%@ Language=VBScript %>
<%Option Explicit%>
<%Response.Buffer=True%>
<%
Const c_TaxRate=5.75
Dim numProductID, numOrderID, numOrderProductID
Dim numQuantity
Dim numSubtotal
Dim numTax
Dim numShipping
Dim numTotalShipping
numSubtotal=0
numShipping=0
numTotal=0
strSQL="SELECT OrderID " & _
"FROM Orders " & _
"WHERE SessionID=" & Session.SessionID
objRS.Open strSQL, objConn
If Not objRS.EOF Then
numOrderID=objRS("OrderID")
Else
' objConn.BeginTrans
strSQL="INSERT INTO Orders(SessionID) " & _
"VALUES (" & Session.SessionID & ")"
objConn.Execute(strSQL)
numOrderID=GetMaxID("Orders", "OrderID")
' objConn.CommitTrans
End If
objRS.Close
numProductID=Request.QueryString("id")
If numProductID<>"" And IsNumeric(numProductID) Then
strSQL="SELECT * " & _
"FROM Product " & _
"WHERE ProductID=" & numProductID
objRS.Open strSQL, objConn
If Not objRS.EOF Then
strSQL="SELECT * " & _
"FROM OrderProduct " & _
"WHERE OrderID=" & numOrderID & _
" AND ProductID=" & numProductID
objRS1.Open strSQL, objConn
If Not objRS1.EOF Then
strSQL="UPDATE OrderProduct " & _
"SET Quantity=" & objRS1("Quantity")+1 & " " & _
"WHERE OrderProductID=" & objRS1("OrderProductID")
objConn.Execute(strSQL)
Else
strSQL="INSERT INTO OrderProduct (OrderID, ProductID, Quantity) " & _
"VALUES (" & numOrderID & ", " & numProductID & ", 1)"
objConn.Execute(strSQL)
End If
End If
objRS.Close
End If
numOrderProductID=Request("Parameter")
Select Case Request("Action")
Case "Delete"
strSQL="DELETE OrderProduct " & _
"WHERE OrderProductID=" & numOrderProductID
objConn.Execute(strSQL)
Case "Update"
strSQL="SELECT * " & _
"FROM OrderProduct " & _
"WHERE OrderID=" & numOrderID
objRS.Open strSQL, objConn
Do While Not objRS.EOF
numQuantity=Request("Quantity" & objRS("OrderProductID"))
If numQuantity<>"" And IsNumeric(numQuantity) Then
If CInt(numQuantity)=0 Then
strSQL="DELETE OrderProduct " & _
"WHERE OrderProductID=" & objRS("OrderQuantity")
objConn.Execute(strSQL)
Else
strSQL="UPDATE OrderProduct " & _
"SET Quantity=" & numQuantity & " " & _
"WHERE OrderProductID=" & objRS("OrderProductID")
objConn.Execute(strSQL)
End If
End If
objRS.MoveNext
Loop
objRS.Close
Case "CheckOut"
' Response.Redirect "http://projects.metrostarsystems.com:8080/securemss/DMO/CreditCard.asp?sid=" & Session.SessionID
' Response.Redirect "https://secure.metrostarsystems.com/DMO/CreditCard.asp?sid=" & Session.SessionID
'Response.Redirect "http://projects.metrostarsystems.com/dreaMerchant/www/book/CreditCard.asp?id=" & Session.SessionID
strSQL="SELECT * " & _
"FROM OrderCart " & _
"WHERE OrderID=" & numOrderID
objRS.Open strSQL, objConn
If objRS.EOF Then
Response.Redirect"../book/viewCart.asp"
Else
Response.Redirect "../book/CreditCard.asp?id=" & Session.SessionID
End If
End Select
%>
DreaMerchant.com
<%Disconnect%>