%@ Language=VBScript %>
<%
If session("agentusername")="" Then
ef=True
ec="授权非法,有可能是超时造成的。"
ElseIf RegExpTest("[^A-Za-z0-9]",Request.QueryString ("username")) Then
ef=True
ec="用户名中有非法字符!"
ElseIf not IsNumeric(Request.QueryString ("id")) Then
ef=True
ec="ID应该是数字!"
end if
if not ef then
Set conn=Server.CreateObject("ADODB.Connection")
conn.Open Application("FreeHostDBlink")
Set dsph = Server.CreateObject("ADODB.Recordset")
Sql="Select * from FreeHost.FreeHost_Order where username='"&Request.QueryString ("username")&"' and (agent1='"&session("agentusername")&"' or agent2='"&session("agentusername")&"')"
if Request.QueryString ("id") <>"" then Sql="Select * from FreeHost.FreeHost_Order where id='"&Request.QueryString ("id")&"' and (agent1='"&session("agentusername")&"' or agent2='"&session("agentusername")&"')"
if Instr(1,sql, ";", 1)>0 or Instr(1,sql, "--", 1)>0 then
Response.Write "非法字符!"
Response.End
end if
dsph.Open Sql,conn,1,3
if dsph.Eof then
ef=True
ec="不存在的订单!"
end if
end if
if not ef then
if Request.QueryString ("changestatus")="彻底删除" then
dsph.delete
dsph.update
dsph.close
Response.Redirect "admorder.asp"
end if
if Request.QueryString ("changestatus")="已完成" then
dsph("status")="已完成"
dsph.update
end if
if Request.QueryString ("changestatus")="已取消" then
dsph("status")="已取消"
dsph.update
end if
if Request.QueryString ("changestatus")="未处理" then
dsph("status")="未处理"
dsph.update
end if
if Request.QueryString ("coreinfo")<>"" then
dsph("coreinfo")=Request.QueryString ("coreinfo")
dsph.update
end if
end if
if not ef then
Set ds = Server.CreateObject("ADODB.Recordset")
Sql="Select * from FreeHost.FreeHost_USER where username='"&dsph ("username")&"' and (agent1='"&session("agentusername")&"' or agent2='"&session("agentusername")&"')"
if Instr(1,sql, ";", 1)>0 or Instr(1,sql, "--", 1)>0 then
Response.Write "非法字符!"
Response.End
end if
ds.Open Sql,conn,1,1
%>
<%session("FreeHostCom").FreeHost_WR("html5")%>订单管理
<%session("FreeHostCom").FreeHost_WR("html6")%>
<%if not ds.eof then%>
<%else%>
<%end if%>
|
<%session("FreeHostCom").FreeHost_WR("html7")%>
<%end if
if ef then
Response.Redirect "e.asp?e="&ec
end if%>