<?php // members.php include_once 'header.php'; if (!isset($_SESSION['email'])) die("<br /><br /><center>You must be logged in to view this page</center>"); $email = $_SESSION['email']; if (isset($_GET['view'])) { $view = sanitizeString($_GET['view']); if ($view == $email) $name = "Your"; else $name = "$view's"; echo "<h3>$name Page</h3>"; showProfile($view); echo "<a href='messages.php?view=$view'>$name Messages</a><br />"; die("<a href='friends.php?view=$view'>$name Friends</a><br />"); } if (isset($_GET['add'])) { $add = sanitizeString($_GET['add']); $query = "SELECT * FROM friends WHERE email='$add' AND friend='$email'"; if (!mysql_num_rows(queryMysql($query))) { $query = "INSERT INTO friends VALUES ('$add', '$email')"; queryMysql($query); } } elseif (isset($_GET['remove'])) { $remove = sanitizeString($_GET['remove']); $query = "DELETE FROM friends WHERE email='$remove' AND friend='$email'"; queryMysql($query); } $result = queryMysql("SELECT first name FROM members ORDER BY email"); $num = mysql_num_rows($result); echo "<h3>Other Members</h3><ul>"; for ($j = 0 ; $j < $num ; ++$j) { $row = mysql_fetch_row($result); if ($row[0] == $email) continue; echo "<li><a href='members.php?view=$row[0]'>$row[0]</a>"; $query = "SELECT * FROM friends WHERE email='$row[0]' AND friend='$email'"; $t1 = mysql_num_rows(queryMysql($query)); $query = "SELECT * FROM friends WHERE email='$email' AND friend='$row[0]'"; $t2 = mysql_num_rows(queryMysql($query)); $addfriend = "add as friend"; if (($t1 + $t2) > 1) { echo " ↔ is a mutual friend"; } elseif ($t1) { echo " ← you are following"; } elseif ($t2) { $addfriend = "recip"; echo " → is following you"; } if (!$t1) { echo " [<a href='members.php?add=".$row[0] . "'>$follow</a>]"; } else { echo " [<a href='members.php?remove=".$row[0] . "'>drop</a>]"; } } ?>