Repository navigation
Expand file tree
/
Copy patheditMessageAdmin.php
More file actions
73 lines (68 loc) · 2.64 KB
/
Copy patheditMessageAdmin.php
File metadata and controls
73 lines (68 loc) · 2.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
<html lang="en">
<?php
//Establish connection with the database
$db_hostname = 'localhost';
$db_database = 'messageboard';
$db_username = 'root';
$db_password = '';
$link = mysqli_connect($db_hostname, $db_username, $db_password, $db_database);
if (mysqli_connect_errno()) die("Unable to connect to MySQL: " . mysqli_connect_error());
session_start();
if ((isset($_SESSION['loggedin']) && $_SESSION['loggedin']) != true) {
echo "<h1> You must login/register to see this page. Redirecting ... ";
sleep(.5);
header("Location: http://localhost:8080/part2/index.html");
}
?>
<head>
<meta charset="utf-8">
<title>messageBoard</title>
<meta name="index" content="The HTML5 Herald">
<meta name="Geno" content="SitePoint">
<link rel="stylesheet" href="styless.css">
</head>
<body>
</head>
<body>
<div class = nav_back>
<topnav>
<ul>
<li><a href="messageboard.php">Return to Chat</a></li>
<li><a class="active" href="messageboard.php">Edits</a></li>
<li><a href="mailto: m216060@usna.edu?subject= help needed">Contact</a></li>
<li><a onclick="logout()" >Log out</a></li>
</ul>
</topnav>
</div>
<!-- Form for inputing a new message -->
<div class="forms_div20">
<h3> Enter your NEW message: </h3>
<form name="messageboard" method="post" onsubmit="messageEscape()">
<label for="message">
<div class= "inputText">
<input type="text" required name="mess" placeholder="Hello There!" maxlength="60">
</div>
</label>
<input type="hidden" name="token" value="<?php echo $_SESSION['token']?>"/>
<input type="hidden" name="timeadded" value="<?php date_default_timezone_set('UTC'); echo date('l jS \of F Y h:i:s A');?>">
<input class= "button" type="submit" value="Send message!">
</form>
<?php
//Check if the if the id is set in the get request and the message is set in the post request
//Also for CSRF check if the session token is the same as the token from the form.
if ((isset($_GET['id']) && isset($_POST['mess'])) && ($_SESSION['token']==$_POST['token'])) {
$id = $_GET['id'];
$newMess = $_POST['mess'];
$sql = $link->prepare("UPDATE messages SET messageVal=? WHERE messageId=?");
$sql -> bind_param("ss",$newMess, $id);
$sql->execute();
// $query = "UPDATE messages SET messageVal='$newMess' WHERE messageId='$id'";
// $result = mysqli_query($link,$query);
//Output the appropriate message
echo "<h2>Message Updated!</h2><br>";
echo "<br> <br> <br> ";
}
//Close the connection
mysqli_close($link);
?>
</html>