPDATE news SET [hittime]=[hittime]+1 WHERE [id]=" + news_id);
         cmd.ExecuteNonQuery();
         cmd.Connection.Close();
         cmd.Connection.Dispose();
         cmd.Dispose();
         dbmanager.closeDB();
     }
 }
Ejemplo n.º 11
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("UPDATE keywords SET [name]=@name,[url]=@url WHERE [id]=" + keywords_id);

        cmd.Parameters.AddWithValue("@name", TextBox1.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@url", TextBox2.Text.ToString().Trim());
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("keywords_edit.aspx");
    }
Ejemplo n.º 12
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("INSERT INTO keywords ([name],[url])"
                                          + "VALUES(@name,@url)");

        cmd.Parameters.AddWithValue("@name", TextBox1.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@url", TextBox2.Text.ToString().Trim());
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("keywords_edit.aspx");
    }
Ejemplo n.º 13
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String strStarttime = "";

        if (strStarttime == "")
        {
            strStarttime = DateTime.Now.ToString("G");
        }
        DateTime dt = Convert.ToDateTime(strStarttime);

        String     picUrl    = Common.getUrl("/images/upload_files/news/", newsPic);
        String     picUrl_w  = Common.getUrl("/images/upload_files/news_w/", newsPic_w);
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("INSERT INTO news ([title],[intro],[picpath],[picpath_w],[date],[detail],[type],[sub_type],[tags],[source],[hittime])"
                                          + "VALUES(@title,@intro,@picpath,@picpath_w,@date,@detail,@type,@sub_type,@tags,@source,@hittime)");

        cmd.Parameters.AddWithValue("@title", TextBox1.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@intro", TextBox2.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@picpath_w", picUrl_w);
        cmd.Parameters.AddWithValue("@date", strStarttime);
        cmd.Parameters.AddWithValue("@detail", FCKeditor1.Value.ToString().Trim());
        cmd.Parameters.AddWithValue("@type", Convert.ToInt32(DropDownList1.SelectedValue));
        cmd.Parameters.AddWithValue("@sub_type", Convert.ToInt32(DropDownList2.SelectedValue));
        cmd.Parameters.AddWithValue("@tags", TextBox3.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@source", TextBox4.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@hittime", 0);
        if (picUrl != "")
        {
            lastnewsPic.ImageUrl = picUrl;
            lastnewsPic.Visible  = true;
        }
        if (picUrl_w != "")
        {
            lastnewsPic_w.ImageUrl = picUrl_w;
            lastnewsPic_w.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("news_edit.aspx");
    }
Ejemplo n.º 14
0
    protected void Submit_Click(object sender, EventArgs e)
    {
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("UPDATE q_and_a SET [q_order]=@q_order,[question]=@question,[answer]=@answer WHERE [id]=" + qanda_id);

        cmd.Parameters.AddWithValue("@q_order", TextBox2.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@question", TextBox1.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@answer", FCKeditor1.Value.ToString().Trim());
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("qanda_edit.aspx");
    }
Ejemplo n.º 15
0
    protected void Page_Load(object sender, EventArgs e)
    {
        try
        {
            if (!Session["security"].Equals("safe"))
            {
                Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>");
            }
        }
        catch (Exception ex)
        {
            Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>");
        }

        tea_id = int.Parse(Request.QueryString["id"]);


        //SqlDataSource1.SelectCommand = "SELECT * FROM q_and_a";
        if (!IsPostBack)
        {
            sqlManager dbmanager = sqlManager.createInstance();
            dbmanager.connectDB();
            SqlCommand    cmd    = dbmanager.getcmd("select * from teachers where id=" + tea_id);
            SqlDataReader reader = cmd.ExecuteReader();
            while (reader.Read())
            {
                TextBox1.Text          = reader["name"].ToString().Trim();
                TextBox2.Text          = reader["info1"].ToString().Trim();
                TextBox4.Text          = reader["info2"].ToString().Trim();
                TextBox3.Text          = reader["t_order"].ToString().Trim();
                FCKeditor_bottom.Value = reader["detail_bottom"].ToString().Trim();
                FCKeditor_right.Value  = reader["detail_right"].ToString().Trim();
                String picUrl = reader["picpath"].ToString().Trim();
                if (picUrl != "")
                {
                    lastteacherPic.ImageUrl = picUrl;
                    lastteacherPic.Visible  = true;
                }
            }
            reader.Close();
            cmd.Connection.Close();
            cmd.Connection.Dispose();
            dbmanager.closeDB();
        }
    }
Ejemplo n.º 16
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("INSERT INTO q_and_a ([q_order],[question],[answer])"
                                          + "VALUES(@q_order,@question,@answer)");

        cmd.Parameters.AddWithValue("@q_order", TextBox2.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@question", TextBox1.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@answer", FCKeditor1.Value.ToString().Trim());
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("qanda_edit.aspx");
    }
Ejemplo n.º 17
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     courseName = TextBox1.Text.ToString().Trim();
        String     cTime      = TextBox2.Text.ToString().Trim();
        String     eTime      = TextBox3.Text.ToString().Trim();
        String     duration   = TextBox4.Text.ToString().Trim();
        int        locationID = int.Parse(DropDownList1.SelectedValue);
        String     circum     = TextBox5.Text.ToString().Trim();
        bool       isFull     = CheckBox1.Checked;
        String     picUrl     = Common.getUrl("/images/upload_files/courseitem/", courseitemPic);
        int        type       = Convert.ToInt32(DropDownList2.SelectedValue);
        string     filter     = DDL_a.SelectedValue + DDL_b.SelectedValue + DDL_c.SelectedValue + DDL_d.SelectedValue + DDL_e.SelectedValue + DDL_f.SelectedValue;
        sqlManager dbmanager  = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand cmd = dbmanager.getcmd("INSERT INTO course_item ([name],[ctime],[etime],[duration],[location],[circum],[isfull],[picpath],[type],[filter])"
                                          + "VALUES(@name,@ctime,@etime,@duration,@location,@circum,@isfull,@picpath,@type,@filter)");

        cmd.Parameters.AddWithValue("@name", courseName);
        cmd.Parameters.AddWithValue("@ctime", cTime);
        cmd.Parameters.AddWithValue("@etime", eTime);
        cmd.Parameters.AddWithValue("@duration", duration);
        cmd.Parameters.AddWithValue("@location", locationID);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@circum", circum);
        cmd.Parameters.AddWithValue("@isfull", isFull);
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@type", type);
        cmd.Parameters.AddWithValue("@filter", filter);
        if (picUrl != "")
        {
            lastcourseitemPic.ImageUrl = picUrl;
            lastcourseitemPic.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("course_item_edit.aspx");
    }
Ejemplo n.º 18
0
    public bool CheckPassword(string newPassword, int eid)
    {
        string strOldPassword = "";

        newPassword = Common.getMD5Code(newPassword);
        sqlManager dbmanager = sqlManager.createInstance();

        try
        {
            dbmanager.connectDB();
            //SqlCommand cmd = dbmanager.getcmd("UPDATE projects SET [newsTitle]=@newstitle,[newsContent]=@NewsContent,[typeid]=@typeid,[version]=@version,[author]=@author,[addtime]= #" + dtNow + "# WHERE [newsid]=" + newsid);
            string        sql    = "select * from admin where id= " + eid;
            SqlCommand    cmd    = dbmanager.getcmd(sql);
            SqlDataReader reader = cmd.ExecuteReader();
            while (reader.Read())
            {
                strOldPassword = reader["password"].ToString();
            }
            reader.Close();
            if (newPassword.ToLower() == strOldPassword.ToLower())
            {
                cmd.Connection.Close();
                cmd.Connection.Dispose();
                cmd.Dispose();
                return(true);
            }
            else
            {
                cmd.Connection.Close();
                cmd.Connection.Dispose();
                cmd.Dispose();
                return(false);
            }
        }
        catch
        {
            dbmanager.closeDB();
            return(false);
        }
    }
Ejemplo n.º 19
0
    public bool IsExistUser(string strUsername)
    {
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand    cmd    = dbmanager.getcmd("SELECT userid FROM webuser WHERE username='******'");
        SqlDataReader reader = cmd.ExecuteReader();

        if (reader.HasRows)
        {
            cmd.Connection.Close();
            cmd.Connection.Dispose();
            cmd.Dispose();
            dbmanager.closeDB();
            return(true);
        }
        else
        {
            dbmanager.closeDB();
            return(false);
        }
    }
Ejemplo n.º 20
0
    protected void Page_Load(object sender, EventArgs e)
    {
        try
        {
            if (!Session["security"].Equals("safe"))
            {
                Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>");
            }
        }
        catch (Exception ex)
        {
            Response.Write("<script language='javascript'>window.parent.location.href='../default.aspx'</script>");
        }

        qanda_id = int.Parse(Request.QueryString["id"]);


        //SqlDataSource1.SelectCommand = "SELECT * FROM q_and_a";
        if (!IsPostBack)
        {
            sqlManager dbmanager = sqlManager.createInstance();
            dbmanager.connectDB();
            SqlCommand    cmd    = dbmanager.getcmd("select * from q_and_a where id=" + qanda_id);
            SqlDataReader reader = cmd.ExecuteReader();
            while (reader.Read())
            {
                TextBox1.Text    = reader["question"].ToString().Trim();
                TextBox2.Text    = reader["q_order"].ToString().Trim();
                FCKeditor1.Value = reader["answer"].ToString().Trim();
            }
            reader.Close();
            cmd.Connection.Close();
            cmd.Connection.Dispose();
            dbmanager.closeDB();
        }
        //hpkreturn.NavigateUrl = "EditNews.aspx?vid=" + strVersion + "&cid=" + ncid;
    }
Ejemplo n.º 21
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     picUrl    = Common.getUrl("/images/upload_files/news/", newsPic);
        String     picUrl_w  = Common.getUrl("/images/upload_files/news_w/", newsPic_w);
        sqlManager dbmanager = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand    cmd    = dbmanager.getcmd("select [picpath],[picpath_w] from news where [id]=" + news_id);
        SqlDataReader reader = cmd.ExecuteReader();

        while (reader.Read())
        {
            string _picpath = reader["picpath"].ToString().Trim();
            if (picUrl == "")
            {
                picUrl = _picpath;
            }
            else
            {
                deletePic(reader["picpath"].ToString().Trim());
            }


            string _picpath_w = reader["picpath_w"].ToString().Trim();
            if (picUrl_w == "")
            {
                picUrl_w = _picpath_w;
            }
            else
            {
                deletePic(reader["picpath_w"].ToString().Trim());
            }
        }
        reader.Close();



        String strStarttime = "";

        if (strStarttime == "")
        {
            strStarttime = DateTime.Now.ToString("G");
        }
        DateTime dt = Convert.ToDateTime(strStarttime);


        cmd = dbmanager.getcmd("UPDATE news SET [title]=@title,[intro]=@intro,[picpath]=@picpath,[picpath_w]=@picpath_w,[detail]=@detail,[type]=@type,[sub_type]=@sub_type,[tags]=@tags,[source]=@source WHERE [id]=" + news_id);
        cmd.Parameters.AddWithValue("@title", TextBox1.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@intro", TextBox2.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@picpath", picUrl);
        cmd.Parameters.AddWithValue("@picpath_w", picUrl_w);
        cmd.Parameters.AddWithValue("@detail", FCKeditor1.Value.ToString().Trim());
        cmd.Parameters.AddWithValue("@type", Convert.ToInt32(DropDownList1.SelectedValue));
        cmd.Parameters.AddWithValue("@sub_type", Convert.ToInt32(DropDownList2.SelectedValue));
        cmd.Parameters.AddWithValue("@tags", TextBox3.Text.ToString().Trim());
        cmd.Parameters.AddWithValue("@source", TextBox4.Text.ToString().Trim());
        if (picUrl != "")
        {
            lastnewsPic.ImageUrl = picUrl;
            lastnewsPic.Visible  = true;
        }
        if (picUrl_w != "")
        {
            lastnewsPic_w.ImageUrl = picUrl_w;
            lastnewsPic_w.Visible  = true;
        }
        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("news_edit.aspx");
    }
Ejemplo n.º 22
0
    protected void Submit_Click2(object sender, EventArgs e)
    {
        String     picUrl_top   = Common.getUrl("/images/upload_files/courseimage_top/", coursePic_top);
        String     picUrl_right = Common.getUrl("/images/upload_files/courseimage_right/", coursePic_right);
        sqlManager dbmanager    = sqlManager.createInstance();

        dbmanager.connectDB();
        SqlCommand    cmd    = dbmanager.getcmd("select * from course_image where [id]=" + course_image_id);
        SqlDataReader reader = cmd.ExecuteReader();

        while (reader.Read())
        {
            string _picpath_top = reader["picpath_top"].ToString().Trim();
            if (picUrl_top == "")
            {
                picUrl_top = _picpath_top;
            }
            else
            {
                deletePic(reader["picpath_top"].ToString().Trim());
            }

            string _picpath_right = reader["picpath_right"].ToString().Trim();
            if (picUrl_right == "")
            {
                picUrl_right = _picpath_right;
            }
            else
            {
                deletePic(reader["picpath_right"].ToString().Trim());
            }
        }
        reader.Close();


        cmd = dbmanager.getcmd("UPDATE course_image SET [name]=@name,[picpath_top]=@picpath_top,[picpath_right]=@picpath_right WHERE [id]=" + course_image_id);
        cmd.Parameters.AddWithValue("@name", TextBox1.Text.Trim());
        cmd.Parameters.AddWithValue("@picpath_top", picUrl_top);
        cmd.Parameters.AddWithValue("@picpath_right", picUrl_right);


        if (picUrl_top != "")
        {
            lastcoursePic_top.ImageUrl = picUrl_top;
            lastcoursePic_top.Visible  = true;
        }


        if (picUrl_right != "")
        {
            lastcoursePic_right.ImageUrl = picUrl_right;
            lastcoursePic_right.Visible  = true;
        }

        cmd.ExecuteNonQuery();
        cmd.Connection.Close();
        cmd.Connection.Dispose();
        cmd.Dispose();
        dbmanager.closeDB();
        Response.Redirect("course_image_edit.aspx");
    }