include("path.php");
require(BASE."include/"."incl.php");
global $current;
if(!$appId) {
errorpage('Internal Database Access Error');
exit;
}
if(!$versionId) {
$versionId = 0;
}
if(!$thread) {
$thread = 0;
}
opendb();
if($body)
{
// add comment to db
$hostname = get_remote();
$subject = strip_tags($subject);
$subject = mysql_escape_string($subject);
$body = mysql_escape_string($body);
// get current userid
$userId = (loggedin()) ? $current->userid : 0;
$result = mysql_query("INSERT INTO appComments VALUES (null, null, $thread, ".
"$appId, $versionId, $userId, '$hostname', '$subject', ".
"'$body', 0)");
if (!$result)
{
errorpage('Internal Database Access Error',mysql_error());
exit;
}
addmsg("New Comment Posted", "green");
redirect(apidb_fullurl("appview.php?appId=$appId&versionId=$versionId"));
}
else
{
apidb_header("Add Comment");
$mesTitle = "Post New Comment";
if($thread)
{
$result = mysql_query("SELECT subject,body FROM appComments WHERE commentId = $thread");
$ob = mysql_fetch_object($result);
if($ob)
{
$mesTitle = "Replying To ... $ob->subject\n";
echo html_frame_start($ob->subject,500);
echo htmlify_urls($ob->body), "
\n";
echo html_frame_end();
}
}
echo "
\n"; apidb_footer(); } ?>