Advertisement
Guest User

Untitled

a guest
Jan 29th, 2015
210
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.00 KB | None | 0 0
  1. <?php
  2.  
  3. if ((!empty($_POST['save'])) && ($_POST['save']=='ok')){
  4. $chyby='';
  5. $_POST['komentar']=trim($_POST['komentar']);
  6. if ($_POST['komentar']==''){
  7. $chyby.='<p>Je nutné zadat text!</p>';
  8. }
  9.  
  10. if ($chyby==''){
  11.  
  12. // nejaka obrana proti sql injection, mozna zbytecne vytvareni novych promenncyh
  13.  
  14. $komentar = mysql_real_escape_string($_POST['komentar']);
  15.  
  16. $komentar = htmlspecialchars($komentar);
  17. $sql="INSERT INTO komentare".
  18. "(uzivatel_id, kapela_id,komentar)".
  19. "VALUES ".
  20. "('$_SESSION[id]','$_GET[kapela]','$komentar')";
  21.  
  22.  
  23. mysql_query($sql) or die("Nelze provést". mysql_error());
  24. header("Location: index.php?page=home");
  25. exit();
  26. }
  27. }
  28.  
  29.  
  30.  
  31. if(isset($_SESSION["id"])) {
  32. if (!empty($chyby)){
  33. echo '<div style="color:red;">'.$chyby.'</div>';
  34. }
  35. echo '<form action="index.php?page=komentare&kapela='. $_GET['kapela'] . '" method="post" >
  36. <input type="hidden" name="save" value="ok" />
  37.  
  38. <label for="komentar">Text:</label>
  39. <input type="text" name="komentar" id="komentar" value="'. htmlspecialchars(@$_POST['komentar']).'" required="required" />
  40.  
  41. <input type="submit" value="Odeslat komentář">
  42. </br></br>
  43.  
  44. </form>
  45. ';
  46.  
  47.  
  48. }
  49. else {
  50. echo "Nemůžete komentovat pokud nejste přihlášen!";
  51. }
  52.  
  53.  
  54. $vysledek=mysql_query("SELECT * FROM komentare JOIN uzivatel ON (komentare.uzivatel_id = uzivatel.id_uzivatele) WHERE komentare.kapela_id = " . $_GET["kapela"]) or die (mysql_error());
  55. while ($zaznam = mysql_fetch_array($vysledek)):
  56. ?>
  57. <h2>
  58. <?php echo $zaznam["jmeno"]; ?>
  59. <?php echo $zaznam["prijmeni"]; ?>
  60. </h2>
  61. <p>
  62. <?php echo $zaznam["komentar"]; ?>
  63. </p>
  64.  
  65. <?php if($zaznam['id_uzivatele'] == $_SESSION['id']): ?>
  66.  
  67. <a href="vymazkomentar.php?id=<?php echo $zaznam["id_komentare"];?>">Vymaz me</a>
  68.  
  69. <?php endif; ?>
  70.  
  71. <?php
  72. endwhile;
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement