Modificare il file:
\Admin\Admins_view.asp
<%@ Language=VBScript %> <html> <link REL="stylesheet" href="include/style.css" type="text/css"> <!--#include file="include/Admins_dbconnection.asp"--> <!--#include file="include/Admins_variables.asp"--> <!--#include file="include/Admins_aspfunctions.asp"--> <body bgcolor=white> <script language="JavaScript" src="include/ts_picker.js"> </script> <form method="POST" action="Admins_list.asp" name="frmAdmin"> <input type=hidden id="TargetPageNumber" name="TargetPageNumber" value="<%=Request.Form("TargetPageNumber")%>" > <input type=hidden id="cmdGotoPage" name="cmdGotoPage"> <input type=hidden id=masterkey name=masterkey value="<%=Request.Form("masterkey")%>"> <input type=hidden id=action name=action value="backtolist"> <script language="JavaScript"> <!--#INCLUDE FILE="include/jsfunctions.js"--> function GotoPage(nPageNumber) { document.forms.frmAdmin.cmdGotoPage.value = 'GotoPage'; document.forms.frmAdmin.TargetPageNumber.value = nPageNumber; document.forms.frmAdmin.submit(); } </script> </form> <% Session.LCID = 1040 On Error Resume Next mypage=Request.Form("targetpagenumber") if mypage="" then _ mypage=1 myaction=Request.Form("action") if myaction="view" or myaction="deleteimage" then _ myaction="edit" if myaction="add" then _ myaction="added" ' open database connection Set rs = server.CreateObject ("ADODB.Recordset") set dbConnection = server.CreateObject ("ADODB.Connection") dbConnection.ConnectionString = strConnection dbConnection.Open Call ReportError sMode = "Edit" strSQL="select " & AddWrappers("ID") & ", " & AddWrappers("Username") & ", " & AddWrappers("Password") & ", " & AddWrappers("accesso") & ", " & AddWrappers("lista") & ", " & AddWrappers("pin") & ", " if InStr(1, LCase(strSQL), LCase(AddWrappers(strKeyField)))<1 then strSQL = "select " & AddWrappers(strKeyField) & ", " & Mid(strSQL, 8) '1 if strKeyField2<>"" and InStr(1, LCase(strSQL), LCase(AddWrappers(strKeyField2)))<1 then strSQL = "select " & AddWrappers(strKeyField2) & ", " & Mid(strSQL, 8) if strKeyField3<>"" and InStr(1, LCase(strSQL), LCase(AddWrappers(strKeyField3)))<1 then strSQL = "select " & AddWrappers(strKeyField3) & ", " & Mid(strSQL, 8) if Right(strSQL,2)= ", " then strSQL = Left(strSQL, Len(strSQL)-2) '1 strSQL = strSQL & " from " & strTableName strSQL=strSQL & " where " & AddWrappers(strKeyField) & "=" & gstrQuote & Replace(request.form("editid"),"'","''") & gstrQuote if strKeyField2<>"" then _ strSQL=strSQL & " and " & AddWrappers(strKeyField2) & "=" & gstrQuote2 & Replace(request.form("editid2"),"'","''") & gstrQuote2 if strKeyField3<>"" then _ strSQL=strSQL & " and " & AddWrappers(strKeyField3) & "=" & gstrQuote3 & Replace(request.form("editid3"),"'","''") & gstrQuote3 Response.Write "<h1>Visualizza il record [" & strKeyField & ": " & request.form("editid") & "]</h1>" response.write "<div align=left><hr width=300 noshade size=1></div>" LogInfo(strSQL) rs.open strSQL, dbConnection Call ReportError Response.write " <a href=Admins_list.asp onClick=""GotoPage( " & mypage & "); return false;"">Torna all'elenco</a><br><br>" Response.Write "<table cellpadding=2>" %> <form name="editform" method="post" action=Admins_edit.asp> <input type=hidden id="TargetPageNumber" name="TargetPageNumber" value="<%=Request.Form("TargetPageNumber")%>" > <input type=hidden id=masterkey name=masterkey value="<%=Request.Form("masterkey")%>"> <input type=hidden id=NeedQuotes<%=BuildFieldName(strKeyField)%> name=NeedQuotes<%=BuildFieldName(strKeyField)%> value="<%=Request.Form("NeedQuotes" & BuildFieldName(strKeyField))%>"> <% if strKeyField2<>"" then %> <input type=hidden id=NeedQuotes<%=BuildFieldName(strKeyField2)%> name=NeedQuotes<%=BuildFieldName(strKeyField2)%> value="<%=Request.Form("NeedQuotes" & BuildFieldName(strKeyField2))%>"> <% end if %> <% if strKeyField3<>"" then %> <input type=hidden id=NeedQuotes<%=BuildFieldName(strKeyField3)%> name=NeedQuotes<%=BuildFieldName(strKeyField3)%> value="<%=Request.Form("NeedQuotes" & BuildFieldName(strKeyField3))%>"> <% end if %> <table> <% Response.Write "<tr><td class=shade>" & Label(rs.Fields("ID").Name) & "</td>" %> <TD> <% if IsBinaryField(rs.Fields("ID")) or Format("ID")=FORMAT_DATABASE_FILE then Response.Write CreateImageControl(rs, "ID", "") else strData = GetData(rs.Fields("ID"), "") Response.Write ProcessLargeText(strData) end if %> </td> <% Response.Write "<tr><td class=shade>" & Label(rs.Fields("Username").Name) & "</td>" %> <TD> <% if IsBinaryField(rs.Fields("Username")) or Format("Username")=FORMAT_DATABASE_FILE then Response.Write CreateImageControl(rs, "Username", "") else strData = GetData(rs.Fields("Username"), "") Response.Write ProcessLargeText(strData) end if %> </td> <% Response.Write "<tr><td class=shade>" & Label(rs.Fields("Password").Name) & "</td>" %> <TD> <% if IsBinaryField(rs.Fields("Password")) or Format("Password")=FORMAT_DATABASE_FILE then Response.Write CreateImageControl(rs, "Password", "") else strData = GetData(rs.Fields("Password"), "") Response.Write ProcessLargeText(strData) end if %> </td> <% Response.Write "<tr><td class=shade>" & Label(rs.Fields("accesso").Name) & "</td>" %> <TD> <% if IsBinaryField(rs.Fields("accesso")) or Format("accesso")=FORMAT_DATABASE_FILE then Response.Write CreateImageControl(rs, "accesso", "") else strData = GetData(rs.Fields("accesso"), "") Response.Write ProcessLargeText(strData) end if %> </td> <% Response.Write "<tr><td class=shade>" & Label(rs.Fields("lista").Name) & "</td>" %> <TD> <% if IsBinaryField(rs.Fields("lista")) or Format("lista")=FORMAT_DATABASE_FILE then Response.Write CreateImageControl(rs, "lista", "") else strData = GetData(rs.Fields("lista"), "") Response.Write ProcessLargeText(strData) end if %> </td> <% Response.Write "<tr><td class=shade>" & Label(rs.Fields("pin").Name) & "</td>" %> <TD> <% if IsBinaryField(rs.Fields("pin")) or Format("pin")=FORMAT_DATABASE_FILE then Response.Write CreateImageControl(rs, "pin", "") else strData = GetData(rs.Fields("pin"), "") Response.Write ProcessLargeText(strData) end if %> </td> </tr></table> <tr height=50><td colspan=2 align=left> <a href=Admins_list.asp onClick="GotoPage('<%=mypage%>'); return false;"><font size="2">Torna all'elenco</font></a><br> </td></tr> </table> </form> </body> </html>
[
Íàçàä
]