Captcha aligned right, & separated note init logic
[dylansserver.git] / index.php
index 16a01ec..f15b999 100644 (file)
--- a/index.php
+++ b/index.php
@@ -296,36 +296,51 @@ class note extends cms {
 
   private $id;
   private $comments_enabled = false;
-  private $url;
+  public $url;
+  public $title;
+  public $year_posted;
+  public $month_posted;
+  public $day_posted;
+  public $text;
+  public $number_of_comments;
 
   public function __construct($comments_enabled = false) {
     parent::__construct();
-       $this->check_exists();
        $this->comments_enabled = $comments_enabled;
     $url = htmlspecialchars($_SERVER['REQUEST_URI']);
        if (isset($_GET['verify'])) {
-      $url = substr($url, 0, (strlen($url)-7));
+      $url = substr($url, 0, (strlen($url)-6));
        }
        $this->url = $url;
-  }
-
-  private function check_exists() {
-    $sql = "SELECT COUNT(*) FROM notes
-                         WHERE url = ?";
-       $results = $this->query($sql, "s", $_GET['note']);
-       if ($results[0]["COUNT(*)"] != 1) {
+    $sql = "SELECT title, date_posted, text, id
+                         FROM notes WHERE url = ?";
+       $result = $this->query($sql, "s",
+                                                         $_GET['note']);
+       if ($result) {
+         $entry = $result[0];
+         $this->id = $entry["id"];
+         $this->title = $entry["title"];
+         $date_posted =  explode("-", $entry["date_posted"]);
+         $this->year_posted = $date_posted[0];
+         $this->month_posted = $date_posted[1];
+         $datetime_posted = explode(' ', $date_posted[2]);
+         $this->day_posted = $datetime_posted[0];
+         $this->text = $entry["text"];
+       } else {
          throw new notFound();
        }
+       $sql = "SELECT COUNT(*) FROM comments
+                         WHERE note = $this->id";
+       $result = $this->db->query($sql);
+       $result = $result->fetch_array();
+       $this->number_of_comments = $result[0];
   }
 
   public function display() {
        $this->display_head();
        $this->display_note();
-       if (isset($_GET['verify'])) {
-         $this->verify();
-       }
        if ($this->comments_enabled) {
-         $this->display_comments();  // but where are they?
+         $this->display_comments();
          $this->display_comment_form();
        }
        $this->write_navigation();
@@ -334,54 +349,70 @@ class note extends cms {
 
   private function verify() {
     require_once('includes/recaptchalib.php');
+       echo "<br>";
     $resp = recaptcha_check_answer ($this->recaptcha_privatekey,
                                                                    $_SERVER["REMOTE_ADDR"],
                                                                    $_POST["recaptcha_challenge_field"],
                                                                    $_POST["recaptcha_response_field"]);
     if (!$resp->is_valid) {
-      echo "The reCAPTCHA wasn't entered correctly. Go back and try it again." . "(reCAPTCHA said: " . $resp->error . ")";
-    }
+      echo "<span style=\"color:red;border:1px solid black;padding:15px;\">sorry, reCAPTCHA said you're not human.</span><br><br><br>";
+    } else {
+         $sql = ("INSERT INTO comments (date_posted, author,
+                               email, text, note)
+                               VALUES(NOW(), ?, ?, ?, ?)");
+         $stmt = $this->db->prepare($sql);
+         // Checks are needed here (no blank text,
+         // and a default author / email need to be set
+         $stmt->bind_param('ssss',
+                                               htmlspecialchars($_POST['author']),
+                                               htmlspecialchars($_POST['email']),
+                                               htmlspecialchars($_POST['text']),
+                                               $this->id);
+         $stmt->execute();
+       }
   }
 
   private function display_note() {
-    $sql = "SELECT title, date_posted, text, id
-                         FROM notes WHERE url = ?";
-       $result = $this->query($sql, "s",
-                                                         $_GET['note']);
-       $entry = $result[0];
-       $this->id = $entry["id"]; // This is needed for display_comments()
-       $title = $entry["title"];
-       $date_posted =  explode("-", $entry["date_posted"]);
-       $year_posted = $date_posted[0];
-       $month_posted = $date_posted[1];
-       $datetime_posted = explode(' ', $date_posted[2]);
-       $day_posted = $datetime_posted[0];
        echo "<div id=\"note\">";
-    echo "<h2><span style=\"color:grey;\">$year_posted/$month_posted/$day_posted/</span>$title</h2>";
-       if (!$this->comments_enabled) {
-         $this->display_comment_link();
-       }
-       echo $entry['text'];
+    echo "<h2><span style=\"color:grey;\">$this->year_posted/$this->month_posted/$this->day_posted/</span>$this->title</h2>";
+       echo $this->text;
   }
 
   private function write_navigation() {
-       echo "<br>";
-    echo "<div id=\"navigation\">";
-    echo "<h2>";
-    echo "<a href=\"/notes/\">notes</a>/";
-    echo "</h2>";
-    echo "</div>";
+    echo <<<END_OF_NAVIGATION
+       <br>
+    <div id=\"navigation\">
+    <h2>
+END_OF_NAVIGATION;
+       if (!$this->comments_enabled) {
+         $this->display_comment_link();
+       }
+    echo <<<END_OF_NAVIGATION
+       <a href="/notes/">notes</a>/
+    </h2>
+    </div>
+END_OF_NAVIGATION;
   }
 
   private function display_comment_link() {
-    $url = $this->url . 'comments/';
-    echo "<a id=\"comment_link\" href=\"$url\">comments</a>";
+    if ($this->number_of_comments > 0) {
+         $anchor_text = "comments ($this->number_of_comments)";
+       } else {
+         $anchor_text = "comment?";
+       }
+       if (substr($this->url, (strlen($this->url)-1), strlen($this->url)) == '/') {
+      $url = $this->url . 'comments/';
+       } else {
+      $url = $this->url . '/comments/';
+       }
+    echo "<a id=\"comment_link\" href=\"$url\">$anchor_text</a>";
   }
 
   private function display_comments() {
     echo "<div id=\"comments\">";
        $sql= "SELECT date_posted, author, email, text
-                FROM comments WHERE note = ?";
+                FROM comments WHERE note = ?
+                        ORDER BY date_posted DESC";
     $result = $this->query($sql, "d", $this->id);
        foreach ($result as $row => $entry) {
          $date_posted = $entry['date_posted'];
@@ -394,18 +425,53 @@ class note extends cms {
          <br>
          <br>
 END_OF_COMMENT;
-       }
+         }
        echo "</div>";
   }
 
   private function display_comment_form() {
-       // Trailing slash is necessary for reloads to work
-    $url = $this->url . "verify/";
-       echo "<form id=\"comment\" method=\"post\" action=\"$url\">";
+    echo <<<END_CAPTCHA_STYLE
+<script type="text/javascript">
+var RecaptchaOptions = {
+   theme : 'custom',
+   custom_theme_widget: 'recaptcha_widget'
+   };
+</script>
+END_CAPTCHA_STYLE;
     require_once('includes/recaptchalib.php');
+       // Trailing slash is necessary for reloads to work
+    $url = $this->url . "verify";
+       echo "<form method=\"post\" action=\"$url\">";
+       echo  <<<FORM
+       <div id="comment">
+
+<h3>comment:</h3>
+<textarea rows="10" cols="70" name=text></textarea>
+<h3>name:</h3>
+<input type=text name=author>
+<h3>email:</h3>
+<input type=text name=email><br>
+<nowiki>
+
+<div id="recaptcha_widget"> 
+<h3 class="recaptcha_only_if_image"><b>what's this say</b>?</h3>
+<h3 class="recaptcha_only_if_audio"><b>enter the numbers you hear</b>:</h3>
+<span style="font-size:80%;">(<a href="javascript:Recaptcha.reload()">another</a>/<span class="recaptcha_only_if_image"><a href="javascript:Recaptcha.switch_type('audio')">audio</a></span>/<span class="recaptcha_only_if_audio"><a href="javascript:Recaptcha.switch_type('image')">Get an image CAPTCHA</a></span><a href="javascript:Recaptcha.showhelp()">help</a>)</span><br><br>
+  <input type="text" id="recaptcha_response_field" name="recaptcha_response_field" />
+  <br><br>
+  <div style="float:right;position:relative;width:100px;"><div id="recaptcha_image"></div></div>
+  <br><br><br><br>
+</div>
+FORM;
        echo recaptcha_get_html($this->recaptcha_publickey);
-       echo "<input type=\"submit\">";
-       echo "</form>";
+       if (isset($_GET['verify'])) {
+         $this->verify();
+       }
+       echo  <<<END_OF_FORM
+       <input class="submit" type="submit" value="comment">
+       </form>
+       </div>
+END_OF_FORM;
   }
 }