<%@LANGUAGE="VBSCRIPT" CODEPAGE="1252"%> <% ' *** Restrict Access To Page: Grant or deny access to this page MM_authorizedUsers="Admin" MM_authFailedURL="login.asp" MM_grantAccess=false If Session("MM_Username") <> "" Then If (false Or CStr(Session("MM_UserAuthorization"))="") Or _ (InStr(1,MM_authorizedUsers,Session("MM_UserAuthorization"))>=1) Then MM_grantAccess = true End If End If If Not MM_grantAccess Then MM_qsChar = "?" If (InStr(1,MM_authFailedURL,"?") >= 1) Then MM_qsChar = "&" MM_referrer = Request.ServerVariables("URL") if (Len(Request.QueryString()) > 0) Then MM_referrer = MM_referrer & "?" & Request.QueryString() MM_authFailedURL = MM_authFailedURL & MM_qsChar & "accessdenied=" & Server.URLEncode(MM_referrer) Response.Redirect(MM_authFailedURL) End If %> <% ' *** Edit Operations: declare variables Dim MM_editAction Dim MM_abortEdit Dim MM_editQuery Dim MM_editCmd Dim MM_editConnection Dim MM_editTable Dim MM_editRedirectUrl Dim MM_editColumn Dim MM_recordId Dim MM_fieldsStr Dim MM_columnsStr Dim MM_fields Dim MM_columns Dim MM_typeArray Dim MM_formVal Dim MM_delim Dim MM_altVal Dim MM_emptyVal Dim MM_i MM_editAction = CStr(Request.ServerVariables("SCRIPT_NAME")) If (Request.QueryString <> "") Then MM_editAction = MM_editAction & "?" & Request.QueryString End If ' boolean to abort record edit MM_abortEdit = false ' query string to execute MM_editQuery = "" %> <% If Request.Form("submit") = "Save Note" Then ' *** Update Record: set variables If (CStr(Request("MM_update")) = "addNote" And CStr(Request("MM_recordId")) <> "") Then MM_editConnection = MM_PBBMember_STRING MM_editTable = "MemNotes" MM_editColumn = "ID" MM_recordId = "" + Request.Form("MM_recordId") + "" MM_editRedirectUrl = "notes.asp" MM_fieldsStr = "createdBy|value|editDate|value|headline|value|noteText|value|expDate|value" MM_columnsStr = "EnteredBy|',none,''|EditDate|',none,NULL|Headline|',none,''|NoteText|',none,''|ExpireDate|',none,NULL" ' create the MM_fields and MM_columns arrays MM_fields = Split(MM_fieldsStr, "|") MM_columns = Split(MM_columnsStr, "|") ' set the form values For MM_i = LBound(MM_fields) To UBound(MM_fields) Step 2 MM_fields(MM_i+1) = CStr(Request.Form(MM_fields(MM_i))) Next ' append the query string to the redirect URL If (MM_editRedirectUrl <> "" And Request.QueryString <> "") Then If (InStr(1, MM_editRedirectUrl, "?", vbTextCompare) = 0 And Request.QueryString <> "") Then MM_editRedirectUrl = MM_editRedirectUrl & "?" & Request.QueryString Else MM_editRedirectUrl = MM_editRedirectUrl & "&" & Request.QueryString End If End If End If %> <% ' *** Update Record: construct a sql update statement and execute it If (CStr(Request("MM_update")) <> "" And CStr(Request("MM_recordId")) <> "") Then ' create the sql update statement MM_editQuery = "update " & MM_editTable & " set " For MM_i = LBound(MM_fields) To UBound(MM_fields) Step 2 MM_formVal = MM_fields(MM_i+1) MM_typeArray = Split(MM_columns(MM_i+1),",") MM_delim = MM_typeArray(0) If (MM_delim = "none") Then MM_delim = "" MM_altVal = MM_typeArray(1) If (MM_altVal = "none") Then MM_altVal = "" MM_emptyVal = MM_typeArray(2) If (MM_emptyVal = "none") Then MM_emptyVal = "" If (MM_formVal = "") Then MM_formVal = MM_emptyVal Else If (MM_altVal <> "") Then MM_formVal = MM_altVal ElseIf (MM_delim = "'") Then ' escape quotes MM_formVal = "'" & Replace(MM_formVal,"'","''") & "'" Else MM_formVal = MM_delim + MM_formVal + MM_delim End If End If If (MM_i <> LBound(MM_fields)) Then MM_editQuery = MM_editQuery & "," End If MM_editQuery = MM_editQuery & MM_columns(MM_i) & " = " & MM_formVal Next MM_editQuery = MM_editQuery & " where " & MM_editColumn & " = " & MM_recordId If (Not MM_abortEdit) Then ' execute the update Set MM_editCmd = Server.CreateObject("ADODB.Command") MM_editCmd.ActiveConnection = MM_editConnection MM_editCmd.CommandText = MM_editQuery MM_editCmd.Execute MM_editCmd.ActiveConnection.Close If (MM_editRedirectUrl <> "") Then Response.Redirect(MM_editRedirectUrl) End If End If End If ElseIf Request.Form("submit") = "Delete Note" Then ' *** Delete Record: declare variables if (CStr(Request("MM_delete")) = "addNote" And CStr(Request("MM_recordId")) <> "") Then MM_editConnection = MM_PBBMember_STRING MM_editTable = "MemNotes" MM_editColumn = "ID" MM_recordId = "" + Request.Form("MM_recordId") + "" MM_editRedirectUrl = "notes.asp" ' append the query string to the redirect URL If (MM_editRedirectUrl <> "" And Request.QueryString <> "") Then If (InStr(1, MM_editRedirectUrl, "?", vbTextCompare) = 0 And Request.QueryString <> "") Then MM_editRedirectUrl = MM_editRedirectUrl & "?" & Request.QueryString Else MM_editRedirectUrl = MM_editRedirectUrl & "&" & Request.QueryString End If End If End If %> <% ' *** Delete Record: construct a sql delete statement and execute it If (CStr(Request("MM_delete")) <> "" And CStr(Request("MM_recordId")) <> "") Then ' create the sql delete statement MM_editQuery = "delete from " & MM_editTable & " where " & MM_editColumn & " = " & MM_recordId If (Not MM_abortEdit) Then ' execute the delete Set MM_editCmd = Server.CreateObject("ADODB.Command") MM_editCmd.ActiveConnection = MM_editConnection MM_editCmd.CommandText = MM_editQuery MM_editCmd.Execute MM_editCmd.ActiveConnection.Close If (MM_editRedirectUrl <> "") Then Response.Redirect(MM_editRedirectUrl) End If End If End If End If %> <% Dim adminName__MMColParam adminName__MMColParam = "1" If (Session("MM_Username") <> "") Then adminName__MMColParam = Session("MM_Username") End If %> <% Dim adminName Dim adminName_numRows Set adminName = Server.CreateObject("ADODB.Recordset") adminName.ActiveConnection = MM_PBBMember_STRING adminName.Source = "SELECT FirstName, LastName FROM RosterNew WHERE ID = " + Replace(adminName__MMColParam, "'", "''") + "" adminName.CursorType = 0 adminName.CursorLocation = 2 adminName.LockType = 1 adminName.Open() adminName_numRows = 0 %> <% Dim editNote__MMColParam editNote__MMColParam = "1" If (Request.QueryString("ID") <> "") Then editNote__MMColParam = Request.QueryString("ID") End If %> <% Dim editNote Dim editNote_numRows Set editNote = Server.CreateObject("ADODB.Recordset") editNote.ActiveConnection = MM_PBBMember_STRING editNote.Source = "SELECT * FROM MemNotes WHERE ID = " + Replace(editNote__MMColParam, "'", "''") + "" editNote.CursorType = 0 editNote.CursorLocation = 2 editNote.LockType = 1 editNote.Open() editNote_numRows = 0 %> Edit A Note
 
Members' Area >> Admin Page >> Create a Member Note

Edited By: <%=(adminName.Fields.Item("FirstName").Value)%> <%=(adminName.Fields.Item("LastName").Value)%>  <%=(adminName.Fields.Item("LastName").Value)%>" name="createdBy">
Date Created: <%=(editNote.Fields.Item("CreateDate").Value)%>
Date Edited: <%=Date()%>
Note Headline: ">
Note Text:
Expiration Date: ">
    
">

 

<% adminName.Close() Set adminName = Nothing %> <% editNote.Close() Set editNote = Nothing %>