type="submit" name="delete-comment[<?php echo $comment['id']; ?> ]" value="Delete" /> <?php } ?> </div> <div class="comment-body"> <?php // this is already escape ?> <?php echo convertNewlinesToParagraphs($comment['text']); ?> </div> </div> <?php } ?> </form>
<?php echo htmlEscape($row['title']); ?> </h2> <div class="date"> <?php echo convertSqlDate($row['created_at']); ?> </div> <?php // This is already escaped, so doesn't need further escaping ?> <?php echo convertNewlinesToParagraphs($row['body']); ?> </div> <?php require 'templates/list-comments.php'; ?> <?php // We use $commentData in this HTML fragment ?> <?php require 'templates/comment-form.php'; ?>