";
echo <<
my projects:
@@ -296,36 +302,55 @@ class note extends cms {
private $id;
private $comments_enabled = false;
- private $url;
+ private $failed_captcha;
+ public $url;
+ public $title;
+ public $year_posted;
+ public $month_posted;
+ public $day_posted;
+ public $text;
+ public $number_of_comments;
public function __construct($comments_enabled = false) {
parent::__construct();
- $this->check_exists();
$this->comments_enabled = $comments_enabled;
$url = htmlspecialchars($_SERVER['REQUEST_URI']);
if (isset($_GET['verify'])) {
- $url = substr($url, 0, (strlen($url)-7));
+ $url = substr($url, 0, (strlen($url)-6));
}
$this->url = $url;
- }
-
- private function check_exists() {
- $sql = "SELECT COUNT(*) FROM notes
- WHERE url = ?";
- $results = $this->query($sql, "s", $_GET['note']);
- if ($results[0]["COUNT(*)"] != 1) {
+ $sql = "SELECT title, date_posted, text, id
+ FROM notes WHERE url = ?";
+ $result = $this->query($sql, "s",
+ $_GET['note']);
+ if ($result) {
+ $entry = $result[0];
+ $this->id = $entry["id"];
+ $this->title = $entry["title"];
+ $date_posted = explode("-", $entry["date_posted"]);
+ $this->year_posted = $date_posted[0];
+ $this->month_posted = $date_posted[1];
+ $datetime_posted = explode(' ', $date_posted[2]);
+ $this->day_posted = $datetime_posted[0];
+ $this->text = $entry["text"];
+ } else {
throw new notFound();
}
+ $sql = "SELECT COUNT(*) FROM comments
+ WHERE note = $this->id";
+ $result = $this->db->query($sql);
+ $result = $result->fetch_array();
+ $this->number_of_comments = $result[0];
+ if (isset($_GET['verify'])) {
+ $this->verify();
+ }
}
public function display() {
$this->display_head();
$this->display_note();
- if (isset($_GET['verify'])) {
- $this->verify();
- }
if ($this->comments_enabled) {
- $this->display_comments(); // but where are they?
+ $this->display_comments();
$this->display_comment_form();
}
$this->write_navigation();
@@ -333,79 +358,157 @@ class note extends cms {
}
private function verify() {
- require_once('includes/recaptchalib.php');
- $resp = recaptcha_check_answer ($this->recaptcha_privatekey,
- $_SERVER["REMOTE_ADDR"],
- $_POST["recaptcha_challenge_field"],
- $_POST["recaptcha_response_field"]);
- if (!$resp->is_valid) {
- echo "The reCAPTCHA wasn't entered correctly. Go back and try it again." . "(reCAPTCHA said: " . $resp->error . ")";
+ if (!isset($_POST['captcha'])) {
+ require_once('includes/recaptchalib.php');
+ echo "
";
+ $resp = recaptcha_check_answer ($this->recaptcha_privatekey,
+ $_SERVER["REMOTE_ADDR"],
+ $_POST["recaptcha_challenge_field"],
+ $_POST["recaptcha_response_field"]);
+ if (!$resp->is_valid) {
+ $this->failed_captcha = true;
+ }
}
+ if (isset($_POST['captcha']) || $resp->is_valid) {
+ $sql = ("INSERT INTO comments (date_posted, author,
+ email, text, note)
+ VALUES(NOW(), ?, ?, ?, ?)");
+ $stmt = $this->db->prepare($sql);
+ // Checks are needed here (no blank text,
+ // and a default author / email need to be set
+ // for no-javascript users.
+ $stmt->bind_param('ssss',
+ htmlspecialchars($_POST['name']),
+ htmlspecialchars($_POST['email']),
+ htmlspecialchars($_POST['text']),
+ $this->id);
+ $stmt->execute();
+ }
}
private function display_note() {
- $sql = "SELECT title, date_posted, text, id
- FROM notes WHERE url = ?";
- $result = $this->query($sql, "s",
- $_GET['note']);
- $entry = $result[0];
- $this->id = $entry["id"]; // This is needed for display_comments()
- $title = $entry["title"];
- $date_posted = explode("-", $entry["date_posted"]);
- $year_posted = $date_posted[0];
- $month_posted = $date_posted[1];
- $datetime_posted = explode(' ', $date_posted[2]);
- $day_posted = $datetime_posted[0];
- echo "";
- echo "
$year_posted/$month_posted/$day_posted/$title
";
- if (!$this->comments_enabled) {
- $this->display_comment_link();
- }
- echo $entry['text'];
+ echo <<
+ $this->year_posted/$this->month_posted/$this->day_posted/$this->title
+ $this->text
+
+END_OF_NOTE;
}
private function write_navigation() {
- echo "
";
- echo "";
- echo "
";
- echo "notes/";
- echo "
";
- echo "
";
+ echo <<
+
+
+END_OF_NAVIGATION;
+ if (!$this->comments_enabled) {
+ $this->display_comment_link();
+ }
+ echo <<back to notes/
+
+
+END_OF_NAVIGATION;
}
private function display_comment_link() {
- $url = $this->url . 'comments/';
- echo "";
+ if ($this->number_of_comments > 0) {
+ $anchor_text = "comments($this->number_of_comments)/";
+ } else {
+ $anchor_text = "comment?";
+ }
+ if (substr($this->url, (strlen($this->url)-1), strlen($this->url)) == '/') {
+ $url = $this->url . 'comments/';
+ } else {
+ $url = $this->url . '/comments/';
+ }
+ echo "";
}
private function display_comments() {
echo "";
}
private function display_comment_form() {
- // Trailing slash is necessary for reloads to work
- $url = $this->url . "verify/";
- echo "";
+ $url = $this->url . "verify";
+ echo "
+
+END_OF_FORM;
+ } else {
+ echo <<
-
+