File Manager
Back to List
|
Up to Parent Directory
| Current Directory: ~/research
Editing: research/add_res.asp
Full path: C:\ict\ICT\research\add_res.asp
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="cksession.asp"--> <!--#INCLUDE FILE="Connectdb.asp"--> <html> <head> <script language="javascript"> function doSubmit() { if( document.frmHisDetail.search_title.value == "" ) { alert("��سҡ�͡���ͧҹ�Ԩ��") document.frmHisDetail.search_title.focus() return false; } if( document.frmHisDetail.search_aut.value == "" ) { alert("��سҡ�͡���ѡ�Ԩ��") document.frmHisDetail.search_aut.focus() return false; } if( document.frmHisDetail.search_adv.value == "" ) { alert("��سҡ�͡���ͼ��Ǻ/����֡��") document.frmHisDetail.search_adv.focus() return false; } if( document.frmHisDetail.search_ref.value == "" ) { alert("��سҡ�͡����������ҧ�ԧ") document.frmHisDetail.search_ref.focus() return false; } if ( document.frmHisDetail.search_year.value == "" ) { alert("��سҡ�͡�����Ż����١��ͧ") document.frmHisDetail.search_year.focus() return false; } if ( document.frmHisDetail.search_page.value == "" ) { alert("��سҡ�͡�����Ũӹǹ˹�����١��ͧ") document.frmHisDetail.search_page.focus() return false; } if( document.frmHisDetail.search_sample.value == "" ) { alert("��سҡ�͡���͡����������ҧ") document.frmHisDetail.search_sample.focus() return false; } if( document.frmHisDetail.search_key.value == "" ) { alert("��سҡ�͡���ͤӤ�") document.frmHisDetail.search_key.focus() return false; }} </script></head> <form name="frmHisDetail" Action = "add_data_res.asp" method="post" > <% 'dim ors 'id_res=request.querystring("search_id") set ors=server.createobject("adodb.recordset") sqlmark="select * from temp_id" ors.open sqlmark,Conn,1,3 ors.movelast id_res_new=request("id_res_new") if id_res_new="" then id_res_new=ors("search_id")+1 update_id=session("login") set ors_id=server.createobject("adodb.recordset") sql_id="insert into temp_id(search_id,update_id) values ("&id_res_new&",'"&update_id&"')" ors_id.open sql_id,Conn,1,3 else id_res_new=request("id_res_new") end if %> <div align="center"><strong>���������ŧҹ�Ԩ��</strong></div><br> <table align="center" width="75%"><tr bgcolor ="#FFFFCC"><td class='text'><font color="#660000"><strong>���ʧҹ�Ԩ��</td><td><input type="text" name="search_id" readonly value=<% =id_res_new %>></td></tr> <% response.write "<tr><td><font color='#660000'><strong>���ͧҹ�Ԩ��</td><td><textarea cols='60' name='search_title' rows='4'></textarea>" response.write "</td></tr>" response.write"<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>�������ҹ�Ԩ��<strong></td><td>" 'set ors_type_res=server.createobject("adodb.recordset") %> <select name="search_type"> <% sql_type1="select * from search_type" set ors_type1=server.createobject("adodb.recordset") ors_type1.open sql_type1,conn,1,3 ors_type1.movefirst do while not ors_type1.eof %> <option value = <%=ors_type1("type_id") %>> <%=ors_type1("type_nameth")%></option><% ors_type1.movenext loop%> </select> <% response.write "</td></tr>" response.write "<tr><td><font color='#660000'><strong>�����</td><td ><textarea cols='35' rows='3' name='search_aut' ></textarea></td></tr>" response.write "<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>����� / ����֡��</td><td ><textarea rows='3' cols='60' name='search_adv'></textarea></td></tr>" response.write"<tr><td><font color='#660000'><strong>����Ңͧ�ҹ�Ԩ��</strong></td><td>" 'set ors_type_res=server.createobject("adodb.recordset") %> <select name="search_aff"> <% sql_source="select * from search_source_type" set ors_source=server.createobject("adodb.recordset") ors_source.open sql_source,conn,1,3 ors_source.movefirst do while not ors_source.eof %> <option value = <%=ors_source("source_id")%>><%=ors_source("source_nameth")%></option><% ors_source.movenext loop%> </select> <% response.write "</td></tr>" response.write "<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>������ҧ�ԧ</td><td ><textarea cols='60' rows='3' name='search_ref' ></textarea></td></tr>" response.write "<tr><td><font color='#660000'><strong>�� </td><td><input name='search_year' onkeypress='if (event.keyCode < 46 || event.keyCode >57 ) event.returnValue=false;'></td></tr>" response.write "<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>�ӹǹ˹��</td><td ><input name='search_page' onkeypress='if (event.keyCode < 46 || event.keyCode >57 ) event.returnValue=false;'></td></tr>" response.write "<tr ><td><font color='#660000'><strong>�����������ҧ</td><td ><textarea rows='3' cols='60' name='search_sample' ></textarea></td></tr>" response.write "<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>���Ѵ���</td><td ><A href=abstr_form.asp?check=3>Upload New File</a>" sql_up="select * from temp_upload where search_id="&id_res_new&"" set ors_up =server.createobject("adodb.recordset") ors_up.open sql_up,conn,1,3 if not ors_up.eof then search_thai=ors_up("abstr") 'response.write "dddd"&ors_up("abstr")&"88888" if search_thai <> " " then search_abstr=ors_up("abstr") session("search_abs")=search_abstr response.write " New File [<a href = "&search_abstr&">"&search_abstr&"</a>]" else response.write " New File [None]" end if 'else 'response.write search_abs 'response.write "<br>"&session("search_abs") end if response.write "</td></tr>" response.write "<tr><td><font color='#660000'><strong>Abstract</td><td ><a href=abstr_form.asp?check=4>Upload New File</a>" sql_up="select * from temp_upload where search_id="&id_res_new&" " set ors_up =server.createobject("adodb.recordset") ors_up.open sql_up,conn,1,3 if not ors_up.eof then search_eng=ors_up("abstr_eng") 'response.write search_eng if search_eng <>" " then search_abstr_eng=ors_up("abstr_eng") session("abs_eng")=search_abstr_eng response.write " New File [<a href = "&search_abstr_eng&">"&search_abstr_eng&"</a>]" else response.write " New File [None]" end if response.write abs_eng end if response.write "</td></tr>" response.write "<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>�Ӥ�</td><td ><textarea cols='60' rows='3' name='search_key' ></textarea></td></tr>" loggin=session("login") 'response.write "<tr ><td><font color='#660000'><strong>�����䢤�������ش</td><td ><input name='update_id' value="&loggin&"></td></tr>" datetime=date&time response.write "<tr bgcolor =#FFFFCC><td><font color='#660000'><strong>�ѹ�����䢤�������ش</td><td ><input name='update_date' value = "&datetime&"></td></tr>" response.write "<tr><td colspan='2'><font color='#0066FF'><strong><a href=addtotemp.asp?search_id="&id_res_new&">++��������ͧ����Ѵ++</td></tr>" session("searchid")=id_res_new sqlselectall="select * from temp where search_id = "&id_res_new&" order by meas_id " set orsselectall=server.createobject("adodb.recordset") orsselectall.open sqlselectall,conn,1,3 '=============================================================================== if not orsselectall.eof then %> <table width="75%" border="0" cellpadding="0" cellspacing="0" align ="center"> <tr bgcolor="#660000"> <td><div align="center"><strong><font color="#CCFFCC">��������ͧ����Ѵ</font></strong></div></td> <td><div align="center"><strong><font color="#CCFFCC">��������ͧ����Ѵ</font></strong></div></td> <td><div align="center"><strong><font color="#CCFFCC">ź</font></strong></div></td></tr> <%'response.write sqlselectall colorv=1 orsselectall.movefirst 'on error resume next do while not orsselectall.eof valuecolor = colorv mod 2 if valuecolor = 0 then vcolor = "#ffffff" else vcolor = "#FFFFCC" end if response.write"<tr bgcolor ="& vcolor &"><td width='16%'><div align='center'>"&orsselectall("meas_id")&"</td>" 'response.write"<td>"&orsselectall("meas_id")&"</td></tr>" measids=orsselectall("meas_id") 'response.write measids sql_1= " select * from measurement_ms where meas_id= " & measids & " " ' response.write sql_1 set ors_1=server.createobject("adodb.recordset") ors_1.open sql_1,conn,1,3 'name=ors_1("meas_name") ' response.write name ' response.write sql_1 response.write "<td>"&ors_1("meas_name")&"</td>" response.write "<td><div align='center'><a href='del_temp.asp?meas_id="&measids&"'><img src='picture/i.p.delete.gif' width='11' height='12' border='0' alt='ź'></a><t/d></tr>" orsselectall.movenext colorv=colorv+1 loop end if response.write "</table>" '=========================================================================== 'ors.Open sqlmark, conn, 1, 3 On Error Resume Next ors.Close Conn.Close ' '<SCRIPT LANGUAGE="JavaScript"> '<!-- ' form1.submit(); '//--> '</SCRIPT> 'response.write "<a href=save_edit_res.asp?search_id="&id_res&">�ѹ�֡</a>" %> <div align ="center"><input type="submit" value="�ѹ�֡" onmousedown="doSubmit();" ></div> </FORM> </html>