Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ad9a00fd49 | |||
| 42faab17e8 | |||
| 1da4842847 |
Generated
+1
-1
@@ -1,6 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="dataSourceStorageLocal" created-in="IU-253.32098.101">
|
||||
<component name="dataSourceStorageLocal" created-in="IU-261.25134.95">
|
||||
<data-source name="articles" uuid="315cb5c9-2b0f-435b-b602-59823b160908">
|
||||
<database-info product="SQLite" version="3.51.1" jdbc-version="4.2" driver-name="SQLite JDBC" driver-version="3.51.1.0" dbms="SQLITE" exact-version="3.51.1" exact-driver-version="3.51">
|
||||
<identifier-quote-string>"</identifier-quote-string>
|
||||
|
||||
+10
-12
@@ -81,12 +81,10 @@ $isEditMode = (isset($_GET["edit"]) && $_GET["edit"] === "1") || !empty($error);
|
||||
|
||||
<br>
|
||||
|
||||
<form action="php/controller/deleteAccount-controller.php"
|
||||
method="POST"
|
||||
class="confirm-delete-account">
|
||||
|
||||
<form action="php/controller/deleteAccount-controller.php" method="POST">
|
||||
<button type="submit"
|
||||
class="button">
|
||||
class="button"
|
||||
onclick="return confirm('Möchtest du deinen Account und alle deine Beiträge wirklich unwiderruflich löschen?');">
|
||||
Account löschen
|
||||
</button>
|
||||
</form>
|
||||
@@ -156,16 +154,14 @@ $isEditMode = (isset($_GET["edit"]) && $_GET["edit"] === "1") || !empty($error);
|
||||
Bearbeiten
|
||||
</a>
|
||||
|
||||
<form action="php/controller/deleteArticle-controller.php"
|
||||
method="POST"
|
||||
class="confirm-delete-article">
|
||||
|
||||
<form action="php/controller/deleteArticle-controller.php" method="POST">
|
||||
<input type="hidden"
|
||||
name="id"
|
||||
value="<?php echo htmlspecialchars($userArticle->getID()); ?>">
|
||||
|
||||
<button type="submit"
|
||||
class="button">
|
||||
class="button"
|
||||
onclick="return confirm('Möchtest du diesen Artikel wirklich löschen?');">
|
||||
Löschen
|
||||
</button>
|
||||
</form>
|
||||
@@ -176,9 +172,11 @@ $isEditMode = (isset($_GET["edit"]) && $_GET["edit"] === "1") || !empty($error);
|
||||
|
||||
<p>Du hast noch keine Beiträge erstellt.</p>
|
||||
|
||||
<a href="index.php?pfad=createArticle" class="button">
|
||||
<button type="button"
|
||||
class="button"
|
||||
onclick="window.location.href='index.php?pfad=createArticle';">
|
||||
Beitrag erstellen!
|
||||
</a>
|
||||
</button>
|
||||
|
||||
<?php endif; ?>
|
||||
</div>
|
||||
|
||||
@@ -124,9 +124,7 @@ $categories = [
|
||||
</div>
|
||||
|
||||
<noscript>
|
||||
<button type="submit" class="nav__search-button">
|
||||
Filter anwenden
|
||||
</button>
|
||||
<button type="submit" class="nav__search-button">Filter anwenden</button>
|
||||
</noscript>
|
||||
</form>
|
||||
|
||||
@@ -195,34 +193,17 @@ $categories = [
|
||||
</div>
|
||||
|
||||
<nav class="s-res-page-navigation" aria-label="Seitennavigation">
|
||||
|
||||
<!-- No-JS-Fallback: -->
|
||||
<noscript>
|
||||
<?php echo renderNoJsPagination(
|
||||
$currentPage,
|
||||
$totalPages,
|
||||
$query,
|
||||
$currentSort,
|
||||
$currentCategory,
|
||||
$limit
|
||||
); ?>
|
||||
<?php echo renderNoJsPagination($currentPage, $totalPages, $query, $currentSort, $currentCategory, $limit); ?>
|
||||
</noscript>
|
||||
|
||||
<!-- JS-Version: wird per search-results.js befüllt/eingeblendet: -->
|
||||
<div id="js-page-navigation" style="display:none;">
|
||||
<button type="button"
|
||||
class="s-res-page-btn"
|
||||
id="prev-page-btn">
|
||||
«
|
||||
</button>
|
||||
|
||||
<button type="button" class="s-res-page-btn" id="prev-page-btn">«</button>
|
||||
<span id="dynamic-page-numbers"></span>
|
||||
|
||||
<button type="button"
|
||||
class="s-res-page-btn"
|
||||
id="next-page-btn">
|
||||
»
|
||||
</button>
|
||||
<button type="button" class="s-res-page-btn" id="next-page-btn">»</button>
|
||||
</div>
|
||||
|
||||
</nav>
|
||||
|
||||
</div>
|
||||
|
||||
@@ -237,7 +237,7 @@ if ($replyAuthor === null) {
|
||||
|
||||
<form method="post"
|
||||
action="index.php?pfad=deleteComment"
|
||||
class="delete-comment-form confirm-delete-comment">
|
||||
class="delete-comment-form">
|
||||
|
||||
<input type="hidden"
|
||||
name="comment_id"
|
||||
@@ -252,7 +252,8 @@ if ($replyAuthor === null) {
|
||||
); ?>">
|
||||
|
||||
<button type="submit"
|
||||
class="delete-comment-button">
|
||||
class="delete-comment-button"
|
||||
onclick="return confirm('Möchtest du diesen Kommentar wirklich löschen?');">
|
||||
Kommentar löschen
|
||||
</button>
|
||||
</form>
|
||||
@@ -368,7 +369,7 @@ if ($replyAuthor === null) {
|
||||
|
||||
<form method="post"
|
||||
action="index.php?pfad=deleteComment"
|
||||
class="delete-comment-form confirm-delete-comment">
|
||||
class="delete-comment-form">
|
||||
|
||||
<input type="hidden"
|
||||
name="comment_id"
|
||||
@@ -383,8 +384,9 @@ if ($replyAuthor === null) {
|
||||
); ?>">
|
||||
|
||||
<button type="submit"
|
||||
class="delete-comment-button">
|
||||
Antwort löschen
|
||||
class="delete-comment-button"
|
||||
onclick="return confirm('Möchtest du diesen Kommentar wirklich löschen?');">
|
||||
Kommentar löschen
|
||||
</button>
|
||||
</form>
|
||||
|
||||
|
||||
@@ -89,6 +89,12 @@
|
||||
Es ist ein Datenbankfehler aufgetreten. Bitte versuche es erneut.
|
||||
</p>
|
||||
<?php endif; ?>
|
||||
<?php if (isset($_SESSION["message"]) && $_SESSION["message"] == "invalid_csrf_token"): ?>
|
||||
<p class="alert-message is-error">
|
||||
Deine Sitzung ist abgelaufen oder die Anfrage konnte nicht überprüft werden.
|
||||
Bitte lade die Seite neu und versuche es erneut.
|
||||
</p>
|
||||
<?php endif; ?>
|
||||
<?php
|
||||
unset($_SESSION["message"]);
|
||||
?>
|
||||
@@ -0,0 +1,88 @@
|
||||
<?php
|
||||
/**
|
||||
* CSRF-Schutz nach dem Synchronizer-Token-Pattern.
|
||||
*
|
||||
* Pro Session wird ein einziges, zufälliges Token erzeugt,
|
||||
* das in jedem Formular als verstecktes Feld mitgeschickt und bei jeder
|
||||
* zustandsändernden Anfrage serverseitig mit dem Session-Token verglichen
|
||||
* wird.
|
||||
*
|
||||
* @author Niklas Ortmann
|
||||
*/
|
||||
|
||||
if (session_status() === PHP_SESSION_NONE) {
|
||||
session_start();
|
||||
}
|
||||
|
||||
/**
|
||||
* Gibt das aktuelle CSRF-Token der Session zurück.
|
||||
*
|
||||
* Existiert noch kein Token, wird eines erzeugt und in der Session
|
||||
* gespeichert.
|
||||
*
|
||||
* @return string Das CSRF-Token
|
||||
*/
|
||||
function csrf_token(): string
|
||||
{
|
||||
if (empty($_SESSION["csrf_token"]) || !is_string($_SESSION["csrf_token"])) {
|
||||
$_SESSION["csrf_token"] = bin2hex(random_bytes(32));
|
||||
}
|
||||
|
||||
return $_SESSION["csrf_token"];
|
||||
}
|
||||
|
||||
/**
|
||||
* Gibt ein verstecktes Formularfeld mit dem aktuellen CSRF-Token aus.
|
||||
*
|
||||
* Wird in jedem Formular benötigt, das eine zustandsändernde
|
||||
* Aktion auslöst.
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
function csrf_field(): void
|
||||
{
|
||||
echo '<input type="hidden" name="csrf_token" value="'
|
||||
. htmlspecialchars(csrf_token())
|
||||
. '">';
|
||||
}
|
||||
|
||||
/**
|
||||
* Prüft, ob das per POST gesendete CSRF-Token zum Session-Token passt.
|
||||
*
|
||||
* Der Vergleich erfolgt zeitkonstant über hash_equals(), um
|
||||
* Timing-Angriffe auf den Vergleich selbst auszuschließen.
|
||||
*
|
||||
* @return bool true, wenn das Token gültig ist
|
||||
*/
|
||||
function csrf_verify(): bool
|
||||
{
|
||||
$sentToken = $_POST["csrf_token"] ?? "";
|
||||
$sessionToken = $_SESSION["csrf_token"] ?? "";
|
||||
|
||||
if (!is_string($sentToken) || $sentToken === "" || $sessionToken === "") {
|
||||
return false;
|
||||
}
|
||||
|
||||
return hash_equals($sessionToken, $sentToken);
|
||||
}
|
||||
|
||||
/**
|
||||
* Bricht die Anfrage ab und leitet mit einer Fehlermeldung um,
|
||||
* wenn das mitgesendete CSRF-Token ungültig oder nicht vorhanden ist.
|
||||
*
|
||||
* Muss am Anfang jeder zustandsändernden POST-Aktion aufgerufen werden,
|
||||
* bevor irgendeine Änderung an Daten vorgenommen wird.
|
||||
*
|
||||
* @param string $redirectTo Ziel-URL, zu der bei ungültigem Token
|
||||
* weitergeleitet wird
|
||||
* @return void
|
||||
*/
|
||||
function csrf_require_valid(string $redirectTo = "index.php"): void
|
||||
{
|
||||
if (!csrf_verify()) {
|
||||
http_response_code(403);
|
||||
$_SESSION["message"] = "invalid_csrf_token";
|
||||
header("Location: " . $redirectTo);
|
||||
exit();
|
||||
}
|
||||
}
|
||||
@@ -2,6 +2,7 @@
|
||||
if (session_status() === PHP_SESSION_NONE) {
|
||||
session_start();
|
||||
}
|
||||
include_once "includes/csrf.php";
|
||||
include_once "php/controller/index-controller.php";
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
@@ -24,10 +25,9 @@ include_once "php/controller/index-controller.php";
|
||||
<link rel="stylesheet" href="css/showCategory.css">
|
||||
|
||||
<script src="js/comments.js" defer></script>
|
||||
<script src="js/profile.js" defer></script>
|
||||
<script src="js/editor.js" async></script>
|
||||
<script src="js/search-results.js" async></script>
|
||||
<script src="js/showCategory.js" async></script>
|
||||
<script src="js/search.js" async></script>
|
||||
|
||||
|
||||
<title>EduForge</title>
|
||||
|
||||
+2
-20
@@ -11,26 +11,6 @@ document.addEventListener("DOMContentLoaded", function () {
|
||||
const parentCommentInput = document.getElementById("parent-comment-id");
|
||||
const replyInfo = document.getElementById("reply-info");
|
||||
|
||||
/**
|
||||
* Fragt vor dem Löschen eines Kommentars nach einer Bestätigung.
|
||||
*
|
||||
* Der Listener funktioniert auch für Kommentare,
|
||||
* die später per AJAX eingefügt werden.
|
||||
*/
|
||||
document.addEventListener("submit", function (event) {
|
||||
if (!event.target.classList.contains("delete-comment-form")) {
|
||||
return;
|
||||
}
|
||||
|
||||
const confirmed = confirm(
|
||||
"Möchtest du diesen Kommentar wirklich löschen?"
|
||||
);
|
||||
|
||||
if (!confirmed) {
|
||||
event.preventDefault();
|
||||
}
|
||||
});
|
||||
|
||||
if (!form || !commentsList || !commentContent || !parentCommentInput) {
|
||||
return;
|
||||
}
|
||||
@@ -172,6 +152,7 @@ document.addEventListener("DOMContentLoaded", function () {
|
||||
<button
|
||||
type="submit"
|
||||
class="delete-comment-button"
|
||||
onclick="return confirm('Möchtest du diesen Kommentar wirklich löschen?');"
|
||||
>
|
||||
Kommentar löschen
|
||||
</button>
|
||||
@@ -249,6 +230,7 @@ document.addEventListener("DOMContentLoaded", function () {
|
||||
<button
|
||||
type="submit"
|
||||
class="delete-comment-button"
|
||||
onclick="return confirm('Möchtest du diesen Kommentar wirklich löschen?');"
|
||||
>
|
||||
Kommentar löschen
|
||||
</button>
|
||||
|
||||
@@ -1,29 +0,0 @@
|
||||
document.addEventListener("DOMContentLoaded", function () {
|
||||
|
||||
const deleteAccountForm = document.querySelector(".confirm-delete-account");
|
||||
|
||||
if (deleteAccountForm) {
|
||||
deleteAccountForm.addEventListener("submit", function (event) {
|
||||
|
||||
if (!confirm("Möchtest du deinen Account und alle deine Beiträge wirklich unwiderruflich löschen?")) {
|
||||
event.preventDefault();
|
||||
}
|
||||
|
||||
});
|
||||
}
|
||||
|
||||
const deleteArticleForms = document.querySelectorAll(".confirm-delete-article");
|
||||
|
||||
deleteArticleForms.forEach(function (form) {
|
||||
|
||||
form.addEventListener("submit", function (event) {
|
||||
|
||||
if (!confirm("Möchtest du diesen Artikel wirklich löschen?")) {
|
||||
event.preventDefault();
|
||||
}
|
||||
|
||||
});
|
||||
|
||||
});
|
||||
|
||||
});
|
||||
@@ -315,15 +315,16 @@ class DatabaseArticleManager implements ArticleManagerDAO {
|
||||
FROM articles
|
||||
WHERE title LIKE :keyword
|
||||
OR content LIKE :keyword
|
||||
OR tags LIKE :keyword;";
|
||||
OR tags LIKE :keyword";
|
||||
|
||||
$command = $db->prepare($sql);
|
||||
if (!$command) {
|
||||
throw new InternalServerErrorException("internal_error");
|
||||
}
|
||||
|
||||
// Wildcards für die SQL-Suche hinzufügen
|
||||
// Wildcards für die Suche hinzufügen
|
||||
$searchParam = '%' . $cleankeyword . '%';
|
||||
|
||||
$success = $command->execute([
|
||||
":keyword" => $searchParam
|
||||
]);
|
||||
@@ -336,11 +337,10 @@ class DatabaseArticleManager implements ArticleManagerDAO {
|
||||
$filteredArticles = [];
|
||||
|
||||
foreach ($rows as $row) {
|
||||
$articleId = intval($row['id']);
|
||||
$likes = $this->getLikesForArticle($articleId);
|
||||
$likes = $this->getLikesForArticle(intval($row['id']));
|
||||
|
||||
$filteredArticles[] = new Article(
|
||||
$articleId,
|
||||
intval($row['id']),
|
||||
$row['title'] ?? '',
|
||||
$row['content'] ?? '',
|
||||
$row['author'] ?? '',
|
||||
@@ -358,7 +358,6 @@ class DatabaseArticleManager implements ArticleManagerDAO {
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Holt alle User-IDs, die einen bestimmten Beitrag geliked haben.
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user