File: /home/mckernan/public_html/iJournal/includes/journal/entry.php
<?php
// journal entry data
// init database name
$database = DB_PREFIX;
// process request
if ($sid != '')
{
// sid check
require "includes/session/sidck.php";
// init return value
$rv = '<root>' . PHP_EOL;
$rv .= '<data>' . PHP_EOL;
// fetch database name / open db
if ( isset($_POST['db']) ) $dbn = $_POST['db'];
if ( isset($_GET['db']) ) $dbn = $_GET['db'];
if ($dbn == '') die();
$database .= $dbn;
require "includes/db.php";
// vars
$perid = getvar($db, 'pid', 'int');
// fetch journal entry record
$query = "SELECT * FROM journal WHERE jrnl_per = " . $perid . " LIMIT 1";
if ($result = $db->query($query))
{
$row = $result->fetch_assoc();
$rv .= '<id>' . $row['jrnl_id'] . '</id>' . PHP_EOL;
$rv .= '<per>' . $perid . '</per>' . PHP_EOL;
$rv .= '<gross>' . $row['jrnl_in_gross'] . '</gross>' . PHP_EOL;
$rv .= '<cogs>' . $row['jrnl_in_cogs'] . '</cogs>' . PHP_EOL;
$rv .= '<other0>' . $row['jrnl_in_0'] . '</other0>' . PHP_EOL;
$rv .= '<other1>' . $row['jrnl_in_1'] . '</other1>' . PHP_EOL;
$rv .= '<other2>' . $row['jrnl_in_2'] . '</other2>' . PHP_EOL;
$rv .= '<other3>' . $row['jrnl_in_3'] . '</other3>' . PHP_EOL;
$rv .= '<oh0>' . $row['jrnl_oh_0'] . '</oh0>' . PHP_EOL;
$rv .= '<oh1>' . $row['jrnl_oh_1'] . '</oh1>' . PHP_EOL;
$rv .= '<oh2>' . $row['jrnl_oh_2'] . '</oh2>' . PHP_EOL;
$rv .= '<oh3>' . $row['jrnl_oh_3'] . '</oh3>' . PHP_EOL;
$rv .= '<oh4>' . $row['jrnl_oh_4'] . '</oh4>' . PHP_EOL;
$rv .= '<oh5>' . $row['jrnl_oh_5'] . '</oh5>' . PHP_EOL;
$rv .= '<oh6>' . $row['jrnl_oh_6'] . '</oh6>' . PHP_EOL;
$rv .= '<oh7>' . $row['jrnl_oh_7'] . '</oh7>' . PHP_EOL;
$rv .= '<oh8>' . $row['jrnl_oh_8'] . '</oh8>' . PHP_EOL;
$rv .= '<la0>' . $row['jrnl_la_0'] . '</la0>' . PHP_EOL;
$rv .= '<la1>' . $row['jrnl_la_1'] . '</la1>' . PHP_EOL;
$rv .= '<la2>' . $row['jrnl_la_2'] . '</la2>' . PHP_EOL;
$rv .= '<la3>' . $row['jrnl_la_3'] . '</la3>' . PHP_EOL;
$rv .= '<la4>' . $row['jrnl_la_4'] . '</la4>' . PHP_EOL;
$rv .= '<la5>' . $row['jrnl_la_5'] . '</la5>' . PHP_EOL;
$rv .= '<la6>' . $row['jrnl_la_6'] . '</la6>' . PHP_EOL;
$rv .= '<la7>' . $row['jrnl_la_7'] . '</la7>' . PHP_EOL;
$rv .= '<op0>' . $row['jrnl_op_0'] . '</op0>' . PHP_EOL;
$rv .= '<op1>' . $row['jrnl_op_1'] . '</op1>' . PHP_EOL;
$rv .= '<op2>' . $row['jrnl_op_2'] . '</op2>' . PHP_EOL;
$rv .= '<op3>' . $row['jrnl_op_3'] . '</op3>' . PHP_EOL;
$rv .= '<op4>' . $row['jrnl_op_4'] . '</op4>' . PHP_EOL;
$rv .= '<op5>' . $row['jrnl_op_5'] . '</op5>' . PHP_EOL;
$rv .= '<op6>' . $row['jrnl_op_6'] . '</op6>' . PHP_EOL;
$rv .= '<op7>' . $row['jrnl_op_7'] . '</op7>' . PHP_EOL;
$rv .= '<op8>' . $row['jrnl_op_8'] . '</op8>' . PHP_EOL;
$rv .= '<op9>' . $row['jrnl_op_9'] . '</op9>' . PHP_EOL;
$rv .= '<op10>' . $row['jrnl_op_10'] . '</op10>' . PHP_EOL;
$rv .= '<op11>' . $row['jrnl_op_11'] . '</op11>' . PHP_EOL;
$rv .= '<op12>' . $row['jrnl_op_12'] . '</op12>' . PHP_EOL;
$rv .= '<op13>' . $row['jrnl_op_13'] . '</op13>' . PHP_EOL;
$rv .= '<op14>' . $row['jrnl_op_14'] . '</op14>' . PHP_EOL;
$rv .= '<op15>' . $row['jrnl_op_15'] . '</op15>' . PHP_EOL;
$rv .= '<op16>' . $row['jrnl_op_16'] . '</op16>' . PHP_EOL;
$rv .= '<op17>' . $row['jrnl_op_17'] . '</op17>' . PHP_EOL;
$rv .= '<op18>' . $row['jrnl_op_18'] . '</op18>' . PHP_EOL;
$rv .= '<op19>' . $row['jrnl_op_19'] . '</op19>' . PHP_EOL;
}
else
{
die;
}
// finish output
$rv .= '</data>' . PHP_EOL;
$rv .= '</root>' . PHP_EOL;
// return data
echo $rv;
die;
}
else
{
header('Server: ');
header('X-Powered-By: ');
header("HTTP/1.0 404 Not Found");
}
?>