<?php 
include('includes/config/config.php');
include('includes/auth/auth.php');
include('includes/functions.php');
include('access.php');
include 'log_entry.php';
error_reporting(E_ERROR | E_PARSE);
?>
<?php 

// Connect to mysqli database
$page = 1; // The current page
$sortname = 'box_id'; // Sort column
$sortorder = 'asc'; // Sort order
$qtype = ''; // Search column
$query = ''; // Search string
// Get posted data
if (isset($_POST['page'])) {
        $page = mysqli_real_escape_string($conn,$_POST['page']);
}
if (isset($_POST['sortname'])) {
        $sortname = mysqli_real_escape_string($conn,$_POST['sortname']);
}
if (isset($_POST['sortorder'])) {
        $sortorder = mysqli_real_escape_string($conn,$_POST['sortorder']);
}
if (isset($_POST['qtype'])) {
        $qtype = mysqli_real_escape_string($conn,$_POST['qtype']);
}
if (isset($_POST['query'])) {
        $query = mysqli_real_escape_string($conn,$_POST['query']);
}
if (isset($_POST['rp'])) {
        $rp = mysqli_real_escape_string($conn,$_POST['rp']);
}
// Setup sort and search SQL using posted data
$hasReadAccess = isAccessible($_SESSION['RoleId'],$menu_key,'R');
$hasWriteAccess = isAccessible($_SESSION['RoleId'],$menu_key,'W');
$hasExecuteAccess = isAccessible($_SESSION['RoleId'],$menu_key,'E');

$sortSql = "order by $sortname $sortorder";
$searchSql = ($qtype != '' && $query != '') ? "where upper($qtype) like upper('%$query%')" : '';
// Get total count of records
$sql = "select count(*)from first_aid_box $searchSql";
$result = mysqli_query($conn,$sql);
$row = mysqli_fetch_array($result);
$total = $row[0];
// Setup paging
if(!isSet($rp)){
	$rp=10;
}
$pageStart = ($page-1)*$rp;
$limitSql = "limit $pageStart, $rp";
// Return JSON data
$data = array();
$data['page'] = $page;
$data['total'] = $total;
$data['rows'] = array();
$sql_first_aid_box = "select * from first_aid_box $searchSql $sortSql $limitSql";
error_log("sql_first_aid_box:".$sql_first_aid_box);
$results_first_aid_box = mysqli_query($conn,$sql_first_aid_box);
$count=($page-1)*$rp+1;

//echo $sql_ailment;
//echo $access_level;

while ($row_first_aid_box = mysqli_fetch_assoc($results_first_aid_box)) {
    //extract $row_first_aid_box;
    $first_aid_box_id=$row_first_aid_box['box_id'];
	//echo $ailment_id;
	$view_link="";
	$edit_link="";
	$delete_link="";
	$links="";
	if($hasReadAccess)
	{
		//"shubham";
	    $view_link="<a  href=\"#\"class=\"grey\"  onclick=\"open_first_aid_box('".$first_aid_box_id."','V');\"><i class=\"ace-icon fa fa-eye bigger-130\"></i></a>";
	}

	if($hasWriteAccess )
	{
	    $edit_link="<a href=\"#\" class=\"blue\" onclick=\"open_first_aid_box('".$first_aid_box_id."','E');\"><i class=\"ace-icon fa fa-edit bigger-130\"></i></a>";
	}
	if($hasExecuteAccess )
	{
	    $delete_link="<a href=\"#\" class=\"red\" onclick=\"delete_first_aid_box('".$first_aid_box_id."');\"><i class=\"ace-icon fa fa-trash-o bigger-130\"></i></a>";
	}
	$first_aider_names=getCommaSeperatedValuesForInClause("select patient_name from patient_master","id",$row_first_aid_box['first_aider']);
	$space="&nbsp;&nbsp;&nbsp;";
	$links =$space.$view_link.$space.$edit_link.$space.$delete_link;

	$data['rows'][] = array(
	    'id' => $row_first_aid_box['box_id'],
	    'cell' => array( $links,$count++,  $row_first_aid_box['box_name'], $row_first_aid_box['box_code'] , $row_first_aid_box['box_loc'],$first_aider_names)
	);
}
echo json_encode($data);
?>