<?php
include 'connection.php'; // your DB connection script

$q = isset($_GET['q']) ? trim($_GET['q']) : '';

if ($q !== '') {
    $stmt = $link->prepare("SELECT pro_id, pro_name, pro_category FROM tbl_product WHERE pro_name LIKE ? LIMIT 10");
    $searchTerm = "%{$q}%";
    $stmt->bind_param("s", $searchTerm);
    $stmt->execute();
    $result = $stmt->get_result();

    echo "<ul>";
    while ($row = $result->fetch_assoc()) {
        $pro_id = htmlspecialchars($row['pro_id']);
        $pro_name = htmlspecialchars($row['pro_name']);
        $pro_category = htmlspecialchars($row['pro_category']);

        echo "<li onclick=\"goToProduct('$pro_id')\">$pro_name <small>($pro_category)</small></li>";
    }
    echo "</ul>";

    $stmt->close();
}
?>
