<?php
include $_SERVER['DOCUMENT_ROOT'] . "/WebBuilder/WebApp.class.php";
$db = new DBMain();



$target_dir = "uploads/";
$target_file = $target_dir . "{$_POST['employee_id']}-" . basename($_FILES["fileToUpload"]["name"]);
$FILE_NAME = "{$_POST['employee_id']}-" . basename($_FILES["fileToUpload"]["name"]);
$uploadOk = 1;
$imageFileType = strtolower(pathinfo($target_file, PATHINFO_EXTENSION));

// Allow certain file formats
if (
    $imageFileType != "jpg" && $imageFileType != "png" && $imageFileType != "jpeg"
    && $imageFileType != "gif" && $imageFileType != "pdf" && $imageFileType != "excel"
) {
    echo "Sorry, only JPG, JPEG, PNG, GIF, pdf, excel files are allowed.";
    $uploadOk = 0;
}

// Check if $uploadOk is set to 0 by an error
if ($uploadOk == 0) {
    echo "Sorry, your file was not uploaded.";
    // if everything is ok, try to upload file
} else {
    if (move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file)) {

        echo "The file " . htmlspecialchars(basename($_FILES["fileToUpload"]["name"])) . " has been uploaded.";
        if ($db->insert("INSERT INTO `documents` (`client_employees_id`,`file_name`,`file_path`) VALUES ({$_POST['employee_id']},'{$_POST['file_name']}','$FILE_NAME')")) {
            echo "<script>window.location.href='edit_employee.php?record_id={$_POST['employee_id']}#uploads'</script>";
        } else {
            echo "INSERT INTO `documents` (`client_employees_id`,`file_name`,`file_path`) VALUES ({$_POST['employee_id']},'{$_POST['file_name']}','$FILE_NAME')";
        }
    } else {
        echo "Sorry, there was an error uploading your file.";
    }
}
