2004-12-12 03:51:51 +00:00
< ? php
2006-06-17 06:10:10 +00:00
include ( " path.php " );
require ( BASE . " include/incl.php " );
require ( BASE . " include/application.php " );
require ( BASE . " include/mail.php " );
$aClean = array (); //array of filtered user input
$aClean [ 'versionId' ] = makeSafe ( $_REQUEST [ 'versionId' ]);
$aClean [ 'thread' ] = makeSafe ( $_REQUEST [ 'thread' ]);
$aClean [ 'body' ] = makeSafe ( $_REQUEST [ 'body' ]);
$aClean [ 'subject' ] = makeSafe ( $_REQUEST [ 'subject' ]);
2004-12-11 04:07:40 +00:00
/********************************/
/* code to submit a new comment */
/********************************/
2004-03-15 16:22:00 +00:00
2005-01-30 00:57:34 +00:00
/*
* application environment
*/
2004-12-11 04:07:40 +00:00
// you must be logged in to submit comments
2005-01-30 23:12:48 +00:00
if ( ! $_SESSION [ 'current' ] -> isLoggedIn ())
2004-12-11 04:07:40 +00:00
{
apidb_header ( " Please login " );
echo " To submit a comment for an application you must be logged in. Please <a href= \" account.php?cmd=login \" >login now</a> or create a <a href= \" account.php?cmd=new \" >new account</a>. " , " \n " ;
2005-01-15 05:59:21 +00:00
exit ;
2004-03-15 16:22:00 +00:00
}
2006-06-17 06:10:10 +00:00
if ( ! is_numeric ( $aClean [ 'versionId' ]) )
2004-12-11 04:07:40 +00:00
{
2006-06-29 16:13:35 +00:00
util_show_error_page ( 'Internal Database Access Error' );
2004-12-11 04:07:40 +00:00
exit ;
2004-03-15 16:22:00 +00:00
}
2006-06-17 06:10:10 +00:00
if ( ! is_numeric ( $aClean [ 'thread' ]))
2004-12-11 04:07:40 +00:00
{
2006-06-17 06:10:10 +00:00
$aClean [ 'thread' ] = 0 ;
2004-12-11 04:07:40 +00:00
}
2004-03-15 16:22:00 +00:00
2004-12-11 04:07:40 +00:00
############################
# ADDS COMMENT TO DATABASE #
############################
2006-06-17 06:10:10 +00:00
if ( ! empty ( $aClean [ 'body' ]))
2004-03-15 16:22:00 +00:00
{
2005-02-02 03:01:29 +00:00
$oComment = new Comment ();
2006-06-17 06:10:10 +00:00
$oComment -> create ( $aClean [ 'subject' ], $aClean [ 'body' ], $aClean [ 'thread' ], $aClean [ 'versionId' ]);
2005-02-02 03:01:29 +00:00
redirect ( apidb_fullurl ( " appview.php?versionId= " . $oComment -> iVersionId ));
2004-03-15 16:22:00 +00:00
}
2004-12-11 04:07:40 +00:00
################################
# USER WANTS TO SUBMIT COMMENT #
################################
2005-01-15 05:59:21 +00:00
else
2004-12-11 04:07:40 +00:00
{
apidb_header ( " Add Comment " );
2004-03-15 16:22:00 +00:00
2004-12-11 04:07:40 +00:00
$mesTitle = " <b>Post New Comment</b> " ;
2004-03-15 16:22:00 +00:00
2006-06-17 06:10:10 +00:00
if ( $aClean [ 'thread' ] > 0 )
2004-12-11 04:07:40 +00:00
{
2006-06-27 19:16:27 +00:00
$hResult = query_parameters ( " SELECT * FROM appComments WHERE commentId = '?' " ,
$aClean [ 'thread' ]);
2006-06-21 01:04:12 +00:00
$oRow = mysql_fetch_object ( $hResult );
if ( $oRow )
2004-11-17 23:05:36 +00:00
{
2006-06-21 01:04:12 +00:00
$mesTitle = " <b>Replying To ...</b> $oRow->subject\n " ;
$originator = $oRow -> userId ;
echo html_frame_start ( $oRow -> subject , 500 );
echo htmlify_urls ( $oRow -> body ), " <br /><br /> \n " ;
2004-12-11 04:07:40 +00:00
echo html_frame_end ();
2004-11-17 23:05:36 +00:00
}
2004-12-11 04:07:40 +00:00
}
2004-03-15 16:22:00 +00:00
2006-06-27 16:54:22 +00:00
echo " <form method= \" post \" action= \" addcomment.php \" > \n " ;
2004-03-15 16:22:00 +00:00
2004-12-11 04:07:40 +00:00
echo html_frame_start ( $mesTitle , 500 , " " , 0 );
echo '<table width="100%" border=0 cellpadding=0 cellspacing=1>' , " \n " ;
2004-12-29 20:21:31 +00:00
echo " <tr class= \" color0 \" ><td align=right><b>From:</b> </td> \n " ;
2005-02-02 00:14:01 +00:00
echo " <td> " . $_SESSION [ 'current' ] -> sRealname . " </td></tr> \n " ;
2004-12-29 20:21:31 +00:00
echo " <tr class= \" color0 \" ><td align=right><b>Subject:</b> </td> \n " ;
2006-06-17 06:10:10 +00:00
echo " <td> <input type= \" text \" size= \" 35 \" name= \" subject \" value= \" " . $aClean [ 'subject' ] . " \" /> </td></tr> \n " ;
echo " <tr class= \" color1 \" ><td colspan=2><textarea name= \" body \" cols= \" 70 \" rows= \" 15 \" wrap= \" virtual \" > " . $aClean [ 'body' ] . " </textarea></td></tr> \n " ;
2004-12-29 20:21:31 +00:00
echo " <tr class= \" color1 \" ><td colspan=2 align=center> \n " ;
2006-06-27 16:54:22 +00:00
echo " <input type= \" submit \" value= \" Post Comment \" class= \" button \" /> \n " ;
echo " <input type= \" reset \" value= \" Reset \" class= \" button \" /> \n " ;
2004-12-11 04:07:40 +00:00
echo " </td></tr> \n " ;
echo " </table> \n " ;
echo html_frame_end ();
2006-06-27 16:54:22 +00:00
echo " <input type= \" hidden \" name= \" thread \" value= \" " . $aClean [ 'thread' ] . " \" /> \n " ;
echo " <input type= \" hidden \" name= \" appId \" value= \" " . $aClean [ 'appId' ] . " \" /> \n " ;
echo " <input type= \" hidden \" name= \" versionId \" value= \" " . $aClean [ 'versionId' ] . " \" /> \n " ;
2006-06-17 06:10:10 +00:00
if ( ! empty ( $aClean [ 'thread' ]))
2004-12-11 04:07:40 +00:00
{
2006-06-27 16:54:22 +00:00
echo " <input type= \" hidden \" name= \" originator \" value= \" $originator\ " /> \n " ;
2004-12-11 04:07:40 +00:00
}
echo " </form> " ;
2004-03-15 16:22:00 +00:00
}
2004-12-11 04:07:40 +00:00
apidb_footer ();
2004-03-15 16:22:00 +00:00
?>