i can’t seem to figure this out. I am new to php and this is like my first full script that i did alone so all help would be appreciated
[php]<?php
require_once(“config.php”);
$auth_host = $GLOBALS['auth_host'];
$auth_user = $GLOBALS['auth_user'];
$auth_pass = $GLOBALS['auth_pass'];
$auth_dbase = $GLOBALS['auth_dbase'];
$user_name=$_POST['username'];
$user_donateamount=$_POST['DonateAmount'];
$user_cardname=$_POST['CardName'];
$db = mysql_connect($auth_host, $auth_user, $auth_pass) or die (mysql_error());
mysql_select_db($auth_dbase,$db);
$sql = mysql_query("SELECT * FROM `user` WHERE 'name' = '$user_name'");
$row = mysql_fetch_array($sql);
if('$user_donateamount' > $row['credits']) {
echo "fail";
} else {
$sql1 = mysql_query("SELECT * FROM `scores` WHERE 'name' = '$user_cardname'");
echo "success";
if($row = mysql_fetch_array($sql))
{
mysql_query("UPDATE `scores` SET `score` = `score` + '$user_donateamount' WHERE 'name' = $user_cardname");
mysql_query("UPDATE `user` SET `credits` = `credits` - '$user_donateamount' WHERE 'name' = $user_name");
echo "success";
}
else {
mysql_query("INSERT INTO scores(name,score ) VALUES ('". mysql_real_escape_string($user_cardname) ."','". mysql_real_escape_string($user_donateamount) ."')");
mysql_query("UPDATE `user` SET `credits` = `credits` - '$user_donateamount' WHERE 'name' = $user_name");
echo “success”;
}}
mysql_close($db);
?> [/php]