-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathpost_process.php
More file actions
65 lines (56 loc) · 2.07 KB
/
Copy pathpost_process.php
File metadata and controls
65 lines (56 loc) · 2.07 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
<?php
// post_process.php
require_once 'includes/init.php';
if (!isset($_SESSION['user_id'])) {
header("Location: login.php");
exit;
}
if ($_SERVER['REQUEST_METHOD'] == 'POST') {
$content = $mysqli->real_escape_string(trim($_POST['content']));
if (empty($content)) {
die("El post no puede estar vacío.");
}
$user_id = $_SESSION['user_id'];
$image_path = null;
// Procesar imagen si se sube
if (isset($_FILES['image']) && $_FILES['image']['error'] === UPLOAD_ERR_OK) {
$fileTmpPath = $_FILES['image']['tmp_name'];
$fileName = $_FILES['image']['name'];
$fileNameCmps = explode(".", $fileName);
$fileExtension = strtolower(end($fileNameCmps));
// Extensiones permitidas
$allowedfileExtensions = array('jpg', 'jpeg', 'png', 'gif');
if (in_array($fileExtension, $allowedfileExtensions)) {
$uploadFileDir = 'images/';
if (!is_dir($uploadFileDir)) {
mkdir($uploadFileDir, 0755, true);
}
// Generar nombre único
$newFileName = md5(time() . $fileName) . '.' . $fileExtension;
$dest_path = $uploadFileDir . $newFileName;
if (move_uploaded_file($fileTmpPath, $dest_path)) {
$image_path = $mysqli->real_escape_string($dest_path);
} else {
die("Error al mover el archivo subido.");
}
} else {
die("Tipo de archivo no permitido. Solo se permiten imágenes (jpg, jpeg, png, gif).");
}
}
// Insertar el post con imagen (si existe)
if ($image_path) {
$sql = "INSERT INTO posts (user_id, content, image) VALUES ($user_id, '$content', '$image_path')";
} else {
$sql = "INSERT INTO posts (user_id, content) VALUES ($user_id, '$content')";
}
if ($mysqli->query($sql)) {
header("Location: index.php");
exit;
} else {
die("Error al publicar: " . $mysqli->error);
}
} else {
header("Location: index.php");
exit;
}
?>