コード例 #1
0
ファイル: interests.php プロジェクト: Groscheri/csrf-seminar
$interests = interest::get_by_user($_SESSION['user']['id']);
if (!is_array($interests) || count($interests) == 0) {
    ?>
<p>No interest at the moment!</p>
<?php 
} else {
    echo '<ul>';
    foreach ($interests as $interest) {
        $id = $interest['id'];
        $name = $interest['name'];
        $description = $interest['description'];
        echo '<li>' . $name . ': ' . $description . ' <a href=\'?p=interests&action=remove&id=' . $id . '\' title=\'Remove this interest\'>Remove</a></li>';
    }
    echo '</ul>';
}
?>

<h3>Create new interest</h3>

<form method="POST" action="?p=interests&action=add">
<input type="hidden" name="csrf_token" value="<?php 
echo csrf::generate_signed_token();
?>
" />
<label for="name">Name: </label><input type="text" name="name" id="name" /><br />
<label for="description">Description: </label><br />
<textarea name="description" placeholder="Description optional"></textarea>
<br />
<input type="submit" value="Create interest" />
</form>