--- a/displayCategory.php +++ b/displayCategory.php @@ -1,14 +1,18 @@

".$_REQUEST['category']."

"; - $query = "SELECT CNID, description, value, agencyName, category, contractStart, supplierName - FROM `contractnotice` - WHERE childCN = 0 - AND category = '" . $_REQUEST['category'] . "' - ORDER BY value DESC"; - $result = mysql_query($query); + $query = 'SELECT "CNID", description, value, "agencyName", category, "contractStart", "supplierName" + FROM contractnotice + WHERE "childCN" is null + AND category = :category + ORDER BY value DESC'; +$query = $conn->prepare($query); +$query->bindParam(":category", $_REQUEST['category']); + $query->execute(); + databaseError($conn->errorInfo()); + echo " @@ -19,7 +23,7 @@ "; - while ($row = mysql_fetch_array($result, MYSQL_BOTH)) { + foreach ($query->fetchAll() as $row) { setlocale(LC_MONETARY, 'en_US'); $value = number_format(doubleval($row['value']) , 2); echo (" @@ -31,30 +35,30 @@ "); } echo "
Contract Notice NumberSupplier
"; - mysql_free_result($result); } else { /* split by main categories */ include_header("Categories"); -$query = "SELECT sum(value), category -FROM `contractnotice` -WHERE childCN = 0 -GROUP BY category ORDER BY sum(value) DESC "; -$result = mysql_query($query); +$query = 'SELECT sum(value), category +FROM contractnotice +WHERE "childCN" is null +GROUP BY category ORDER BY sum(value) DESC '; +$query = $conn->prepare($query); + $query->execute(); + databaseError($conn->errorInfo()); echo ""; -while ($row = mysql_fetch_array($result, MYSQL_BOTH)) { + foreach ($query->fetchAll() as $row) { setlocale(LC_MONETARY, 'en_US'); $value = number_format(doubleval($row[0]) , 2); echo (""); } echo "
Category Total Contracts Value
{$row[1]}\$$value
"; -mysql_free_result($result); } include_footer(); ?>