[TEP-COMMIT] [CVS catalog] use the new database class

hpdl-OfajU3CKLf1/[email protected] 23 Feb 2005 15:28:32 -0000
Newsgroups gmane.comp.web.oscommerce.cvs
Message-ID <[email protected]>
<html>
<head>
<style><!--
  body {background-color:#ffffff;}
  .file {border:1px solid #eeeeee;margin-top:1em;margin-bottom:1em;}
  .pathname {font-family:monospace; float:right;}
  .fileheader {margin-bottom:.5em;}
  .diff {margin:0;}
  .tasklist {padding:4px;border:1px dashed #000000;margin-top:1em;}
  .tasklist ul {margin-top:0;margin-bottom:0;}
  tr.alt {background-color:#eeeeee}
  #added {background-color:#ddffdd;}
  #addedchars {background-color:#99ff99;font-weight:bolder;}
  tr.alt #added {background-color:#ccf7cc;}
  #removed {background-color:#ffdddd;}
  #removedchars {background-color:#ff9999;font-weight:bolder;}
  tr.alt #removed {background-color:#f7cccc;}
  #info {color:#888888;}
  #context {background-color:#eeeeee;}
  td {padding-left:.3em;padding-right:.3em;}
  tr.head {border-bottom-width:1px;border-bottom-style:solid;}
  tr.head td {padding:0;padding-top:.2em;}
  .task {background-color:#ffff00;}
  .comment {padding:4px;border:1px dashed #000000;background-color:#ffffdd}
  .error {color:red;}
  hr {border-width:0px;height:2px;background:black;}
--></style>
</head>
<body>
<table cellspacing="0" cellpadding="0" border="0" rules="cols">
<tr class="head"><td colspan="4">Commit in <b><tt>catalog/catalog</tt></b><span id="info"> on MAIN</span></td></tr>
<tr><td><tt><a href="#file1">checkout_payment.php</a></tt></td><td align="right" id="added">+7</td><td align="right" id="removed">-4</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment.php?rev=1.119&amp;content-type=text/vnd.viewcvs-markup">1.119</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment.php.diff?r1=1.119&amp;r2=1.120">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment.php?rev=1.120&amp;content-type=text/vnd.viewcvs-markup">1.120</a></td></tr>
<tr class="alt"><td><tt><a href="#file2">checkout_payment_address.php</a></tt></td><td align="right" id="added">+18</td><td align="right" id="removed">-11</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment_address.php?rev=1.17&amp;content-type=text/vnd.viewcvs-markup">1.17</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment_address.php.diff?r1=1.17&amp;r2=1.18">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment_address.php?rev=1.18&amp;content-type=text/vnd.viewcvs-markup">1.18</a></td></tr>
<tr><td><tt><a href="#file3">checkout_process.php</a></tt></td><td align="right" id="added">+159</td><td align="right" id="removed">-124</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_process.php?rev=1.131&amp;content-type=text/vnd.viewcvs-markup">1.131</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_process.php.diff?r1=1.131&amp;r2=1.132">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_process.php?rev=1.132&amp;content-type=text/vnd.viewcvs-markup">1.132</a></td></tr>
<tr class="alt"><td><tt><a href="#file4">checkout_shipping.php</a></tt></td><td align="right" id="added">+7</td><td align="right" id="removed">-4</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.23&amp;content-type=text/vnd.viewcvs-markup">1.23</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php.diff?r1=1.23&amp;r2=1.24">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.24&amp;content-type=text/vnd.viewcvs-markup">1.24</a></td></tr>
<tr><td><tt><a href="#file5">checkout_shipping_address.php</a></tt></td><td align="right" id="added">+18</td><td align="right" id="removed">-11</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping_address.php?rev=1.19&amp;content-type=text/vnd.viewcvs-markup">1.19</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping_address.php.diff?r1=1.19&amp;r2=1.20">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping_address.php?rev=1.20&amp;content-type=text/vnd.viewcvs-markup">1.20</a></td></tr>
<tr class="alt"><td><tt><a href="#file6">checkout_success.php</a></tt></td><td align="right" id="added">+19</td><td align="right" id="removed">-11</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_success.php?rev=1.51&amp;content-type=text/vnd.viewcvs-markup">1.51</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_success.php.diff?r1=1.51&amp;r2=1.52">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_success.php?rev=1.52&amp;content-type=text/vnd.viewcvs-markup">1.52</a></td></tr>
<tr><td></td><td align="right" id="added">+228</td><td align="right" id="removed">-165</td><td></td></tr>
</table>
<small id="info">6 modified files</small><br />
<pre class="comment">
use the new database class
</pre>
<hr /><a name="file1" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_payment.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment.php?rev=1.119&amp;content-type=text/vnd.viewcvs-markup">1.119</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment.php.diff?r1=1.119&amp;r2=1.120">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment.php?rev=1.120&amp;content-type=text/vnd.viewcvs-markup">1.120</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.119 -r1.120
--- checkout_payment.php	2004/07/22 21:45:38	1.119
+++ checkout_payment.php	2005/02/23 15:28:26	1.120
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -57,10 +57,13 @@
</small></pre><pre class="diff" id="context">     $osC_Session-&gt;set('billto', $osC_Customer-&gt;default_address_id);
   } else {
 // verify the selected billing address
</pre><pre class="diff" id="removed">-    $check_address_query = tep_db_query("select count(*) as total from " . TABLE_ADDRESS_BOOK . " where customers_id = '" . (int)$osC_Customer-&gt;id . "' and address_book_id = '" . (int)$osC_Session-&gt;value('billto') . "'");
-    $check_address = tep_db_fetch_array($check_address_query);
</pre><pre class="diff" id="added">+    $Qcheck = $osC_Database-&gt;query('select count(*) as total from :table_address_book where customers_id = :customers_id and address_book_id = :address_book_id');
+    $Qcheck-&gt;bindTable(':table_address_book', TABLE_ADDRESS_BOOK);
+    $Qcheck-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+    $Qcheck-&gt;bindInt(':address_book_id', $osC_Session-&gt;value('billto'));
+    $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    if ($check_address['total'] != '1') {
</pre><pre class="diff" id="added">+    if ($Qcheck-&gt;valueInt('total') != 1) {
</pre><pre class="diff" id="context">       $osC_Session-&gt;set('billto', $osC_Customer-&gt;default_address_id);
 
       $osC_Session-&gt;remove('payment');
</pre></div>
<hr /><a name="file2" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_payment_address.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment_address.php?rev=1.17&amp;content-type=text/vnd.viewcvs-markup">1.17</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment_address.php.diff?r1=1.17&amp;r2=1.18">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_payment_address.php?rev=1.18&amp;content-type=text/vnd.viewcvs-markup">1.18</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.17 -r1.18
--- checkout_payment_address.php	2004/07/22 21:46:24	1.17
+++ checkout_payment_address.php	2005/02/23 15:28:26	1.18
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -182,10 +182,13 @@
</small></pre><pre class="diff" id="context"> 
       $osC_Session-&gt;set('billto', $_POST['address']);
 
</pre><pre class="diff" id="removed">-      $check_address_query = tep_db_query("select count(*) as total from " . TABLE_ADDRESS_BOOK . " where customers_id = '" . (int)$osC_Customer-&gt;id . "' and address_book_id = '" . (int)$osC_Session-&gt;value('billto') . "'");
-      $check_address = tep_db_fetch_array($check_address_query);
</pre><pre class="diff" id="added">+      $Qcheck = $osC_Database-&gt;query('select count(*) as total from :table_address_book where customers_id = :customers_id and address_book_id = :address_book_id');
+      $Qcheck-&gt;bindTable(':table_address_book', TABLE_ADDRESS_BOOK);
+      $Qcheck-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+      $Qcheck-&gt;bindInt(':address_book_id', $osC_Session-&gt;value('billto'));
+      $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-      if ($check_address['total'] == '1') {
</pre><pre class="diff" id="added">+      if ($Qcheck-&gt;valueInt('total') == 1) {
</pre><pre class="diff" id="context">         if ($reset_payment == true) {
           $osC_Session-&gt;remove('payment');
         }
</pre><pre class="diff"><small id="info">@@ -363,23 +366,27 @@
</small></pre><pre class="diff" id="context"> &lt;?php
       $radio_buttons = 0;
 
</pre><pre class="diff" id="removed">-      $addresses_query = tep_db_query("select address_book_id, entry_firstname as firstname, entry_lastname as lastname, entry_company as company, entry_street_address as street_address, entry_suburb as suburb, entry_city as city, entry_postcode as postcode, entry_state as state, entry_zone_id as zone_id, entry_country_id as country_id from " . TABLE_ADDRESS_BOOK . " where customers_id = '" . (int)$osC_Customer-&gt;id . "'");
-      while ($addresses = tep_db_fetch_array($addresses_query)) {
-        $format_id = tep_get_address_format_id($addresses['country_id']);
</pre><pre class="diff" id="added">+      $Qaddresses = $osC_Database-&gt;query('select address_book_id, entry_firstname as firstname, entry_lastname as lastname, entry_company as company, entry_street_address as street_address, entry_suburb as suburb, entry_city as city, entry_postcode as postcode, entry_state as state, entry_zone_id as zone_id, entry_country_id as country_id from :table_address_book where customers_id = :customers_id');
+      $Qaddresses-&gt;bindTable(':table_address_book', TABLE_ADDRESS_BOOK);
+      $Qaddresses-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+      $Qaddresses-&gt;execute();
+
+      while ($Qaddresses-&gt;next()) {
+        $format_id = tep_get_address_format_id($Qaddresses-&gt;valueInt('country_id'));
</pre><pre class="diff" id="context"> ?&gt;
               &lt;tr&gt;
                 &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                 &lt;td colspan="2"&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-       if ($addresses['address_book_id'] == $osC_Session-&gt;value('billto')) {
</pre><pre class="diff" id="added">+       if ($Qaddresses-&gt;valueInt('address_book_id') == $osC_Session-&gt;value('billto')) {
</pre><pre class="diff" id="context">           echo '                  &lt;tr id="defaultSelected" class="moduleRowSelected" onmouseover="rowOverEffect(this)" onmouseout="rowOutEffect(this)" onclick="selectRowEffect(this, ' . $radio_buttons . ')"&gt;' . "\n";
         } else {
           echo '                  &lt;tr class="moduleRow" onmouseover="rowOverEffect(this)" onmouseout="rowOutEffect(this)" onclick="selectRowEffect(this, ' . $radio_buttons . ')"&gt;' . "\n";
         }
 ?&gt;
                     &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="main" colspan="2"&gt;&lt;b&gt;&lt;?php echo $addresses['firstname'] . ' ' . $addresses['lastname']; ?&gt;&lt;/b&gt;&lt;/td&gt;
-                    &lt;td class="main" align="right"&gt;&lt;?php echo osc_draw_radio_field('address', $addresses['address_book_id'], $osC_Session-&gt;value('billto')); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="main" colspan="2"&gt;&lt;b&gt;&lt;?php echo $Qaddresses-&gt;valueProtected('firstname') . ' ' . $Qaddresses-&gt;valueProtected('lastname'); ?&gt;&lt;/b&gt;&lt;/td&gt;
+                    &lt;td class="main" align="right"&gt;&lt;?php echo osc_draw_radio_field('address', $Qaddresses-&gt;valueInt('address_book_id'), $osC_Session-&gt;value('billto')); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                     &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                   &lt;/tr&gt;
                   &lt;tr&gt;
</pre><pre class="diff"><small id="info">@@ -387,7 +394,7 @@
</small></pre><pre class="diff" id="context">                     &lt;td colspan="3"&gt;&lt;table border="0" cellspacing="0" cellpadding="2"&gt;
                       &lt;tr&gt;
                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                        &lt;td class="main"&gt;&lt;?php echo tep_address_format($format_id, $<span id="removedchars">addresses</span>, true, ' ', ', '); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                        &lt;td class="main"&gt;&lt;?php echo tep_address_format($format_id, $<span id="addedchars">Qaddresses-&gt;toArray()</span>, true, ' ', ', '); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                       &lt;/tr&gt;
                     &lt;/table&gt;&lt;/td&gt;
</pre></div>
<hr /><a name="file3" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_process.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_process.php?rev=1.131&amp;content-type=text/vnd.viewcvs-markup">1.131</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_process.php.diff?r1=1.131&amp;r2=1.132">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_process.php?rev=1.132&amp;content-type=text/vnd.viewcvs-markup">1.132</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.131 -r1.132
--- checkout_process.php	2004/04/03 10:27:42	1.131
+++ checkout_process.php	2005/02/23 15:28:27	1.132
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -53,71 +53,72 @@
</small></pre><pre class="diff" id="context"> 
   $order_totals = $order_total_modules-&gt;process();
 
</pre><pre class="diff" id="removed">-  $sql_data_array = array('customers_id' =&gt; $osC_Customer-&gt;id,
-                          'customers_name' =&gt; $order-&gt;customer['firstname'] . ' ' . $order-&gt;customer['lastname'],
-                          'customers_company' =&gt; $order-&gt;customer['company'],
-                          'customers_street_address' =&gt; $order-&gt;customer['street_address'],
-                          'customers_suburb' =&gt; $order-&gt;customer['suburb'],
-                          'customers_city' =&gt; $order-&gt;customer['city'],
-                          'customers_postcode' =&gt; $order-&gt;customer['postcode'],
-                          'customers_state' =&gt; $order-&gt;customer['state'],
-                          'customers_country' =&gt; $order-&gt;customer['country']['title'],
-                          'customers_telephone' =&gt; $order-&gt;customer['telephone'],
-                          'customers_email_address' =&gt; $order-&gt;customer['email_address'],
-                          'customers_address_format_id' =&gt; $order-&gt;customer['format_id'],
-                          'customers_ip_address' =&gt; tep_get_ip_address(),
-                          'delivery_name' =&gt; $order-&gt;delivery['firstname'] . ' ' . $order-&gt;delivery['lastname'],
-                          'delivery_company' =&gt; $order-&gt;delivery['company'],
-                          'delivery_street_address' =&gt; $order-&gt;delivery['street_address'],
-                          'delivery_suburb' =&gt; $order-&gt;delivery['suburb'],
-                          'delivery_city' =&gt; $order-&gt;delivery['city'],
-                          'delivery_postcode' =&gt; $order-&gt;delivery['postcode'],
-                          'delivery_state' =&gt; $order-&gt;delivery['state'],
-                          'delivery_country' =&gt; $order-&gt;delivery['country']['title'],
-                          'delivery_address_format_id' =&gt; $order-&gt;delivery['format_id'],
-                          'billing_name' =&gt; $order-&gt;billing['firstname'] . ' ' . $order-&gt;billing['lastname'],
-                          'billing_company' =&gt; $order-&gt;billing['company'],
-                          'billing_street_address' =&gt; $order-&gt;billing['street_address'],
-                          'billing_suburb' =&gt; $order-&gt;billing['suburb'],
-                          'billing_city' =&gt; $order-&gt;billing['city'],
-                          'billing_postcode' =&gt; $order-&gt;billing['postcode'],
-                          'billing_state' =&gt; $order-&gt;billing['state'],
-                          'billing_country' =&gt; $order-&gt;billing['country']['title'],
-                          'billing_address_format_id' =&gt; $order-&gt;billing['format_id'],
-                          'payment_method' =&gt; $order-&gt;info['payment_method'],
-                          'cc_type' =&gt; $order-&gt;info['cc_type'],
-                          'cc_owner' =&gt; $order-&gt;info['cc_owner'],
-                          'cc_number' =&gt; $order-&gt;info['cc_number'],
-                          'cc_expires' =&gt; $order-&gt;info['cc_expires'],
-                          'date_purchased' =&gt; 'now()',
-                          'orders_status' =&gt; $order-&gt;info['order_status'],
-                          'currency' =&gt; $order-&gt;info['currency'],
-                          'currency_value' =&gt; $order-&gt;info['currency_value']);
</pre><pre class="diff" id="added">+  $Qorder = $osC_Database-&gt;query('insert into :table_orders (customers_id, customers_name, customers_company, customers_street_address, customers_suburb, customers_city, customers_postcode, customers_state, customers_country, customers_telephone, customers_email_address, customers_address_format_id, customers_ip_address, delivery_name, delivery_company, delivery_street_address, delivery_suburb, delivery_city, delivery_postcode, delivery_state, delivery_country, delivery_address_format_id, billing_name, billing_company, billing_street_address, billing_suburb, billing_city, billing_postcode, billing_state, billing_country, billing_address_format_id, payment_method, cc_type, cc_owner, cc_number, cc_expires, date_purchased, orders_status, currency, currency_value) values (:customers_id, :customers_name, :customers_company, :customers_street_address, :cu
 stomers_suburb, :customers_city, :customers_postcode, :customers_state, :customers_country
 , :customers_telephone, :customers_email_address,<strong class="error">[...]</strong>
+  $Qorder-&gt;bindTable(':table_orders', TABLE_ORDERS);
+  $Qorder-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+  $Qorder-&gt;bindValue(':customers_name', $order-&gt;customer['firstname'] . ' ' . $order-&gt;customer['lastname']);
+  $Qorder-&gt;bindValue(':customers_company', $order-&gt;customer['company']);
+  $Qorder-&gt;bindValue(':customers_street_address', $order-&gt;customer['street_address']);
+  $Qorder-&gt;bindValue(':customers_suburb', $order-&gt;customer['suburb']);
+  $Qorder-&gt;bindValue(':customers_city', $order-&gt;customer['city']);
+  $Qorder-&gt;bindValue(':customers_postcode', $order-&gt;customer['postcode']);
+  $Qorder-&gt;bindValue(':customers_state', $order-&gt;customer['state']);
+  $Qorder-&gt;bindValue(':customers_country', $order-&gt;customer['country']['title']);
+  $Qorder-&gt;bindValue(':customers_telephone', $order-&gt;customer['telephone']);
+  $Qorder-&gt;bindValue(':customers_email_address', $order-&gt;customer['email_address']);
+  $Qorder-&gt;bindInt(':customers_address_format_id', $order-&gt;customer['format_id']);
+  $Qorder-&gt;bindValue(':customers_ip_address', tep_get_ip_address());
+  $Qorder-&gt;bindValue(':delivery_name', $order-&gt;delivery['firstname'] . ' ' . $order-&gt;delivery['lastname']);
+  $Qorder-&gt;bindValue(':delivery_company', $order-&gt;delivery['company']);
+  $Qorder-&gt;bindValue(':delivery_street_address', $order-&gt;delivery['street_address']);
+  $Qorder-&gt;bindValue(':delivery_suburb', $order-&gt;delivery['suburb']);
+  $Qorder-&gt;bindValue(':delivery_city', $order-&gt;delivery['city']);
+  $Qorder-&gt;bindValue(':delivery_postcode', $order-&gt;delivery['postcode']);
+  $Qorder-&gt;bindValue(':delivery_state', $order-&gt;delivery['state']);
+  $Qorder-&gt;bindValue(':delivery_country', $order-&gt;delivery['country']['title']);
+  $Qorder-&gt;bindInt(':delivery_address_format_id', $order-&gt;delivery['format_id']);
+  $Qorder-&gt;bindValue(':billing_name', $order-&gt;billing['firstname'] . ' ' . $order-&gt;billing['lastname']);
+  $Qorder-&gt;bindValue(':billing_company', $order-&gt;billing['company']);
+  $Qorder-&gt;bindValue(':billing_street_address', $order-&gt;billing['street_address']);
+  $Qorder-&gt;bindValue(':billing_suburb', $order-&gt;billing['suburb']);
+  $Qorder-&gt;bindValue(':billing_city', $order-&gt;billing['city']);
+  $Qorder-&gt;bindValue(':billing_postcode', $order-&gt;billing['postcode']);
+  $Qorder-&gt;bindValue(':billing_state', $order-&gt;billing['state']);
+  $Qorder-&gt;bindValue(':billing_country', $order-&gt;billing['country']['title']);
+  $Qorder-&gt;bindInt(':billing_address_format_id', $order-&gt;billing['format_id']);
+  $Qorder-&gt;bindValue(':payment_method', $order-&gt;info['payment_method']);
+  $Qorder-&gt;bindValue(':cc_type', $order-&gt;info['cc_type']);
+  $Qorder-&gt;bindValue(':cc_owner', $order-&gt;info['cc_owner']);
+  $Qorder-&gt;bindValue(':cc_number', $order-&gt;info['cc_number']);
+  $Qorder-&gt;bindValue(':cc_expires', $order-&gt;info['cc_expires']);
+  $Qorder-&gt;bindRaw(':date_purchased', 'now()');
+  $Qorder-&gt;bindValue(':orders_status', $order-&gt;info['order_status']);
+  $Qorder-&gt;bindValue(':currency', $order-&gt;info['currency']);
+  $Qorder-&gt;bindValue(':currency_value', $order-&gt;info['currency_value']);
+  $Qorder-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  tep_db_perform(TABLE_ORDERS, $sql_data_array);
</pre><pre class="diff" id="added">+  $insert_id = $osC_Database-&gt;nextID();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  $insert_id = tep_db_insert_id();
-
</pre><pre class="diff" id="context">   for ($i=0, $n=sizeof($order_totals); $i&lt;$n; $i++) {
</pre><pre class="diff" id="removed">-    $sql_data_array = array('orders_id' =&gt; $insert_id,
-                            'title' =&gt; $order_totals[$i]['title'],
-                            'text' =&gt; $order_totals[$i]['text'],
-                            'value' =&gt; $order_totals[$i]['value'],
-                            'class' =&gt; $order_totals[$i]['code'],
-                            'sort_order' =&gt; $order_totals[$i]['sort_order']);
-
-    tep_db_perform(TABLE_ORDERS_TOTAL, $sql_data_array);
</pre><pre class="diff" id="added">+    $Qtotals = $osC_Database-&gt;query('insert into :table_orders_total (orders_id, title, text, value, class, sort_order) values (:orders_id, :title, :text, :value, :class, :sort_order)');
+    $Qtotals-&gt;bindTable(':table_orders_total', TABLE_ORDERS_TOTAL);
+    $Qtotals-&gt;bindInt(':orders_id', $insert_id);
+    $Qtotals-&gt;bindValue(':title', $order_totals[$i]['title']);
+    $Qtotals-&gt;bindValue(':text', $order_totals[$i]['text']);
+    $Qtotals-&gt;bindValue(':value', $order_totals[$i]['value']);
+    $Qtotals-&gt;bindValue(':class', $order_totals[$i]['code']);
+    $Qtotals-&gt;bindInt(':sort_order', $order_totals[$i]['sort_order']);
+    $Qtotals-&gt;execute();
</pre><pre class="diff" id="context">   }
</pre><pre class="diff" id="removed">-
-  $customer_notification = (SEND_EMAILS == 'true') ? '1' : '0';
-
-  $sql_data_array = array('orders_id' =&gt; $insert_id,
-                          'orders_status_id' =&gt; $order-&gt;info['order_status'],
-                          'date_added' =&gt; 'now()',
-                          'customer_notified' =&gt; $customer_notification,
-                          'comments' =&gt; $order-&gt;info['comments']);
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  tep_db_perform(TABLE_ORDERS_STATUS_HISTORY, $sql_data_array);
</pre><pre class="diff" id="added">+  $Qstatus = $osC_Database-&gt;query('insert into :table_orders_status_history (orders_id, orders_status_id, date_added, customer_notified, comments) values (:orders_id, :orders_status_id, :date_added, :customer_notified, :comments)');
+  $Qstatus-&gt;bindTable(':table_orders_status_history', TABLE_ORDERS_STATUS_HISTORY);
+  $Qstatus-&gt;bindInt(':orders_id', $insert_id);
+  $Qstatus-&gt;bindInt(':orders_status_id', $order-&gt;info['order_status']);
+  $Qstatus-&gt;bindRaw(':date_added', 'now()');
+  $Qstatus-&gt;bindInt(':customer_notified', (SEND_EMAILS == 'true') ? '1' : '0');
+  $Qstatus-&gt;bindValue(':comments', $order-&gt;info['comments']);
+  $Qstatus-&gt;execute();
</pre><pre class="diff" id="context"> 
 // initialized for the email confirmation
   $products_ordered = '';
</pre><pre class="diff"><small id="info">@@ -130,93 +131,127 @@
</small></pre><pre class="diff" id="context"> // Stock Update - Joao Correia
     if (STOCK_LIMITED == 'true') {
       if (DOWNLOAD_ENABLED == 'true') {
</pre><pre class="diff" id="removed">-        $stock_query_raw = "SELECT products_quantity, pad.products_attributes_filename
-                            FROM " . TABLE_PRODUCTS . " p
-                            LEFT JOIN " . TABLE_PRODUCTS_ATTRIBUTES . " pa
-                             ON p.products_id=pa.products_id
-                            LEFT JOIN " . TABLE_PRODUCTS_ATTRIBUTES_DOWNLOAD . " pad
-                             ON pa.products_attributes_id=pad.products_attributes_id
-                            WHERE p.products_id = '" . tep_get_prid($order-&gt;products[$i]['id']) . "'";
-// Will work with only one option for downloadable products
-// otherwise, we have to build the query dynamically with a loop
</pre><pre class="diff" id="added">+        $Qstock = $osC_Database-&gt;query('select products_quantity, pad.products_attributes_filename from :table_products p left join :table_products_attributes pa on (p.products_id = pa.products_id) left join :table_products_attributes_download pad on (pa.products_attributes_id = pad.products_attributes_id) where p.products_id = :products_id');
+        $Qstock-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+        $Qstock-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+        $Qstock-&gt;bindTable(':table_products_attributes_download', TABLE_PRODUCTS_ATTRIBUTES_DOWNLOAD);
+        $Qstock-&gt;bindInt(':products_id', tep_get_prid($order-&gt;products[$i]['id']));
+
+// Will work with only one option for downloadable products otherwise, we have to build the query dynamically with a loop
</pre><pre class="diff" id="context">         $products_attributes = $order-&gt;products[$i]['attributes'];
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">         if (is_array($products_attributes)) {
</pre><pre class="diff" id="removed">-          $stock_query_raw .= " AND pa.options_id = '" . $products_attributes[0]['option_id'] . "' AND pa.options_values_id = '" . $products_attributes[0]['value_id'] . "'";
</pre><pre class="diff" id="added">+          $Qstock-&gt;appendQuery('and pa.options_id = :options_id and pa.options_values_id = :options_values_id');
+          $Qstock-&gt;bindInt(':options_id', $products_attributes[0]['option_id']);
+          $Qstock-&gt;bindInt(':options_values_id', $products_attributes[0]['value_id']);
</pre><pre class="diff" id="context">         }
</pre><pre class="diff" id="removed">-        $stock_query = tep_db_query($stock_query_raw);
</pre><pre class="diff" id="context">       } else {
</pre><pre class="diff" id="removed">-        $stock_query = tep_db_query("select products_quantity from " . TABLE_PRODUCTS . " where products_id = '" . tep_get_prid($order-&gt;products[$i]['id']) . "'");
</pre><pre class="diff" id="added">+        $Qstock = $osC_Database-&gt;query('select products_quantity from :table_products where products_id = :products_id');
+        $Qstock-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+        $Qstock-&gt;bindInt(':products_id', tep_get_prid($order-&gt;products[$i]['id']));
</pre><pre class="diff" id="context">       }
</pre><pre class="diff" id="removed">-      if (tep_db_num_rows($stock_query) &gt; 0) {
-        $stock_values = tep_db_fetch_array($stock_query);
</pre><pre class="diff" id="added">+
+      $Qstock-&gt;execute();
+
+      if ($Qstock-&gt;numberOfRows() &gt; 0) {
+        $stock_left = $Qstock-&gt;valueInt('products_quantity');
+
</pre><pre class="diff" id="context"> // do not decrement quantities if products_attributes_filename exists
</pre><pre class="diff" id="removed">-        if ((DOWNLOAD_ENABLED != 'true') || (!$stock_values['products_attributes_filename'])) {
-          $stock_left = $stock_values['products_quantity'] - $order-&gt;products[$i]['qty'];
-        } else {
-          $stock_left = $stock_values['products_quantity'];
</pre><pre class="diff" id="added">+        if ((DOWNLOAD_ENABLED != 'true') || ((DOWNLOAD_ENABLED == 'true') &amp;&amp; (strlen($Qstock-&gt;value('products_attributes_filename')) &lt; 1))) {
+          $stock_left = $stock_left - $order-&gt;products[$i]['qty'];
+
+          $Qupdate = $osC_Database-&gt;query('update :table_products set products_quantity = :products_quantity where products_id = :products_id');
+          $Qupdate-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+          $Qupdate-&gt;bindInt(':products_quantity', $stock_left);
+          $Qupdate-&gt;bindInt(':products_id', tep_get_prid($order-&gt;products[$i]['id']));
+          $Qupdate-&gt;execute();
</pre><pre class="diff" id="context">         }
</pre><pre class="diff" id="removed">-        tep_db_query("update " . TABLE_PRODUCTS . " set products_quantity = '" . $stock_left . "' where products_id = '" . tep_get_prid($order-&gt;products[$i]['id']) . "'");
-        if ( ($stock_left &lt; 1) &amp;&amp; (STOCK_ALLOW_CHECKOUT == 'false') ) {
-          tep_db_query("update " . TABLE_PRODUCTS . " set products_status = '0' where products_id = '" . tep_get_prid($order-&gt;products[$i]['id']) . "'");
</pre><pre class="diff" id="added">+
+        if ((STOCK_ALLOW_CHECKOUT == 'false') &amp;&amp; ($stock_left &lt; 1)) {
+          $Qupdate = $osC_Database-&gt;query('update :table_products set products_status = :products_status where products_id = :products_id');
+          $Qupdate-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+          $Qupdate-&gt;bindInt(':products_status', 0);
+          $Qupdate-&gt;bindInt(':products_id', tep_get_prid($order-&gt;products[$i]['id']));
+          $Qupdate-&gt;execute();
</pre><pre class="diff" id="context">         }
       }
     }
 
 // Update products_ordered (for bestsellers list)
</pre><pre class="diff" id="removed">-    tep_db_query("update " . TABLE_PRODUCTS . " set products_ordered = products_ordered + " . sprintf('%d', $order-&gt;products[$i]['qty']) . " where products_id = '" . tep_get_prid($order-&gt;products[$i]['id']) . "'");
</pre><pre class="diff" id="added">+    $Qupdate = $osC_Database-&gt;query('update :table_products set products_ordered = products_ordered + :products_ordered where products_id = :products_id');
+    $Qupdate-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+    $Qupdate-&gt;bindInt(':products_ordered', $order-&gt;products[$i]['qty']);
+    $Qupdate-&gt;bindInt(':products_id', tep_get_prid($order-&gt;products[$i]['id']));
+    $Qupdate-&gt;execute();
+
+    $Qproducts = $osC_Database-&gt;query('insert into :table_orders_products (orders_id, products_id, products_model, products_name, products_price, final_price, products_tax, products_quantity) values (:orders_id, :products_id, :products_model, :products_name, :products_price, :final_price, :products_tax, :products_quantity)');
+    $Qproducts-&gt;bindTable(':table_orders_products', TABLE_ORDERS_PRODUCTS);
+    $Qproducts-&gt;bindInt(':orders_id', $insert_id);
+    $Qproducts-&gt;bindInt(':products_id', tep_get_prid($order-&gt;products[$i]['id']));
+    $Qproducts-&gt;bindValue(':products_model', $order-&gt;products[$i]['model']);
+    $Qproducts-&gt;bindValue(':products_name', $order-&gt;products[$i]['name']);
+    $Qproducts-&gt;bindValue(':products_price', $order-&gt;products[$i]['price']);
+    $Qproducts-&gt;bindValue(':final_price', $order-&gt;products[$i]['final_price']);
+    $Qproducts-&gt;bindValue(':products_tax', $order-&gt;products[$i]['tax']);
+    $Qproducts-&gt;bindInt(':products_quantity', $order-&gt;products[$i]['qty']);
+    $Qproducts-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    $sql_data_array = array('orders_id' =&gt; $insert_id,
-                            'products_id' =&gt; tep_get_prid($order-&gt;products[$i]['id']),
-                            'products_model' =&gt; $order-&gt;products[$i]['model'],
-                            'products_name' =&gt; $order-&gt;products[$i]['name'],
-                            'products_price' =&gt; $order-&gt;products[$i]['price'],
-                            'final_price' =&gt; $order-&gt;products[$i]['final_price'],
-                            'products_tax' =&gt; $order-&gt;products[$i]['tax'],
-                            'products_quantity' =&gt; $order-&gt;products[$i]['qty']);
-    tep_db_perform(TABLE_ORDERS_PRODUCTS, $sql_data_array);
-    $order_products_id = tep_db_insert_id();
</pre><pre class="diff" id="added">+    $order_products_id = $osC_Database-&gt;nextID();
</pre><pre class="diff" id="context"> 
 //------insert customer choosen option to order--------
     $attributes_exist = '0';
     $products_ordered_attributes = '';
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">     if (isset($order-&gt;products[$i]['attributes'])) {
       $attributes_exist = '1';
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">       for ($j=0, $n2=sizeof($order-&gt;products[$i]['attributes']); $j&lt;$n2; $j++) {
         if (DOWNLOAD_ENABLED == 'true') {
</pre><pre class="diff" id="removed">-          $attributes_query = "select popt.products_options_name, poval.products_options_values_name, pa.options_values_price, pa.price_prefix, pad.products_attributes_maxdays, pad.products_attributes_maxcount , pad.products_attributes_filename
-                               from " . TABLE_PRODUCTS_OPTIONS . " popt, " . TABLE_PRODUCTS_OPTIONS_VALUES . " poval, " . TABLE_PRODUCTS_ATTRIBUTES . " pa
-                               left join " . TABLE_PRODUCTS_ATTRIBUTES_DOWNLOAD . " pad
-                                on pa.products_attributes_id=pad.products_attributes_id
-                               where pa.products_id = '" . $order-&gt;products[$i]['id'] . "'
-                                and pa.options_id = '" . $order-&gt;products[$i]['attributes'][$j]['option_id'] . "'
-                                and pa.options_id = popt.products_options_id
-                                and pa.options_values_id = '" . $order-&gt;products[$i]['attributes'][$j]['value_id'] . "'
-                                and pa.options_values_id = poval.products_options_values_id
-                                and popt.language_id = '" . $osC_Session-&gt;value('languages_id') . "'
-                                and poval.language_id = '" . $osC_Session-&gt;value('languages_id') . "'";
-          $attributes = tep_db_query($attributes_query);
</pre><pre class="diff" id="added">+          $Qattributes = $osC_Database-&gt;query('select popt.products_options_name, poval.products_options_values_name, pa.options_values_price, pa.price_prefix, pad.products_attributes_maxdays, pad.products_attributes_maxcount, pad.products_attributes_filename from :table_products_options popt, :table_products_options_values poval, :table_products_attributes pa left join :table_products_attributes_download pad on (pa.products_attributes_id = pad.products_attributes_id) where pa.products_id = :products_id and pa.options_id = :options_id and pa.options_id = popt.products_options_id and pa.options_values_id = :options_values_id and pa.options_values_id = poval.products_options_values_id and popt.language_id = :popt_language_id and poval.language_id = :poval_language_id');
+          $Qattributes-&gt;bindTable(':table_products_options', TABLE_PRODUCTS_OPTIONS);
+          $Qattributes-&gt;bindTable(':table_products_options_values', TABLE_PRODUCTS_OPTIONS_VALUES);
+          $Qattributes-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+          $Qattributes-&gt;bindTable(':table_products_attributes_download', TABLE_PRODUCTS_ATTRIBUTES_DOWNLOAD);
+          $Qattributes-&gt;bindInt(':products_id', $order-&gt;products[$i]['id']);
+          $Qattributes-&gt;bindInt(':options_id', $order-&gt;products[$i]['attributes'][$j]['option_id']);
+          $Qattributes-&gt;bindInt(':options_values_id', $order-&gt;products[$i]['attributes'][$j]['value_id']);
+          $Qattributes-&gt;bindInt(':popt_language_id', $osC_Session-&gt;value('languages_id'));
+          $Qattributes-&gt;bindInt(':poval_language_id', $osC_Session-&gt;value('languages_id'));
</pre><pre class="diff" id="context">         } else {
</pre><pre class="diff" id="removed">-          $attributes = tep_db_query("select popt.products_options_name, poval.products_options_values_name, pa.options_values_price, pa.price_prefix from " . TABLE_PRODUCTS_OPTIONS . " popt, " . TABLE_PRODUCTS_OPTIONS_VALUES . " poval, " . TABLE_PRODUCTS_ATTRIBUTES . " pa where pa.products_id = '" . $order-&gt;products[$i]['id'] . "' and pa.options_id = '" . $order-&gt;products[$i]['attributes'][$j]['option_id'] . "' and pa.options_id = popt.products_options_id and pa.options_values_id = '" . $order-&gt;products[$i]['attributes'][$j]['value_id'] . "' and pa.options_values_id = poval.products_options_values_id and popt.language_id = '" . $osC_Session-&gt;value('languages_id') . "' and poval.language_id = '" . $osC_Session-&gt;value('languages_id') . "'");
</pre><pre class="diff" id="added">+          $Qattributes = $osC_Database-&gt;query('select popt.products_options_name, poval.products_options_values_name, pa.options_values_price, pa.price_prefix from :table_products_options popt, :table_products_options_values poval, :table_products_attributes pa where pa.products_id = :products_id and pa.options_id = :options_id and pa.options_id = popt.products_options_id and pa.options_values_id = :options_values_id and pa.options_values_id = poval.products_options_values_id and popt.language_id = :popt_language_id and poval.language_id = :poval_language_id');
+          $Qattributes-&gt;bindTable(':table_products_options', TABLE_PRODUCTS_OPTIONS);
+          $Qattributes-&gt;bindTable(':table_products_options_values', TABLE_PRODUCTS_OPTIONS_VALUES);
+          $Qattributes-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+          $Qattributes-&gt;bindInt(':products_id', $order-&gt;products[$i]['id']);
+          $Qattributes-&gt;bindInt(':options_id', $order-&gt;products[$i]['attributes'][$j]['option_id']);
+          $Qattributes-&gt;bindInt(':options_values_id', $order-&gt;products[$i]['attributes'][$j]['value_id']);
+          $Qattributes-&gt;bindInt(':popt_language_id', $osC_Session-&gt;value('languages_id'));
+          $Qattributes-&gt;bindInt(':poval_language_id', $osC_Session-&gt;value('languages_id'));
</pre><pre class="diff" id="context">         }
</pre><pre class="diff" id="removed">-        $attributes_values = tep_db_fetch_array($attributes);
</pre><pre class="diff" id="added">+        $Qattributes-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-        $sql_data_array = array('orders_id' =&gt; $insert_id,
-                                'orders_products_id' =&gt; $order_products_id,
-                                'products_options' =&gt; $attributes_values['products_options_name'],
-                                'products_options_values' =&gt; $attributes_values['products_options_values_name'],
-                                'options_values_price' =&gt; $attributes_values['options_values_price'],
-                                'price_prefix' =&gt; $attributes_values['price_prefix']);
-        tep_db_perform(TABLE_ORDERS_PRODUCTS_ATTRIBUTES, $sql_data_array);
-
-        if ((DOWNLOAD_ENABLED == 'true') &amp;&amp; isset($attributes_values['products_attributes_filename']) &amp;&amp; tep_not_null($attributes_values['products_attributes_filename'])) {
-          $sql_data_array = array('orders_id' =&gt; $insert_id,
-                                  'orders_products_id' =&gt; $order_products_id,
-                                  'orders_products_filename' =&gt; $attributes_values['products_attributes_filename'],
-                                  'download_maxdays' =&gt; $attributes_values['products_attributes_maxdays'],
-                                  'download_count' =&gt; $attributes_values['products_attributes_maxcount']);
-          tep_db_perform(TABLE_ORDERS_PRODUCTS_DOWNLOAD, $sql_data_array);
</pre><pre class="diff" id="added">+        $Qopa = $osC_Database-&gt;query('insert into :table_orders_products_attributes (orders_id, orders_products_id, products_options, products_options_values, options_values_price, price_prefix) values (:orders_id, :orders_products_id, :products_options, :products_options_values, :options_values_price, :price_prefix)');
+        $Qopa-&gt;bindTable(':table_orders_products_attributes', TABLE_ORDERS_PRODUCTS_ATTRIBUTES);
+        $Qopa-&gt;bindInt(':orders_id', $insert_id);
+        $Qopa-&gt;bindInt(':orders_products_id', $order_products_id);
+        $Qopa-&gt;bindValue(':products_options', $attributes_values['products_options_name']);
+        $Qopa-&gt;bindValue(':products_options_values', $attributes_values['products_options_values_name']);
+        $Qopa-&gt;bindValue(':options_values_price', $attributes_values['options_values_price']);
+        $Qopa-&gt;bindValue(':price_prefix', $attributes_values['price_prefix']);
+        $Qopa-&gt;execute();
+
+        if ((DOWNLOAD_ENABLED == 'true') &amp;&amp; (strlen($Qattributes-&gt;value('products_attributes_filename')) &gt; 0)) {
+          $Qopd = $osC_Database-&gt;query('insert into :table_orders_products_download (orders_id, orders_products_id, orders_products_filename, download_maxdays, download_count) values (:orders_id, :orders_products_id, :orders_products_filename, :download_maxdays, :download_count)');
+          $Qopd-&gt;bindTable(':table_orders_products_download', TABLE_ORDERS_PRODUCTS_DOWNLOAD);
+          $Qopd-&gt;bindInt(':orders_id', $insert_id);
+          $Qopd-&gt;bindInt(':orders_products_id', $order_products_id);
+          $Qopd-&gt;bindValue(':orders_products_filename', $Qattributes-&gt;value('products_attributes_filename'));
+          $Qopd-&gt;bindValue(':download_maxdays', $Qattributes-&gt;value('products_attributes_maxdays'));
+          $Qopd-&gt;bindValue(':download_count', $Qattributes-&gt;value('products_attributes_maxcount'));
+          $Qopd-&gt;execute();
</pre><pre class="diff" id="context">         }
</pre><pre class="diff" id="removed">-        $products_ordered_attributes .= "\n\t" . $attributes_values['products_options_name'] . ' ' . $attributes_values['products_options_values_name'];
</pre><pre class="diff" id="added">+
+        $products_ordered_attributes .= "\n\t" . $Qattributes-&gt;value('products_options_name') . ' ' . $Qattributes-&gt;value('products_options_values_name');
</pre><pre class="diff" id="context">       }
     }
 //------insert customer choosen option eof ----
</pre><pre class="diff"><small id="info">@@ -234,7 +269,7 @@
</small></pre><pre class="diff" id="context">                  EMAIL_TEXT_INVOICE_URL . ' ' . tep_href_link(FILENAME_ACCOUNT_HISTORY_INFO, 'order_id=' . $insert_id, 'SSL', false) . "\n" .
                  EMAIL_TEXT_DATE_ORDERED . ' ' . strftime(DATE_FORMAT_LONG) . "\n\n";
   if ($order-&gt;info['comments']) {
</pre><pre class="diff" id="removed">-    $email_order .= tep_<span id="removedchars">db_output</span>($order-&gt;info['comments']) . "\n\n";
</pre><pre class="diff" id="added">+    $email_order .= tep_<span id="addedchars">output_string_protected</span>($order-&gt;info['comments']) . "\n\n";
</pre><pre class="diff" id="context">   }
   $email_order .= EMAIL_TEXT_PRODUCTS . "\n" .
                   EMAIL_SEPARATOR . "\n" .
</pre><strong class="error" title="1 lines truncated at column 1000">[Note: Some over-long lines of diff output only partialy shown]</strong>
</div>
<hr /><a name="file4" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_shipping.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.23&amp;content-type=text/vnd.viewcvs-markup">1.23</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php.diff?r1=1.23&amp;r2=1.24">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.24&amp;content-type=text/vnd.viewcvs-markup">1.24</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.23 -r1.24
--- checkout_shipping.php	2004/07/22 21:43:16	1.23
+++ checkout_shipping.php	2005/02/23 15:28:27	1.24
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -35,10 +35,13 @@
</small></pre><pre class="diff" id="context">     $osC_Session-&gt;set('sendto', $osC_Customer-&gt;default_address_id);
   } else {
 // verify the selected shipping address
</pre><pre class="diff" id="removed">-    $check_address_query = tep_db_query("select count(*) as total from " . TABLE_ADDRESS_BOOK . " where customers_id = '" . (int)$osC_Customer-&gt;id . "' and address_book_id = '" . (int)$osC_Session-&gt;value('sendto') . "'");
-    $check_address = tep_db_fetch_array($check_address_query);
</pre><pre class="diff" id="added">+    $Qcheck = $osC_Database-&gt;query('select count(*) as total from :table_address_book where customers_id = :customers_id and address_book_id = :address_book_id');
+    $Qcheck-&gt;bindTable(':table_address_book', TABLE_ADDRESS_BOOK);
+    $Qcheck-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+    $Qcheck-&gt;bindInt(':address_book_id', $osC_Session-&gt;value('sendto'));
+    $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    if ($check_address['total'] != '1') {
</pre><pre class="diff" id="added">+    if ($Qcheck-&gt;valueInt('total') != 1) {
</pre><pre class="diff" id="context">       $osC_Session-&gt;set('sendto', $osC_Customer-&gt;default_address_id);
 
       $osC_Session-&gt;remove('shipping');
</pre></div>
<hr /><a name="file5" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_shipping_address.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping_address.php?rev=1.19&amp;content-type=text/vnd.viewcvs-markup">1.19</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping_address.php.diff?r1=1.19&amp;r2=1.20">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping_address.php?rev=1.20&amp;content-type=text/vnd.viewcvs-markup">1.20</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.19 -r1.20
--- checkout_shipping_address.php	2004/07/22 21:44:58	1.19
+++ checkout_shipping_address.php	2005/02/23 15:28:27	1.20
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -194,10 +194,13 @@
</small></pre><pre class="diff" id="context"> 
       $osC_Session-&gt;set('sendto', $_POST['address']);
 
</pre><pre class="diff" id="removed">-      $check_address_query = tep_db_query("select count(*) as total from " . TABLE_ADDRESS_BOOK . " where customers_id = '" . (int)$osC_Customer-&gt;id . "' and address_book_id = '" . (int)$osC_Session-&gt;value('sendto') . "'");
-      $check_address = tep_db_fetch_array($check_address_query);
</pre><pre class="diff" id="added">+      $Qcheck = $osC_Database-&gt;query('select count(*) as total from :table_address_book where customers_id = :customers_id and address_book_id = :address_book_id');
+      $Qcheck-&gt;bindTable(':table_address_book', TABLE_ADDRESS_BOOK);
+      $Qcheck-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+      $Qcheck-&gt;bindInt(':address_book_id', $osC_Session-&gt;value('sendto'));
+      $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-      if ($check_address['total'] == '1') {
</pre><pre class="diff" id="added">+      if ($Qcheck-&gt;valueInt('total') == 1) {
</pre><pre class="diff" id="context">         if ($reset_shipping == true) {
           $osC_Session-&gt;remove('shipping');
         }
</pre><pre class="diff"><small id="info">@@ -374,23 +377,27 @@
</small></pre><pre class="diff" id="context"> &lt;?php
       $radio_buttons = 0;
 
</pre><pre class="diff" id="removed">-      $addresses_query = tep_db_query("select address_book_id, entry_firstname as firstname, entry_lastname as lastname, entry_company as company, entry_street_address as street_address, entry_suburb as suburb, entry_city as city, entry_postcode as postcode, entry_state as state, entry_zone_id as zone_id, entry_country_id as country_id from " . TABLE_ADDRESS_BOOK . " where customers_id = '" . (int)$osC_Customer-&gt;id . "'");
-      while ($addresses = tep_db_fetch_array($addresses_query)) {
-        $format_id = tep_get_address_format_id($addresses['country_id']);
</pre><pre class="diff" id="added">+      $Qaddresses = $osC_Database-&gt;query('select address_book_id, entry_firstname as firstname, entry_lastname as lastname, entry_company as company, entry_street_address as street_address, entry_suburb as suburb, entry_city as city, entry_postcode as postcode, entry_state as state, entry_zone_id as zone_id, entry_country_id as country_id from :table_address_book where customers_id = :customers_id');
+      $Qaddresses-&gt;bindTable(':table_address_book', TABLE_ADDRESS_BOOK);
+      $Qaddresses-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+      $Qaddresses-&gt;execute();
+
+      while ($Qaddresses-&gt;next()) {
+        $format_id = tep_get_address_format_id($Qaddresses-&gt;valueInt('country_id'));
</pre><pre class="diff" id="context"> ?&gt;
               &lt;tr&gt;
                 &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                 &lt;td colspan="2"&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-       if ($addresses['address_book_id'] == $osC_Session-&gt;value('sendto')) {
</pre><pre class="diff" id="added">+       if ($Qaddresses-&gt;valueInt('address_book_id') == $osC_Session-&gt;value('sendto')) {
</pre><pre class="diff" id="context">           echo '                  &lt;tr id="defaultSelected" class="moduleRowSelected" onmouseover="rowOverEffect(this)" onmouseout="rowOutEffect(this)" onclick="selectRowEffect(this, ' . $radio_buttons . ')"&gt;' . "\n";
         } else {
           echo '                  &lt;tr class="moduleRow" onmouseover="rowOverEffect(this)" onmouseout="rowOutEffect(this)" onclick="selectRowEffect(this, ' . $radio_buttons . ')"&gt;' . "\n";
         }
 ?&gt;
                     &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="main" colspan="2"&gt;&lt;b&gt;&lt;?php echo tep_output_string_protected($addresses['firstname'] . ' ' . $addresses['lastname']); ?&gt;&lt;/b&gt;&lt;/td&gt;
-                    &lt;td class="main" align="right"&gt;&lt;?php echo osc_draw_radio_field('address', $addresses['address_book_id'], $osC_Session-&gt;value('sendto')); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="main" colspan="2"&gt;&lt;b&gt;&lt;?php echo $Qaddresses-&gt;valueProtected('firstname') . ' ' . $Qaddresses-&gt;valueProtected('lastname'); ?&gt;&lt;/b&gt;&lt;/td&gt;
+                    &lt;td class="main" align="right"&gt;&lt;?php echo osc_draw_radio_field('address', $Qaddresses-&gt;valueInt('address_book_id'), $osC_Session-&gt;value('sendto')); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                     &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                   &lt;/tr&gt;
                   &lt;tr&gt;
</pre><pre class="diff"><small id="info">@@ -398,7 +405,7 @@
</small></pre><pre class="diff" id="context">                     &lt;td colspan="3"&gt;&lt;table border="0" cellspacing="0" cellpadding="2"&gt;
                       &lt;tr&gt;
                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                        &lt;td class="main"&gt;&lt;?php echo tep_address_format($format_id, $<span id="removedchars">addresses</span>, true, ' ', ', '); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                        &lt;td class="main"&gt;&lt;?php echo tep_address_format($format_id, $<span id="addedchars">Qaddresses-&gt;toArray()</span>, true, ' ', ', '); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                       &lt;/tr&gt;
                     &lt;/table&gt;&lt;/td&gt;
</pre></div>
<hr /><a name="file6" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_success.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_success.php?rev=1.51&amp;content-type=text/vnd.viewcvs-markup">1.51</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_success.php.diff?r1=1.51&amp;r2=1.52">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_success.php?rev=1.52&amp;content-type=text/vnd.viewcvs-markup">1.52</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.51 -r1.52
--- checkout_success.php	2004/07/22 17:23:53	1.51
+++ checkout_success.php	2005/02/23 15:28:27	1.52
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -34,18 +34,26 @@
</small></pre><pre class="diff" id="context">   $breadcrumb-&gt;add(NAVBAR_TITLE_1);
   $breadcrumb-&gt;add(NAVBAR_TITLE_2);
 
</pre><pre class="diff" id="removed">-  $global_query = tep_db_query("select global_product_notifications from " . TABLE_CUSTOMERS_INFO . " where customers_info_id = '" . (int)$osC_Customer-&gt;id . "'");
-  $global = tep_db_fetch_array($global_query);
</pre><pre class="diff" id="added">+  $Qglobal = $osC_Database-&gt;query('select global_product_notifications from :table_customers_info where customers_info_id =:customers_info_id');
+  $Qglobal-&gt;bindTable(':table_customers_info', TABLE_CUSTOMERS_INFO);
+  $Qglobal-&gt;bindInt(':customers_info_id', $osC_Customer-&gt;id);
+  $Qglobal-&gt;execute();
+
+  if ($Qglobal-&gt;valueInt('global_product_notifications') !== 1) {
+    $Qorder = $osC_Database-&gt;query('select orders_id from :table_orders where customers_id = :customers_id order by date_purchased desc limit 1');
+    $Qorder-&gt;bindTable(':table_orders', TABLE_ORDERS);
+    $Qorder-&gt;bindInt(':customers_id', $osC_Customer-&gt;id);
+    $Qorder-&gt;execute();
+
+    $Qproducts = $osC_Database-&gt;query('select products_id, products_name from :table_orders_products where orders_id = :orders_id order by products_name');
+    $Qproducts-&gt;bindTable(':table_orders_products', TABLE_ORDERS_PRODUCTS);
+    $Qproducts-&gt;bindInt(':orders_id', $Qorder-&gt;valueInt('orders_id'));
+    $Qproducts-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if ($global['global_product_notifications'] != '1') {
-    $orders_query = tep_db_query("select orders_id from " . TABLE_ORDERS . " where customers_id = '" . (int)$osC_Customer-&gt;id . "' order by date_purchased desc limit 1");
-    $orders = tep_db_fetch_array($orders_query);
-
</pre><pre class="diff" id="context">     $products_array = array();
</pre><pre class="diff" id="removed">-    $products_query = tep_db_query("select products_id, products_name from " . TABLE_ORDERS_PRODUCTS . " where orders_id = '" . (int)$orders['orders_id'] . "' order by products_name");
-    while ($products = tep_db_fetch_array($products_query)) {
-      $products_array[] = array('id' =&gt; $products['products_id'],
-                                'text' =&gt; $products['products_name']);
</pre><pre class="diff" id="added">+    while ($Qproducts-&gt;next()) {
+      $products_array[] = array('id' =&gt; $Qproducts-&gt;valueInt('products_id'),
+                                'text' =&gt; $Qproducts-&gt;value('products_name'));
</pre><pre class="diff" id="context">     }
   }
 ?&gt;
</pre></div>
<center><small><a href="http://www.badgers-in-foil.co.uk/projects/cvsspam/" title="commit -&gt; email">CVSspam</a> 0.2.9</small></center>
</body></html>


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click