blog_read.php
<?php include('core/init.inc.php'); if (isset($_GET['pid'], $_POST['user'], $_POST['body'])){ if(add_comment($_GET['pid'], $_POST['user'], $_POST['body'])){ header("Location: blog_read.php?pid={$_GET['pid']}"); } else{ header('Location: blog_list.php'); } die(); } ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="description" content="" /> <meta name="keywords" content="" /> <title>Consistent by FCT</title> <link href="http://fonts.googleapis.com/css?family=Bitter" rel="stylesheet" type="text/css" /> <link rel="stylesheet" type="text/css" href="css/style.css" /> <link href="style.css" rel="stylesheet" type="text/css" /> <script type="text/javascript" src="jquery-1.7.1.min.js"></script> <script type="text/javascript" src="jquery.dropotron-1.0.js"></script> <script type="text/javascript"> $(function() { $('#menu > ul').dropotron({ alignment: 'center', mode: 'fade', offsetY: -13 }); }); </script> </head> <body> <div id="wrapper"> <div id="header"> <div id="logo"> <h1><a href="index_php.php">The OWNag3 Gamer Site</a></h1> <p class="slogan">Get your Swag on<a href="http://www.freecsstemplates.org"></a></p> </div> </div> <div id="menu"> <ul> <li><a href="gameproducts.html">Game Products</a></li> <li><a href="events.html">events</a></li> <li><a href="videos.html">Videos</a></li> <li><a href="gameforum.html">Game Forum</a></li> <li><a href="affiliates.html"></a></li> </ul> </div> <div id="page"> <div id="sidebar"> <div class="box"> <h3>Login</h3> <form method="post" action="checklogin.php"> Username:<input type="text" name="username" /><br /> Password: <input type="password" name="password" /><br /> <input type="submit" value="Login" /> </form> <p> </p> <p> </p> <h3>The Game blog</h3> <p> Come share us all your top secrets to help pwn noobs on the battlefield. Show us your sick montage clips! </p> </div> </div> </div> <div id="content"> <?php if (isset($_GET['pid']) === false || valid_pid($_GET['pid']) === false){ echo mysql_error(); echo 'Invalid Post ID'; } else{ $post = get_post($_GET['pid']); ?> <h2><?php echo $post['title']; ?></h2> <h4>By <?php echo $post['user']; ?> on <?php echo $post['date']; ?> (<?php echo count($post['comments']); ?> comments)</h4> <hr /> <p><?php echo $post['body'];?></p> <hr /> <?php foreach ($post['comments'] as $comment){ ?> <h4>By <?php echo $comment['user'];?> on <?php echo $comment['date']; ?></h4> <p><?php echo $comment['body']; ?></p> <hr /> <?php } ?> <form action="" method="post"> <p> <label for="user">Name</label> <input type="text" name="user" id="user" /> </p> <p> <textarea name="body" rows="20" cols="60"></textarea> </p> <p> <input type="submit" value="Add Comment" /> </p> </form> <?php } ?> </div> <br class="clearfix" /> </div> </div> <div id="footer"> <p><a href="gameproducts.html">Game Products</a> | <a href="events.html">Events</a> | <a href="videos.html">Videos</a> | <a href="gameforum.html">Game Forums</a> | <a href="affiliates.html">Affiliates</a></p> <p> </p> </div> </body> </html>blog_list.php
<?php include('core/init.inc.php'); ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <!-- Design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 3.0 License Name : Consistent Description: A two-column, fixed-width design with dark color scheme. Version : 1.0 Released : 20120322 --> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="description" content="" /> <meta name="keywords" content="" /> <title>Consistent by FCT</title> <link href="http://fonts.googleapis.com/css?family=Bitter" rel="stylesheet" type="text/css" /> <link rel="stylesheet" type="text/css" href="css/style.css" /> <link href="style.css" rel="stylesheet" type="text/css" /> <script type="text/javascript" src="jquery-1.7.1.min.js"></script> <script type="text/javascript" src="jquery.dropotron-1.0.js"></script> <script type="text/javascript"> $(function() { $('#menu > ul').dropotron({ alignment: 'center', mode: 'fade', offsetY: -13 }); }); </script> </head> <body> <div id="wrapper"> <div id="header"> <div id="logo"> <h1><a href="index_php.php">The OWNag3 Gamer Site</a></h1> <p class="slogan">Get your Swag on<a href="http://www.freecsstemplates.org"></a></p> </div> </div> <div id="menu"> <ul> <li><a href="gameproducts.html">Game Products</a></li> <li><a href="events.html">events</a></li> <li><a href="videos.html">Videos</a></li> <li><a href="gameforum.html">Game Forum</a></li> <li><a href="affiliates.html"></a></li> </ul> </div> <div id="page"> <div id="sidebar"> <div class="box"> <h3>Login</h3> <form method="post" action="checklogin.php"> Username:<input type="text" name="username" /><br /> Password: <input type="password" name="password" /><br /> <input type="submit" value="Login" /> </form> <p> </p> <p> </p> <h3>The Game blog</h3> <p> Come share us all your top secrets to help pwn noobs on the battlefield. Show us your sick montage clips! </p> </div> </div> </div> <div id="content"> <?php $posts = get_posts(); foreach ($posts as $post){ ?> <h2><a href="blog_read.php?pid=<?php echo $post['id']; ?>"<?php echo $post['title']; ?></a></h2> <h4>By <?php echo $post['user']; ?> on <?php echo $post['date']; ?></h4> <h4>(<?php echo $post['total_comments']; ?> comments, last comment <?php echo $post['last_comment']; ?>)</h4> <hr /> <p><?php echo $post['preview']; ?></p> <?php } ?> <br class="clearfix" /> </div> <br class="clearfix" /> </div> </div> <div id="footer"> <p><a href="gameproducts.html">Game Products</a> | <a href="events.html">Events</a> | <a href="videos.html">Videos</a> | <a href="gameforum.html">Game Forums</a> | <a href="affiliates.html">Affiliates</a></p> <p> </p> </div> </body> </html>posts.inc
<?php function valid_pid($pid){ $pid = (int)$pid; $total = mysql_query("SELECT COUNT(`post_id`) FROM `posts` WHERE `post_id` = {$pid}"); $total = mysql_result($total, 0); if ($total != 1){ return false; } else{ return true; } } function get_posts(){ $sql = "SELECT `posts`.`post_id` AS `id`, `posts`.`post_title` AS `title`, LEFT(`posts`.`post_body`, 512) AS `preview`, `posts`.`post_user` AS `user`, DATE_FORMAT(`posts`.`post_date`, '%d/%m/%Y %H:%i:%s') AS `date`, `comments`.`total_comments`, DATE_FORMAT(`comments`.`last_comment`, '%d/%m/%Y %H:%i:%s') AS `last_comment` FROM `posts` LEFT JOIN ( SELECT `post_id`, COUNT(`comment_id`) AS `total_comments`, MAX(`comment_date`) AS `last_comment` FROM `comments` GROUP BY `post_id` ) AS `comments` ON `posts`.`post_id` = `comments`.`post_id` ORDER BY `posts`.`post_date` DESC"; $posts = mysql_query($sql); $rows = array(); while(($row = mysql_fetch_assoc($posts)) !== false){ $rows[] = array( 'id' => $row['id'], 'title' => $row['title'], 'preview' => $row['preview'], 'user' => $row['user'], 'date' => $row['date'], 'total_comments' =>($row['total_comments'] === null) ? 0 : $row['total_comments'], 'last_comment' =>($row['last_comment'] ===null) ? 'never' : $row['last_comment'] ); } return $rows; } function get_post($pid){ $pid = (int)$pid; $sql = "SELECT `post_title` AS `title`, `post_body` AS `body`, `post_user` AS `user`, `post_date` AS `date` FROM `posts` WHERE `post_id` = {$pid}"; $post = mysql_query($sql); $post = mysql_fetch_assoc($post); $post['comments'] = get_comments($pid); return $post; } function add_post($name, $title, $body){ $name = mysql_real_escape_string(htmlentities($name)); $title = mysql_real_escape_string(htmlentities($title)); $body = mysql_real_escape_string(nl2br(htmlentities($body))); mysql_query("INSERT INTO `posts` (`post_user`, `post_title`, `post_body`, `post_date`) VALUES ('{$name}', '{$title}', '{$body}', NOW())"); } ?>comments.inc
<?php function get_comments($pid){ $pid = (int)$pid; $sql = "SELECT `comment_body` AS `body`, `comment_user` AS `user`, DATE_FORMAT(`comment_date`, '%d/%m/%Y %H:%i:%s') AS `date` FROM `comments` WHERE `post_id` = {$pid}"; $comments = mysql_query($sql); $return = array(); while (($row = mysql_fetch_assoc($comments)) !== false){ $return[] = $row; } return $return; } function add_comment($pid, $user, $body){ if (valid_pid($pid) === false){ return false; } $pid = (int)$pud; $user = mysql_real_escape_string(htmlentities($user)); $body = mysql_real_escape_string(htmlentities($body)); mysql_query("INSERT INTO `comments` (`post_id`, `comment_user`, `comment_body`, `comment_date`) VALUES ({$pid}, '{$user}', '{$body}', NOW())"); return true; } ?>