%
Select Case action
'添加留言调用
Case "add"
'判断是否外部提交
dim From_url,Serv_url
From_url = Cstr(Request.ServerVariables("HTTP_Referer"))
Serv_url = Cstr(Request.ServerVariables("Server_Name"))
If mid(From_url,8,len(Serv_url)) <> Serv_url Then
Response.Write ""
Response.End
End If
'二次判断,防止屏蔽JS后提交数据
Books_Name=htmlencode(Request.form("Books_Name"))
Books_Info=htmlencode(Request.form("Books_Info"))
'判断提交数据是否为空
If Books_info="" then
Response.Write ""
Response.End
'判断昵称能大于5个汉字
ElseIf len(Books_name)>10 then
Response.Write ""
Response.End
'判断留言内容不能小于5个汉字,大于600个汉字!
ElseIf len(Books_info)>600 or len(Books_info)<5 then
Response.Write ""
Response.End
Else
conn.execute("Insert Into [
昵称:桂林米粉网友 综合评分:7.3 时间:2010-1-4 15:17:56 IP: 116.1.100.48 |
细粉汤粉味道不错,值得推荐,尤其在冬季. |
|
查看所有评论] (Books_Name,Books_Leiid,Books_Mail,Books_Qq,Books_Info,Books_Time,Books_Ip) values ('"& Books_Name &"','"& id &"','"& Books_Mail &"','"& Books_Qq &"','"& Books_Info &"','"& now() &"','"& ip &"')")
Response.Redirect Url
Response.End
End If
'回复调用
Case "Reply"
checkadmin
conn.execute("update [ 昵称:桂林米粉网友 综合评分:7.3 时间:2010-1-4 15:17:56 IP: 116.1.100.48 |
细粉汤粉味道不错,值得推荐,尤其在冬季. |
|
查看所有评论] Set Books_Name='"&htmlencode(Request.form("Books_Name"))&"',Books_Info='"& htmlencode(uhtmlencode(Request.form("Books_Info"))) &"',Books_Reply='"& htmlencode(Request.form("Books_Reply")) &"'where Books_Id="& Id &"")
Response.Redirect Url
Response.End
'删除调用
Case "del"
checkadmin
conn.execute("delete from [ 昵称:桂林米粉网友 综合评分:7.3 时间:2010-1-4 15:17:56 IP: 116.1.100.48 |
细粉汤粉味道不错,值得推荐,尤其在冬季. |
|
查看所有评论] where Books_Id="&Id)
Response.Redirect Url
Response.End
'登陆后台调用
Case "logincheck"
Admin_User=htmlencode(Request.form("Admin_User"))
Admin_Pass=md5(Request.form("Admin_Pass"))
Set mRs=conn.execute("select * from [Admin] where Admin_User='"&Admin_User&"' and Admin_Pass='"&Admin_Pass&"'")
If not mRs.eof then
Session("Admin")=mRs("Admin_User")
Response.Redirect Url
Response.End
Else
Response.Write ""
Response.End
End If
'登陆页面
Case "login"
%>