%
function htmlencode(str)
htmlencode=replace(replace(str,chr(13)," "),"'","''")
end function
dim rs,sql
if request("action")="add" then
set rs=server.createobject("adodb.recordset")
set rs_words=server.createobject("adodb.recordset")
sql_words="select * from words where announceid is null"
rs_words.open sql_words,conn,1,3
rs_words.addnew
rs_words("title")=request("title")
rs_words("body")=htmlencode(request("content"))
rs_words("author")=request("author")
rs_words("email")=request("email")
rs_words("tel")=request("tel")
rs_words("Expression")="smiley"
rs_words("orders")=0
rs_words("adddate")=date()
rs_words("addtime")=time()
rs_words.update
rs_words("rootid")=rs_words("announceid")
rs_words.update
rs_words.close
response.redirect "index.asp"
end if
%>