include 'includes/config.inc.php'; if ($logged_in && isset($_POST['add_gift'])) { $title = ''; $description = ''; $link = ''; if (isset($_POST['title'])) { $title = mysql_real_escape_string(trim($_POST['title'])); } if (isset($_POST['description'])) { $description = mysql_real_escape_string(trim($_POST['description'])); } if (isset($_POST['link'])) { $link = mysql_real_escape_string(trim($_POST['link'])); } $sql = "INSERT INTO user_giftwish (title, description, link, id) values ('$title', '$description', '$link', '$user_id')"; $result = mysql_query($sql); if ($result) { echo 'Gift added successfully'; } } if ($logged_in && isset($_POST['del_gift'])) { $gift_id = intval(trim($_POST['gift_id'])); $sql="UPDATE user_giftwish SET active = 0 WHERE gift_id = '$gift_id'"; $result = mysql_query($sql); if ($result) { echo 'Gift deleted!'; } } ?>