real_escape($_GET['val']);
if(!empty($val) || $val == "edit"){
$id = $db->real_escape($_GET['id']);
$result = $db->fetch_array($db->query("SELECT * FROM department WHERE department_id = '$id'"));
$edit = true;
}
if(isset($_POST['create']) || isset($_POST['update'])){
$id = $db->real_escape($_POST['department_id']);
$department = $db->real_escape($_POST['department']);
if(isset($_POST['update'])){
$operation = "UPDATE";
$where = "WHERE department_id = '$id'";
$success_message = "Record Successfully Update";
}elseif(isset($_POST['create'])){
$operation = "INSERT INTO";
$where = "";
$success_message = "Record Successfully Added";
}
if($db->num_rows($db->query("SELECT * FROM department WHERE department = '$department'")) == 0 || isset($_POST['update'])){
$query = "$operation department SET department = '$department', create_date = NOW() $where";
if($db->query($query)){
$msg = $success_message;
}else{
$error = "Network Error.";
}
}else{
$error = "This department already exist.";
}
}
?>