require_once("db.inc.phtml");
require_once("site.inc.phtml");
if(substr($submit,0,10) == "Add Shipto"){
$sql = "INSERT INTO shipTo (billToID,company,address1,address2,city,state,zip,mainPhone) VALUES ";
$sql .= "(";
$sql .= "'" . addslashes($_POST["billToID"]) . "',";
$sql .= "'" . addslashes($_POST["company"]) . "',";
$sql .= "'" . addslashes($_POST["address1"]) . "',";
$sql .= "'" . addslashes($_POST["address2"]) . "',";
$sql .= "'" . addslashes($_POST["city"]) . "',";
$sql .= "'" . addslashes($_POST["state"]) . "',";
$sql .= "'" . eregi_replace("[^0-9]","",$_POST["zip"]) . "',";
$sql .= "'" . eregi_replace("[^0-9]","",$_POST["mainPhone"]) . "')";
print($sql);
exit;
$result = mysql_query($sql);
if(!$result){
print("Error: " . $sql . " on page " . $PHP_SELF);
exit;
}
header("Location:http://" . $SITEIP . "/DeliveryManager/chooseLocation.phtml?formType=" . $formType . "&billToID=" . $billToID);
exit;
}else{
$sql = "SELECT company,address1,billToID FROM billTo WHERE billToID='" . $billToID . "'";
$result = mysql_query($sql);
if(!$result){
print("Error: " . $sql . " on page " . $PHP_SELF);
exit;
}
$myBillTo = mysql_fetch_array($result);
print("Choose Ship To for " . $myBillTo["company"] . " - " . $myBillTo["address1"] . "
");
$sql = "SELECT * FROM shipTo";
if($hasAccount == "true"){
$sql .= " LEFT JOIN accounts on shipTo.billToID=accounts.accountID";
}
$sql .= " WHERE billToID='" . $billToID . "'";
$sql .= " ORDER BY address1";
print($sql);
$result = mysql_query($sql);
if(!$result){
print("Error: " . $sql . " on page " . $PHP_SELF);
exit;
}
?>
} ?>