Beispiel #1
0
    echo wikimenu();
    echo "</div>";
    echo "</div>";
}
if ($action == "edit") {
    $res = sql_query("SELECT * FROM wiki WHERE id = {$id}");
    $rescheck = sql_query("SELECT userid FROM wiki WHERE id = {$id}");
    $wikicheck = mysql_fetch_assoc($rescheck);
    if (get_user_class() >= UC_MODERATOR or $CURUSER["id"] == $wikicheck["userid"]) {
        echo navmenu();
        echo "<div id=\"wiki-container\">\r\n  <div id=\"wiki-row\">";
        while ($wiki = mysql_fetch_array($res)) {
            echo "\r\n\t\t\t\t<div id=\"wiki-content-left\" align=\"right\">\r\n\t\t\t\t\t<form method=\"post\" action=\"wiki.php\">\r\n\t\t\t\t\t<div id=\"name\"><input type=\"hidden\" name=\"article-id\" value=\"{$wiki['id']}\">\r\n\t\t\t\t\t<input type=\"text\" name=\"article-name\" id=\"name\" value=\"{$wiki['name']}\"></div>\r\n\t\t\t\t\t<div id=\"content-add\"><table width=100% height=100% id=\"wikiedit\" border=0 cellpadding=0 cellspacing=0><tr><td><textarea name=\"article-body\" id=\"body\">{$wiki['body']}</textarea>\r\n\t\t\t\t\t<div align=\"center\"><input type=\"submit\" name=\"article-edit\" value=\"Edit\"> <input type=\"button\" value=\"Preview\" onclick=\"editPreview()\" /></div></td></tr></table>";
            echo "</div></form></div>";
        }
        echo wikimenu();
        echo "</div>";
        echo "</div>";
    } else {
        newerr("Error", "Access Denied");
    }
}
if ($action == "sort") {
    $sortres = sql_query("SELECT * FROM wiki WHERE name LIKE '{$letter}%' ORDER BY name");
    if (mysql_num_rows($sortres) > 0) {
        echo navmenu();
        echo "Articles starting with the letter <b>{$letter}</b>";
        while ($wiki = mysql_fetch_array($sortres)) {
            if ($wiki["userid"] !== 0) {
                $wikiname = mysql_fetch_assoc(sql_query("SELECT username FROM users WHERE id = {$wiki['userid']}"));
            }
Beispiel #2
0
    $HTMLOUT .= wikimenu();
    $HTMLOUT .= "</div>";
    $HTMLOUT .= "</div>";
}
if ($action == "edit") {
    $res = sql_query("SELECT * FROM wiki WHERE id = " . sqlesc($id));
    $rescheck = sql_query("SELECT userid FROM wiki WHERE id =" . sqlesc($id));
    $wikicheck = mysqli_fetch_assoc($rescheck);
    if ($CURUSER['class'] >= UC_STAFF or $CURUSER["id"] == $wikicheck["userid"]) {
        $HTMLOUT .= navmenu();
        $HTMLOUT .= "<div id=\"wiki-container\">\n  <div id=\"wiki-row\">";
        while ($wiki = mysqli_fetch_array($res)) {
            $HTMLOUT .= "\n\t\t\t\t<div id=\"wiki-content-left\" align=\"right\">\n\t\t\t\t\t<form method=\"post\" action=\"wiki.php\">\n\t\t\t\t\t<div><input type=\"hidden\" name=\"article-id\" value=\"" . (int) $wiki['id'] . "\" />\n\t\t\t\t\t<input type=\"text\" name=\"article-name\" id=\"name\" value=\"" . htmlsafechars($wiki['name']) . "\" /></div>\n\t\t\t\t\t<div id=\"content-add\"><table width=\"100%\" style=\"height: 100%;\" id=\"wikiedit\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\"><tr><td><textarea name=\"article-body\" rows=\"70\" cols=\"10\" id=\"body\">" . htmlsafechars($wiki['body']) . "</textarea>\n\t\t\t\t\t<div align=\"center\"><input type=\"submit\" name=\"article-edit\" value=\"Edit\" /></div></td></tr></table>";
            $HTMLOUT .= "</div></form></div>";
        }
        $HTMLOUT .= wikimenu();
        $HTMLOUT .= "</div>";
        $HTMLOUT .= "</div>";
    } else {
        $HTMLOUT .= newerr("Error", "Access Denied");
    }
}
if ($action == "sort") {
    $sortres = sql_query("SELECT * FROM wiki WHERE name LIKE '{$letter}%' ORDER BY name");
    if (mysqli_num_rows($sortres) > 0) {
        $HTMLOUT .= navmenu();
        $HTMLOUT .= "Articles starting with the letter <b>" . htmlsafechars($letter) . "</b>";
        while ($wiki = mysqli_fetch_array($sortres)) {
            if ($wiki["userid"] !== 0) {
                $wikiname = mysqli_fetch_assoc(sql_query("SELECT username FROM users WHERE id = " . sqlesc($wiki['userid'])));
            }