1 <?php
include "config.php";
2 function auth($userid, $password)
4 $sql = "SELECT username FROM users WHERE username='$userid' AND userpass='$password'";
5 $result = mysql_query($sql);
6 if (!mysql_num_rows($result))
10 $query_data = mysql_fetch_row($result);
11 return $query_data[0];
14 function gettopic($topicid)
16 $sql = "SELECT * FROM topics WHERE topicid='$topicid'";
17 $result = mysql_query($sql);
18 $myrow = mysql_fetch_array($result);
19 return $myrow["topicname"];
21 function getboard($boardid)
23 $sql = "SELECT * FROM boards WHERE boardid='$boardid'";
24 $result = mysql_query($sql);
25 $myrow = mysql_fetch_array($result);
26 return $myrow["boardlevel"];
28 function userlevel($boardid)
30 $sql = "SELECT * FROM users WHERE username='$boardid'";
31 $result = mysql_query($sql);
32 $myrow = mysql_fetch_array($result);
33 return $myrow["level"];
35 $username = auth($uname, $pword);
38 echo "You are not <a href=login.php>Logged In</a>.";
43 echo '<form method=post action=messagesearch.php>
44 <input type=text name=query><br>
45 <br><input type=submit name=submit value="Search">
51 echo 'You must enter what you are searching for..<br><br>
52 <form method=post action=messagesearch.php>
53 <input type=text name=query><br>
54 <br><input type=submit name=submit value="Search">
58 $sql = "SELECT * FROM messages WHERE messbody LIKE '%$query%' ORDER BY messageid ASC LIMIT 0,50";
59 $result = mysql_query($sql);
60 echo "<table width=100%><tr><td><b>Topic Title</b></td><td><b>Posted By</b></td><td><b>Posted At</b></td></tr>";
61 while ($myrow = mysql_fetch_array($result))
63 $topicname = gettopic($myrow["topic"]);
64 $userlevel = userlevel($uname);
65 $boardlevel = getboard($myrow["mesboard"]);
66 if ($userlevel >= $boardlevel)
68 echo "<tr><td><a href=messagelist.php?board=".$myrow["mesboard"]."&topic=".$myrow["topic"].">".$topicname."</a></td><td>".$myrow["messby"]."</td><td>".$myrow["postdate"]."</td></tr>";