diff -r bb97e0de63cf -r 395833e20f88 www/includes/db_inventory_suppliers.php --- a/www/includes/db_inventory_suppliers.php Mon Aug 13 23:01:25 2018 +0200 +++ b/www/includes/db_inventory_suppliers.php Thu Aug 16 16:01:13 2018 +0200 @@ -23,9 +23,12 @@ $sql .= "', phone='" . mysqli_real_escape_string($connect, $_GET['phone']); $sql .= "', notes='" . mysqli_real_escape_string($connect, $_GET['notes']); $sql .= "';"; - error_log("\"$sql\""); - $result = mysqli_query($connect, $sql) or die("SQL Error 1: " . mysqli_error($connect)); - error_log("result " . $result); + $result = mysqli_query($connect, $sql); + if (! $result) { + syslog(LOG_NOTICE, "db_inventory_suppliers: ".$sql." result: ".mysqli_error($connect)); + } else { + syslog(LOG_NOTICE, "db_inventory_suppliers: inserted ".$_GET['name']); + } echo $result; } else if (isset($_GET['update'])) { @@ -40,18 +43,24 @@ $sql .= "', phone='" . mysqli_real_escape_string($connect, $_GET['phone']); $sql .= "', notes='" . mysqli_real_escape_string($connect, $_GET['notes']); $sql .= "' WHERE record='" . $_GET['record'] . "';"; - error_log("\"$sql\""); - $result = mysqli_query($connect, $sql) or die("SQL Error 1: " . mysqli_error($connect)); - error_log("result " . $result); + $result = mysqli_query($connect, $sql); + if (! $result) { + syslog(LOG_NOTICE, "db_inventory_suppliers: ".$sql." result: ".mysqli_error($connect)); + } else { + syslog(LOG_NOTICE, "db_inventory_suppliers: updated record ".$_GET['record']); + } echo $result; } else if (isset($_GET['delete'])) { // DELETE COMMAND // FIXME: need to check if the record is in use $sql = "DELETE FROM `inventory_suppliers` WHERE record='".$_GET['record']."';"; - error_log("\"$sql\""); - $result = mysqli_query($connect, $sql) or die("SQL Error 1: " . mysqli_error($connect)); - error_log("result " . $result); + $result = mysqli_query($connect, $sql); + if (! $result) { + syslog(LOG_NOTICE, "db_inventory_suppliers: ".$sql." result: ".mysqli_error($connect)); + } else { + syslog(LOG_NOTICE, "db_inventory_suppliers: deleted record ".$_GET['record']); + } echo $result; } else {