diff --git a/index.js b/index.js index bb3aab7a4ae29bf1455a327ca7c62f5016678c3b..05f3e320b0cdfbbad1aa70d61ebdc8e713557cbc 100644 --- a/index.js +++ b/index.js @@ -294,16 +294,15 @@ app.post("/delete-equipment", isAuthenticated, (req, res) => { app.get("/loans", (req, res) => { if (req.user && req.user.role === "user") { db.query( - `SELECT loans.id, loans.quantity, loans.status, equipment.name AS equipment_name - FROM loans - JOIN equipment ON loans.equipment_id = equipment.id + `SELECT loans.id, loans.quantity, loans.status, equipment.name AS equipment_name + FROM loans + JOIN equipment ON loans.equipment_id = equipment.id WHERE loans.user_id = ?`, - [req.user.id], + [req.user.id], // req.user.id will be substituted into the ? (err, loans) => { if (err) { return res.status(500).send("Error retrieving loans"); } - // ส่งข้อมูลทั้ง loans และ equipment ไปยัง EJS res.render("loans", { loans: loans, user: req.user }); } );