File size: 2,219 Bytes
0dff816
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
<?php
require_once '../../db.php';
redirectIfNotLoggedIn();

if ($_SERVER['REQUEST_METHOD'] == 'POST') {
    $data = json_decode(file_get_contents('php://input'), true);
    $package_name = $data['package'];
    $amount = $data['amount'];
    $user_id = $_SESSION['user_id'];
    
    // Check if user has sufficient balance
    if ($_SESSION['balance'] < $amount) {
        echo json_encode(['success' => false, 'message' => 'Insufficient balance.']);
        exit;
    }
    
    // Get package details
    $stmt = $pdo->prepare("SELECT * FROM packages WHERE name = ?");
    $stmt->execute([$package_name]);
    $package = $stmt->fetch(PDO::FETCH_ASSOC);
    
    if (!$package) {
        echo json_encode(['success' => false, 'message' => 'Package not found.']);
        exit;
    }
    
    // Start transaction
    $pdo->beginTransaction();
    
    try {
        // Deduct amount from user balance
        $stmt = $pdo->prepare("UPDATE users SET balance = balance - ?, package = ? WHERE id = ?");
        $stmt->execute([$amount, $package_name, $user_id]);
        
        // Record transaction
        $stmt = $pdo->prepare("INSERT INTO transactions (user_id, type, amount, description, status) VALUES (?, 'purchase', ?, ?, 'completed')");
        $stmt->execute([$user_id, $amount, "Purchased {$package_name} package"]);
        
        // Add to user packages
        $stmt = $pdo->prepare("INSERT INTO user_packages (user_id, package_id, investment_amount, expected_return) VALUES (?, ?, ?, ?)");
        $stmt->execute([$user_id, $package['id'], $amount, $package['return_amount']]);
        
        // Update user package
        $stmt = $pdo->prepare("UPDATE users SET package = ? WHERE id = ?");
        $stmt->execute([$package_name, $user_id]);
        
        // Commit transaction
        $pdo->commit();
        
        // Update session
        $_SESSION['balance'] -= $amount;
        $_SESSION['package'] = $package_name;
        
        echo json_encode(['success' => true, 'message' => 'Package purchased successfully!']);
    } catch (Exception $e) {
        $pdo->rollBack();
        echo json_encode(['success' => false, 'message' => 'Purchase failed: ' . $e->getMessage()]);
    }
}
?>