%dim action,userinfo,burn,sql action=request.querystring("action") if lguserid="" or isnull(lguserid) then response.redirect"login.asp" select case action case"myinfo" set rs=conn.execute("select*from [user] where userid="&lguserid&" and not del") userinfo=rs("userinfo") userinfo=split(userinfo,"|") burn=userinfo(2) burn=split(burn,"-") session(prefix&"regtime")=userinfo(9) %>
<%case"edit" dim password,repassword,email,sex,burn1,burn2,burn3,home,qq,gxqm,picw,pich,bbspic,mypic,toupic dim canreg,z,sickpass,regtime,userid,newuserinfo,bad,b,diyname function checkbad(str) if isnull(str) then exit function bad=split(application(prefix&"badcontent"), "|") for b=0 to ubound(bad) str=Replace(str,bad(b),string(len(bad(b)),"*")) next checkbad=str end function email=Replace(Request.Form("email"),"'","''") sex=checknum(request.form("sex")) burn1=replace(Request.Form("burn1"),"'","") burn2=replace(Request.Form("burn2"),"'","") burn3=replace(Request.Form("burn3"),"'","") home=Replace(Request.Form("home"),"'","''") home=ubbg(home) qq=Replace(Request.Form("qq"),"'","''") gxqm=Request.Form("gxqm") gxqm=Replace(left(gxqm,255),"'","''") gxqm=replace(gxqm,"|","│") gxqm=checkbad(gxqm) if checknum(session(prefix&"tempgrade"))>=1 then diyname=Request.Form("diyname") diyname=Replace(left(diyname,8),"'","") diyname=replace(diyname,"|","│") diyname=checkbad(diyname) end if picw=Replace(Request.Form("picw"),"'","''") pich=Replace(Request.Form("pich"),"'","''") mypic=Replace(Request.Form("mypic"),"'","''") mypic=ubbg(mypic) bbspic=Replace(Request.Form("bbspic"),"'","''") canreg=true if email="" or sex="" then canreg=false mes="·请填写完整必填的资料。