function insert_rating($rating, $article_id) { if(mysqli_num_rows(mysqli_query("SELECT ID FROM articles_ratings WHERE rater_ip='".mysqli_real_escape_string(getIP())."' AND ID='".mysqli_real_escape_string($article_id)."'"))==0) { if(mysqli_query($conn, "INSERT INTO articles_ratings (`article_id`, `rating_value`, `rater_ip`) VALUES ('".mysqli_real_escape_string($article_id)."', '".mysqli_real_escape_string($rating)."', '".mysqli_real_escape_string(getIP())."')")) { $response = 'Thank you for voting this article!'; } else { $response = 'Ups. A problem. I was unable to save your rating!'; } } else { $response = 'Sorry but you can only rate once'; } $objResponse = new xajaxResponse(); $objResponse->addAssign("response","innerHTML", $response); return $objResponse; }