MINI
C:
/
xampp
/
htdocs
/
polling_rt - Copy
/
Upload File:
files >> C:/xampp/htdocs/polling_rt - Copy/vote.php
<?php require 'inc/db.php'; require 'inc/functions.php'; if ($_SERVER['REQUEST_METHOD'] !== 'POST') { header('Location: index.php'); exit; } $candidate_id = isset($_POST['candidate_id']) ? (int)$_POST['candidate_id'] : 0; $ip = get_client_ip(); // Cek kandidat valid $stmt = $mysqli->prepare('SELECT id FROM candidates WHERE id = ?'); $stmt->bind_param('i', $candidate_id); $stmt->execute(); $stmt->store_result(); if ($stmt->num_rows === 0) { die('Kandidat tidak ditemukan.'); } $stmt->close(); // Cek IP sudah voting? $stmt = $mysqli->prepare('SELECT id FROM votes WHERE voter_ip = ?'); $stmt->bind_param('s', $ip); $stmt->execute(); $stmt->store_result(); if ($stmt->num_rows > 0) { // sudah voting header('Location: index.php?msg=already'); exit; } $stmt->close(); // simpan vote (transaksi) $mysqli->begin_transaction(); try { $stmt = $mysqli->prepare('INSERT INTO votes (candidate_id, voter_ip) VALUES (?,?)'); $stmt->bind_param('is', $candidate_id, $ip); $stmt->execute(); $stmt->close(); $stmt2 = $mysqli->prepare('UPDATE candidates SET votes = votes + 1 WHERE id = ?'); $stmt2->bind_param('i', $candidate_id); $stmt2->execute(); $stmt2->close(); $mysqli->commit(); header('Location: index.php?msg=thanks'); } catch(Exception $e) { $mysqli->rollback(); header('Location: index.php?msg=error'); }
Copyright ©2021 || Defacer Indonesia