<?php
  // load viewer library
  $libraryPath = 'cmsAdmin/lib/viewer_functions.php';
  $dirsToCheck = array('/home/qaa/public_html/','','../','../../','../../../');
  foreach ($dirsToCheck as $dir) { if (@include_once("$dir$libraryPath")) { break; }}
  if (!function_exists('getRecords')) { die("Couldn't load viewer library, check filepath in sourcecode."); }
  
// submit form
if (@$_REQUEST['submit']) {

  // error checking
  $alertsAndErrors = "";
  if (!@$_REQUEST['company'])    { $alertsAndErrors .= "Please specify company!<br/>\n"; }

  // turn off strict mysql error checking for: STRICT_ALL_TABLES
  $mysqlVersion = preg_replace("/[^0-9\.]/", "", mysql_get_server_info());
  $isMySql5     = version_compare($mysqlVersion, '5.0.0', '>=');
  if ($isMySql5) {
    mysql_query("SET SESSION sql_mode = 'NO_ZERO_IN_DATE,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER'") or die("MySQL Error: " .mysql_error(). "\n");
  }

  // add record
  if (!@$alertsAndErrors) {
    mysql_query("INSERT INTO `{$TABLE_PREFIX}application_form` SET
      company                           = '".mysql_real_escape_string( $_REQUEST['company'] )."',
      abn                               = '".mysql_real_escape_string( $_REQUEST['abn'] )."',
      established                       = '".mysql_real_escape_string( $_REQUEST['established'] )."',
      company_type                      = '".mysql_real_escape_string( $_REQUEST['company_type'] )."',
      if_other                          = '".mysql_real_escape_string( $_REQUEST['if_other'] )."',
      email                             = '".mysql_real_escape_string( $_REQUEST['email'] )."',
      telephone                         = '".mysql_real_escape_string( $_REQUEST['telephone'] )."',
      fax                               = '".mysql_real_escape_string( $_REQUEST['fax'] )."',
      mobile                            = '".mysql_real_escape_string( $_REQUEST['mobile'] )."',
      period_from                       = '".mysql_real_escape_string( $_REQUEST['period_from'] )."',
      period_to                         = '".mysql_real_escape_string( $_REQUEST['period_to'] )."',
      public_liability                  = '".mysql_real_escape_string( $_REQUEST['public_liability'] )."',
      product                           = '".mysql_real_escape_string( $_REQUEST['product'] )."',
      professional                      = '".mysql_real_escape_string( $_REQUEST['professional'] )."',
      description                       = '".mysql_real_escape_string( $_REQUEST['description'] )."',
      powerline_clearing                = '".mysql_real_escape_string( $_REQUEST['powerline_clearing'] )."',
      powerline_clearing_yes            = '".mysql_real_escape_string( $_REQUEST['powerline_clearing_yes'] )."',
      no_type_unregistered_vehicles     = '".mysql_real_escape_string( $_REQUEST['no_type_unregistered_vehicles'] )."',
      lifting_equipment                 = '".mysql_real_escape_string( $_REQUEST['lifting_equipment'] )."',
      actual                            = '".mysql_real_escape_string( $_REQUEST['actual'] )."',
      estimate                          = '".mysql_real_escape_string( $_REQUEST['estimate'] )."',
      years_in_business                 = '".mysql_real_escape_string( $_REQUEST['years_in_business'] )."',
      no_employees                      = '".mysql_real_escape_string( $_REQUEST['no_employees'] )."',
      estimated_total_annual_wages      = '".mysql_real_escape_string( $_REQUEST['estimated_total_annual_wages'] )."',
      sub_contractors                   = '".mysql_real_escape_string( $_REQUEST['sub_contractors'] )."',
      subcontactor_wages                = '".mysql_real_escape_string( $_REQUEST['subcontactor_wages'] )."',
      previous_experience               = '".mysql_real_escape_string( $_REQUEST['previous_experience'] )."',
      additional_services               = '".mysql_real_escape_string( $_REQUEST['additional_services'] )."',
      additional_services_details       = '".mysql_real_escape_string( $_REQUEST['additional_services_details'] )."',
      accepted_liability                = '".mysql_real_escape_string( $_REQUEST['accepted_liability'] )."',
      given_away_rights                 = '".mysql_real_escape_string( $_REQUEST['given_away_rights'] )."',
      claims_against                    = '".mysql_real_escape_string( $_REQUEST['claims_against'] )."',
      a_loss_date                       = '".mysql_real_escape_string( $_REQUEST['a_loss_date'] )."',
      a_loss_description                = '".mysql_real_escape_string( $_REQUEST['a_loss_description'] )."',
      a_loss_paid                       = '".mysql_real_escape_string( $_REQUEST['a_loss_paid'] )."',
      a_loss_reserve                    = '".mysql_real_escape_string( $_REQUEST['a_loss_reserve'] )."',
      b_loss_date                       = '".mysql_real_escape_string( $_REQUEST['b_loss_date'] )."',
      b_loss_description                = '".mysql_real_escape_string( $_REQUEST['b_loss_description'] )."',
      b_loss_paid                       = '".mysql_real_escape_string( $_REQUEST['b_loss_paid'] )."',
      b_loss_reserve                    = '".mysql_real_escape_string( $_REQUEST['b_loss_reserve'] )."',
      c_loss_date                       = '".mysql_real_escape_string( $_REQUEST['c_loss_date'] )."',
      c_loss_description                = '".mysql_real_escape_string( $_REQUEST['c_loss_description'] )."',
      c_loss_paid                       = '".mysql_real_escape_string( $_REQUEST['c_loss_paid'] )."',
      c_loss_reserve                    = '".mysql_real_escape_string( $_REQUEST['c_loss_reserve'] )."',
      addition_claims_against           = '".mysql_real_escape_string( $_REQUEST['addition_claims_against'] )."',
      additional_claims_detail          = '".mysql_real_escape_string( $_REQUEST['additional_claims_detail'] )."',
      a_previous_insurer_name           = '".mysql_real_escape_string( $_REQUEST['a_previous_insurer_name'] )."',
      a_previous_from                   = '".mysql_real_escape_string( $_REQUEST['a_previous_from'] )."',
      a_previous_to                     = '".mysql_real_escape_string( $_REQUEST['a_previous_to'] )."',
      b_previous_insurer_name           = '".mysql_real_escape_string( $_REQUEST['b_previous_insurer_name'] )."',
      b_previous_from                   = '".mysql_real_escape_string( $_REQUEST['b_previous_from'] )."',
      b_previous_to                     = '".mysql_real_escape_string( $_REQUEST['b_previous_to'] )."',
      previous_cancellations_etc        = '".mysql_real_escape_string( $_REQUEST['previous_cancellations_etc'] )."',
      previous_cancellations_detail     = '".mysql_real_escape_string( $_REQUEST['previous_cancellations_detail'] )."',

                      createdDate      = NOW(),
                      updatedDate      = NOW(),
                      createdByUserNum = '0',
                      updatedByUserNum = '0'")
    or die("MySQL Error Creating Record:<br/>\n". htmlspecialchars(mysql_error()) . "\n");
    $recordNum = mysql_insert_id();

    // display thanks message and clear form
    $alertsAndErrors = "Thanks, we've added that record!";
    $_REQUEST = array();
  }

}

  $csv = ''; 
  $csv .= implode(', ', array_map('_csvExport_escapeAsCSV', array_keys($_REQUEST))) . "\n"; 
  $csv .= implode(', ', array_map('_csvExport_escapeAsCSV', array_values($_REQUEST))) . "\n"; 
   
  sendMessage(array( 
    'from'    => "tim@forrest.id.au", 
    'to'      => "tim@toledoh.com.au", 
    'subject' => "Application Form", 
    'text'    => "Text message content", 
    'attachments' => array( 
      'form.csv'  => $csv 
    ) 
  ));
  
?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title></title>
<style type="text/css">
  body, td { font-family: arial }
</style>
</head>
<body>

<form method="post" action="">
<input type="hidden" name="submit" value="1" />

<h1>Sample Record Add Form</h1>

<?php if (@$alertsAndErrors): ?>
  <div style="color: red; font-weight: bold; font-size: 16px; font-family: arial;"><br/>
    <?php echo $alertsAndErrors; ?><br/><br/>
  </div>
<?php endif ?>


company<input type="text" name="company" value="<?php echo htmlspecialchars(@$_REQUEST['company']) ?>" size="30" /><br />
abn<input type="text" name="abn" value="<?php echo htmlspecialchars(@$_REQUEST['abn']) ?>" size="30" /><br />
established<input type="text" name="established" value="<?php echo htmlspecialchars(@$_REQUEST['established']) ?>" size="30" /><br />
company_type<input type="text" name="company_type" value="<?php echo htmlspecialchars(@$_REQUEST['company_type']) ?>" size="30" /><br />
if_other<input type="text" name="if_other" value="<?php echo htmlspecialchars(@$_REQUEST['if_other']) ?>" size="30" /><br />
email<input type="text" name="email" value="<?php echo htmlspecialchars(@$_REQUEST['email']) ?>" size="30" /><br />
telephone<input type="text" name="telephone" value="<?php echo htmlspecialchars(@$_REQUEST['telephone']) ?>" size="30" /><br />
fax<input type="text" name="fax" value="<?php echo htmlspecialchars(@$_REQUEST['fax']) ?>" size="30" /><br />
mobile<input type="text" name="mobile" value="<?php echo htmlspecialchars(@$_REQUEST['mobile']) ?>" size="30" /><br />
period_from<input type="text" name="period_from" value="<?php echo htmlspecialchars(@$_REQUEST['period_from']) ?>" size="30" /><br />
period_to<input type="text" name="period_to" value="<?php echo htmlspecialchars(@$_REQUEST['period_to']) ?>" size="30" /><br />
public_liability<input type="text" name="public_liability" value="<?php echo htmlspecialchars(@$_REQUEST['public_liability']) ?>" size="30" /><br />
product<input type="text" name="product" value="<?php echo htmlspecialchars(@$_REQUEST['product']) ?>" size="30" /><br />
professional<input type="text" name="professional" value="<?php echo htmlspecialchars(@$_REQUEST['professional']) ?>" size="30" /><br />
description<input type="text" name="description" value="<?php echo htmlspecialchars(@$_REQUEST['description']) ?>" size="30" /><br />
powerline_clearing<input type="text" name="powerline_clearing" value="<?php echo htmlspecialchars(@$_REQUEST['powerline_clearing']) ?>" size="30" /><br />
powerline_clearing_yes<input type="text" name="powerline_clearing_yes" value="<?php echo htmlspecialchars(@$_REQUEST['powerline_clearing_yes']) ?>" size="30" /><br />
no_type_unregistered_vehicles<input type="text" name="no_type_unregistered_vehicles" value="<?php echo htmlspecialchars(@$_REQUEST['no_type_unregistered_vehicles']) ?>" size="30" /><br />
lifting_equipment<input type="text" name="lifting_equipment" value="<?php echo htmlspecialchars(@$_REQUEST['lifting_equipment']) ?>" size="30" /><br />
actual<input type="text" name="actual" value="<?php echo htmlspecialchars(@$_REQUEST['actual']) ?>" size="30" /><br />
estimate<input type="text" name="estimate" value="<?php echo htmlspecialchars(@$_REQUEST['estimate']) ?>" size="30" /><br />
years_in_business<input type="text" name="years_in_business" value="<?php echo htmlspecialchars(@$_REQUEST['years_in_business']) ?>" size="30" /><br />
no_employees<input type="text" name="no_employees" value="<?php echo htmlspecialchars(@$_REQUEST['no_employees']) ?>" size="30" /><br />
estimated_total_annual_wages<input type="text" name="estimated_total_annual_wages" value="<?php echo htmlspecialchars(@$_REQUEST['estimated_total_annual_wages']) ?>" size="30" /><br />
sub_contractors<input type="text" name="sub_contractors" value="<?php echo htmlspecialchars(@$_REQUEST['sub_contractors']) ?>" size="30" /><br />
subcontactor_wages<input type="text" name="subcontactor_wages" value="<?php echo htmlspecialchars(@$_REQUEST['subcontactor_wages']) ?>" size="30" /><br />
previous_experience<input type="text" name="previous_experience" value="<?php echo htmlspecialchars(@$_REQUEST['previous_experience']) ?>" size="30" /><br />
additional_services<input type="text" name="additional_services" value="<?php echo htmlspecialchars(@$_REQUEST['additional_services']) ?>" size="30" /><br />
additional_services_details<input type="text" name="additional_services_details" value="<?php echo htmlspecialchars(@$_REQUEST['additional_services_details']) ?>" size="30" /><br />
accepted_liability<input type="text" name="accepted_liability" value="<?php echo htmlspecialchars(@$_REQUEST['accepted_liability']) ?>" size="30" /><br />
given_away_rights<input type="text" name="given_away_rights" value="<?php echo htmlspecialchars(@$_REQUEST['given_away_rights']) ?>" size="30" /><br />
claims_against<input type="text" name="claims_against" value="<?php echo htmlspecialchars(@$_REQUEST['claims_against']) ?>" size="30" /><br />
a_loss_date<input type="text" name="a_loss_date" value="<?php echo htmlspecialchars(@$_REQUEST['a_loss_date']) ?>" size="30" /><br />
a_loss_description<input type="text" name="a_loss_description" value="<?php echo htmlspecialchars(@$_REQUEST['a_loss_description']) ?>" size="30" /><br />
a_loss_paid<input type="text" name="a_loss_paid" value="<?php echo htmlspecialchars(@$_REQUEST['a_loss_paid']) ?>" size="30" /><br />
a_loss_reserve<input type="text" name="a_loss_reserve" value="<?php echo htmlspecialchars(@$_REQUEST['a_loss_reserve']) ?>" size="30" /><br />
b_loss_date<input type="text" name="b_loss_date" value="<?php echo htmlspecialchars(@$_REQUEST['b_loss_date']) ?>" size="30" /><br />
b_loss_description<input type="text" name="b_loss_description" value="<?php echo htmlspecialchars(@$_REQUEST['b_loss_description']) ?>" size="30" /><br />
b_loss_paid<input type="text" name="b_loss_paid" value="<?php echo htmlspecialchars(@$_REQUEST['b_loss_paid']) ?>" size="30" /><br />
b_loss_reserve<input type="text" name="b_loss_reserve" value="<?php echo htmlspecialchars(@$_REQUEST['b_loss_reserve']) ?>" size="30" /><br />
c_loss_date<input type="text" name="c_loss_date" value="<?php echo htmlspecialchars(@$_REQUEST['c_loss_date']) ?>" size="30" /><br />
c_loss_description<input type="text" name="c_loss_description" value="<?php echo htmlspecialchars(@$_REQUEST['c_loss_description']) ?>" size="30" /><br />
c_loss_paid<input type="text" name="c_loss_paid" value="<?php echo htmlspecialchars(@$_REQUEST['c_loss_paid']) ?>" size="30" /><br />
c_loss_reserve<input type="text" name="c_loss_reserve" value="<?php echo htmlspecialchars(@$_REQUEST['c_loss_reserve']) ?>" size="30" /><br />
addition_claims_against<input type="text" name="addition_claims_against" value="<?php echo htmlspecialchars(@$_REQUEST['addition_claims_against']) ?>" size="30" /><br />
additional_claims_detail<input type="text" name="additional_claims_detail" value="<?php echo htmlspecialchars(@$_REQUEST['additional_claims_detail']) ?>" size="30" /><br />
a_previous_insurer_name<input type="text" name="a_previous_insurer_name" value="<?php echo htmlspecialchars(@$_REQUEST['a_previous_insurer_name']) ?>" size="30" /><br />
a_previous_from<input type="text" name="a_previous_from" value="<?php echo htmlspecialchars(@$_REQUEST['a_previous_from']) ?>" size="30" /><br />
a_previous_to<input type="text" name="a_previous_to" value="<?php echo htmlspecialchars(@$_REQUEST['a_previous_to']) ?>" size="30" /><br />
b_previous_insurer_name<input type="text" name="b_previous_insurer_name" value="<?php echo htmlspecialchars(@$_REQUEST['b_previous_insurer_name']) ?>" size="30" /><br />
b_previous_from<input type="text" name="b_previous_from" value="<?php echo htmlspecialchars(@$_REQUEST['b_previous_from']) ?>" size="30" /><br />
b_previous_to<input type="text" name="b_previous_to" value="<?php echo htmlspecialchars(@$_REQUEST['b_previous_to']) ?>" size="30" /><br />
previous_cancellations_etc<input type="text" name="previous_cancellations_etc" value="<?php echo htmlspecialchars(@$_REQUEST['previous_cancellations_etc']) ?>" size="30" /><br />
previous_cancellations_detail<input type="text" name="previous_cancellations_detail" value="<?php echo htmlspecialchars(@$_REQUEST['previous_cancellations_detail']) ?>" size="30" /><br />
<br/><br/>


<input type="submit" name="add" value="Add Record &gt;&gt;" />

</form>
</body>
</html>
