<?php

// MySQL
session_start();
include("config.php");
include("header.php");
$menu_type = "loader";
include("menu.php");

$query = mysql_query("SELECT * FROM users WHERE name='".$_SESSION['name']."'") or die(mysql_error());
$list = mysql_fetch_object($query);

if(isset($_POST['check'])) {

	$query1 = mysql_query("SELECT * FROM vouchers WHERE code='".$_POST['code']."'") or die(mysql_error());
	$list1 = mysql_num_rows($query1);
	if($list1 == 1) {
		$query2 = mysql_query("SELECT * FROM vouchers WHERE code='".$_POST['code']."'") or die(mysql_error());
		$list2 = mysql_fetch_object($query2);

		$query3 = mysql_query("SELECT * FROM buy_furni WHERE id='".$list2->furni."'") or die(mysql_error());
		$list3 = mysql_fetch_object($query3);

		mysql_query("INSERT INTO furni (id, custom, height, inRoom, state, location, name, sitHeight, type, variable, stack) VALUES ('','".$list3->custom."', '".$list3->height."', '".$list3->inRoom."', '".$list3->state."', '".$list3->location."', '".$list3->name."', '".$list3->sitHeight."', '".$list3->type."', '".$list3->variable."', '".$list3->stack."')") or die(mysql_error());
		$checker = mysql_query("SELECT * FROM furni ORDER BY id DESC") or die(mysql_error());
		
		
       	
		   
		mysql_query("DELETE FROM vouchers WHERE id='".$list2->id."'") or die(mysql_error());



		$sql4 = "SELECT * FROM buy_furni WHERE name='".$list3->name."' ORDER BY id DESC";
		$query4 = mysql_query($sql4);
		$list4 = mysql_fetch_object($query4);
		
		$update = $list->hand.";".$list2->furni;

		mysql_query("UPDATE users SET hand = '".$update."' WHERE name = '".$_SESSION['name']."'") or die(mysql_error());
		
		echo "Furni added";

	} else {
		echo "Code Error";
	}
} else {
?>
<form method="post">
Code: <input type="text" name="code" class="textfield"><br>
<input type="submit" name="check" value="Check Code" class="submit">
</form>
<?}?>