Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ad9a00fd49 | |||
| 42faab17e8 | |||
| 1da4842847 |
Generated
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
<?xml version="1.0" encoding="UTF-8"?>
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
<project version="4">
|
<project version="4">
|
||||||
<component name="dataSourceStorageLocal" created-in="IU-253.32098.101">
|
<component name="dataSourceStorageLocal" created-in="IU-261.25134.95">
|
||||||
<data-source name="articles" uuid="315cb5c9-2b0f-435b-b602-59823b160908">
|
<data-source name="articles" uuid="315cb5c9-2b0f-435b-b602-59823b160908">
|
||||||
<database-info product="SQLite" version="3.51.1" jdbc-version="4.2" driver-name="SQLite JDBC" driver-version="3.51.1.0" dbms="SQLITE" exact-version="3.51.1" exact-driver-version="3.51">
|
<database-info product="SQLite" version="3.51.1" jdbc-version="4.2" driver-name="SQLite JDBC" driver-version="3.51.1.0" dbms="SQLITE" exact-version="3.51.1" exact-driver-version="3.51">
|
||||||
<identifier-quote-string>"</identifier-quote-string>
|
<identifier-quote-string>"</identifier-quote-string>
|
||||||
|
|||||||
+2
-40
@@ -5,30 +5,6 @@ $repliesByParent = [];
|
|||||||
$articleObj = null;
|
$articleObj = null;
|
||||||
|
|
||||||
include_once 'php/controller/showArticle-controller.php';
|
include_once 'php/controller/showArticle-controller.php';
|
||||||
require_once 'php/model/UserManager.php';
|
|
||||||
|
|
||||||
$userManager = UserManager::getInstance();
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Liefert den vollständigen Namen zu einer gespeicherten E-Mail-Adresse.
|
|
||||||
* Falls kein Benutzer gefunden wird, wird die E-Mail als Ersatz angezeigt.
|
|
||||||
*/
|
|
||||||
function getCommentAuthorName($email, $userManager)
|
|
||||||
{
|
|
||||||
$email = trim($email);
|
|
||||||
$user = $userManager->findUser($email);
|
|
||||||
|
|
||||||
if ($user === null) {
|
|
||||||
return $email;
|
|
||||||
}
|
|
||||||
|
|
||||||
$vorname = trim($user["vorname"] ?? "");
|
|
||||||
$nachname = trim($user["nachname"] ?? "");
|
|
||||||
|
|
||||||
$fullName = trim($vorname . " " . $nachname);
|
|
||||||
|
|
||||||
return $fullName !== "" ? $fullName : $email;
|
|
||||||
}
|
|
||||||
/*
|
/*
|
||||||
* Ermittelt, ob ohne JavaScript auf einen Kommentar
|
* Ermittelt, ob ohne JavaScript auf einen Kommentar
|
||||||
* geantwortet werden soll.
|
* geantwortet werden soll.
|
||||||
@@ -197,14 +173,7 @@ if ($replyAuthor === null) {
|
|||||||
|
|
||||||
<p>
|
<p>
|
||||||
<strong>
|
<strong>
|
||||||
<?php
|
<?php echo htmlspecialchars($comment->getAuthor()); ?>
|
||||||
echo htmlspecialchars(
|
|
||||||
getCommentAuthorName(
|
|
||||||
$comment->getAuthor(),
|
|
||||||
$userManager
|
|
||||||
)
|
|
||||||
);
|
|
||||||
?>
|
|
||||||
</strong>
|
</strong>
|
||||||
|
|
||||||
<span>
|
<span>
|
||||||
@@ -335,14 +304,7 @@ if ($replyAuthor === null) {
|
|||||||
|
|
||||||
<p>
|
<p>
|
||||||
<strong>
|
<strong>
|
||||||
<?php
|
<?php echo htmlspecialchars($reply->getAuthor()); ?>
|
||||||
echo htmlspecialchars(
|
|
||||||
getCommentAuthorName(
|
|
||||||
$reply->getAuthor(),
|
|
||||||
$userManager
|
|
||||||
)
|
|
||||||
);
|
|
||||||
?>
|
|
||||||
</strong>
|
</strong>
|
||||||
|
|
||||||
<span>
|
<span>
|
||||||
|
|||||||
+5
-194
@@ -154,32 +154,21 @@ h1 {
|
|||||||
|
|
||||||
.button {
|
.button {
|
||||||
width: 100%;
|
width: 100%;
|
||||||
padding: 14px;
|
padding: 12px;
|
||||||
background-color: #2563eb;
|
background-color: #2563eb;
|
||||||
color: white;
|
color: white;
|
||||||
border: 2px solid transparent;
|
border: none;
|
||||||
border-radius: 8px;
|
border-radius: 8px;
|
||||||
font-size: 1rem;
|
font-size: 1rem;
|
||||||
font-weight: bold;
|
font-weight: bold;
|
||||||
cursor: pointer;
|
cursor: pointer;
|
||||||
transition:
|
transition: background-color 0.2s, transform 0.2s, box-shadow 0.2s;
|
||||||
background-color 0.2s ease,
|
|
||||||
transform 0.2s ease,
|
|
||||||
box-shadow 0.2s ease,
|
|
||||||
border-color 0.2s ease;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
.button:hover {
|
.button:hover {
|
||||||
background-color: #1e40af;
|
|
||||||
border-color: #93c5fd;
|
|
||||||
transform: translateY(-3px) scale(1.01);
|
|
||||||
box-shadow: 0 8px 18px rgba(37, 99, 235, 0.35);
|
|
||||||
}
|
|
||||||
|
|
||||||
.button:active {
|
|
||||||
background-color: #1d4ed8;
|
background-color: #1d4ed8;
|
||||||
transform: translateY(1px) scale(0.99);
|
transform: translateY(-2px);
|
||||||
box-shadow: 0 2px 5px rgba(37, 99, 235, 0.25);
|
box-shadow: 0 4px 10px rgba(0,0,0,0.15);
|
||||||
}
|
}
|
||||||
|
|
||||||
.register-link {
|
.register-link {
|
||||||
@@ -236,182 +225,4 @@ h1 {
|
|||||||
text-align: center;
|
text-align: center;
|
||||||
text-decoration: none;
|
text-decoration: none;
|
||||||
box-sizing: border-box;
|
box-sizing: border-box;
|
||||||
}
|
|
||||||
|
|
||||||
/* Deutlichere Klickreaktion für Kategorien */
|
|
||||||
.category-link:active {
|
|
||||||
transform: translateY(1px);
|
|
||||||
box-shadow: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Sichtbare Tastatur-Markierung */
|
|
||||||
.button:focus-visible,
|
|
||||||
.category-link:focus-visible,
|
|
||||||
.article-link a:focus-visible,
|
|
||||||
.register-link a:focus-visible {
|
|
||||||
outline: 3px solid #fbbf24;
|
|
||||||
outline-offset: 3px;
|
|
||||||
}
|
|
||||||
/* Kommentarbereich */
|
|
||||||
|
|
||||||
#comments-list {
|
|
||||||
display: flex;
|
|
||||||
flex-direction: column;
|
|
||||||
gap: 20px;
|
|
||||||
margin-bottom: 40px;
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list > div,
|
|
||||||
.comment {
|
|
||||||
background-color: #ffffff;
|
|
||||||
border: 1px solid #dbe3ec;
|
|
||||||
border-radius: 12px;
|
|
||||||
padding: 24px;
|
|
||||||
box-shadow: 0 4px 12px rgba(0, 0, 0, 0.06);
|
|
||||||
transition:
|
|
||||||
transform 0.2s ease,
|
|
||||||
box-shadow 0.2s ease,
|
|
||||||
border-color 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list > div:hover,
|
|
||||||
.comment:hover {
|
|
||||||
transform: translateY(-3px);
|
|
||||||
border-color: #93c5fd;
|
|
||||||
box-shadow: 0 8px 20px rgba(0, 0, 0, 0.12);
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list textarea,
|
|
||||||
#comment-content {
|
|
||||||
width: 100%;
|
|
||||||
box-sizing: border-box;
|
|
||||||
padding: 14px;
|
|
||||||
border: 1px solid #cbd5e1;
|
|
||||||
border-radius: 8px;
|
|
||||||
font-size: 1rem;
|
|
||||||
resize: vertical;
|
|
||||||
transition:
|
|
||||||
border-color 0.2s ease,
|
|
||||||
box-shadow 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list textarea:focus,
|
|
||||||
#comment-content:focus {
|
|
||||||
outline: none;
|
|
||||||
border-color: #2563eb;
|
|
||||||
box-shadow: 0 0 0 4px rgba(37, 99, 235, 0.18);
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list a {
|
|
||||||
color: #2563eb;
|
|
||||||
font-weight: bold;
|
|
||||||
text-decoration: none;
|
|
||||||
border-radius: 4px;
|
|
||||||
transition:
|
|
||||||
color 0.2s ease,
|
|
||||||
background-color 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list a:hover {
|
|
||||||
color: #1e40af;
|
|
||||||
background-color: #dbeafe;
|
|
||||||
text-decoration: underline;
|
|
||||||
}
|
|
||||||
|
|
||||||
#comments-list button {
|
|
||||||
cursor: pointer;
|
|
||||||
}
|
|
||||||
.delete-comment-button {
|
|
||||||
display: inline-block;
|
|
||||||
background: #ffffff;
|
|
||||||
color: #dc2626;
|
|
||||||
border: 2px solid #dc2626;
|
|
||||||
border-radius: 8px;
|
|
||||||
padding: 10px 18px;
|
|
||||||
font-size: 0.95rem;
|
|
||||||
font-weight: 600;
|
|
||||||
cursor: pointer;
|
|
||||||
transition:
|
|
||||||
background-color 0.25s ease,
|
|
||||||
color 0.25s ease,
|
|
||||||
transform 0.2s ease,
|
|
||||||
box-shadow 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
.delete-comment-button:hover {
|
|
||||||
background: #dc2626;
|
|
||||||
color: #ffffff;
|
|
||||||
transform: translateY(-2px);
|
|
||||||
box-shadow: 0 6px 14px rgba(220,38,38,0.25);
|
|
||||||
}
|
|
||||||
|
|
||||||
.delete-comment-button:active {
|
|
||||||
transform: translateY(1px);
|
|
||||||
box-shadow: none;
|
|
||||||
}
|
|
||||||
.delete-comment-form {
|
|
||||||
margin-top: 12px;
|
|
||||||
margin-bottom: 12px;
|
|
||||||
}
|
|
||||||
/* Button zum Öffnen der Kommentarbearbeitung */
|
|
||||||
.edit-comment-button {
|
|
||||||
display: inline-block;
|
|
||||||
width: auto;
|
|
||||||
padding: 10px 18px;
|
|
||||||
background-color: #2563eb;
|
|
||||||
color: #ffffff;
|
|
||||||
border: 2px solid #2563eb;
|
|
||||||
border-radius: 8px;
|
|
||||||
font-size: 0.95rem;
|
|
||||||
font-weight: 600;
|
|
||||||
cursor: pointer;
|
|
||||||
list-style: none;
|
|
||||||
transition:
|
|
||||||
background-color 0.2s ease,
|
|
||||||
border-color 0.2s ease,
|
|
||||||
transform 0.2s ease,
|
|
||||||
box-shadow 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Entfernt das normale Dreieck in einigen Browsern */
|
|
||||||
.edit-comment-button::-webkit-details-marker {
|
|
||||||
display: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Eigenes Symbol vor dem Text */
|
|
||||||
.edit-comment-button::before {
|
|
||||||
content: "✏ ";
|
|
||||||
}
|
|
||||||
|
|
||||||
.edit-comment-button:hover {
|
|
||||||
background-color: #1e40af;
|
|
||||||
border-color: #1e40af;
|
|
||||||
transform: translateY(-2px);
|
|
||||||
box-shadow: 0 5px 12px rgba(37, 99, 235, 0.3);
|
|
||||||
}
|
|
||||||
|
|
||||||
.edit-comment-button:active {
|
|
||||||
transform: translateY(1px);
|
|
||||||
box-shadow: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.edit-comment-button:focus-visible {
|
|
||||||
outline: 3px solid #fbbf24;
|
|
||||||
outline-offset: 3px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Abstand zwischen Bearbeiten und Löschen */
|
|
||||||
.edit-comment-details {
|
|
||||||
margin-bottom: 12px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Geöffneter Bearbeitungsbereich */
|
|
||||||
.edit-comment-details[open] .edit-comment-button {
|
|
||||||
margin-bottom: 12px;
|
|
||||||
background-color: #1e40af;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Geändertes Symbol, wenn der Bereich geöffnet ist */
|
|
||||||
.edit-comment-details[open] .edit-comment-button::before {
|
|
||||||
content: "▲ ";
|
|
||||||
}
|
}
|
||||||
+3
-87
@@ -248,9 +248,9 @@ CSS für die navbar
|
|||||||
z-index: 1000;
|
z-index: 1000;
|
||||||
transition: left 0.3s ease;
|
transition: left 0.3s ease;
|
||||||
padding: 2rem 1rem;
|
padding: 2rem 1rem;
|
||||||
box-shadow: 2px 0 10px rgba(0, 0, 0, 0.5);
|
box-shadow: 2px 0 10px rgba(0,0,0,0.5);
|
||||||
overflow-y: auto;
|
overflow-y: auto;
|
||||||
|
|
||||||
/* Genug Abstand oben rechts, damit Links nicht hinter dem X liegen */
|
/* Genug Abstand oben rechts, damit Links nicht hinter dem X liegen */
|
||||||
padding: 4rem 1.5rem 2rem 1.5rem;
|
padding: 4rem 1.5rem 2rem 1.5rem;
|
||||||
}
|
}
|
||||||
@@ -302,89 +302,5 @@ CSS für die navbar
|
|||||||
padding: 0.8rem 1rem;
|
padding: 0.8rem 1rem;
|
||||||
cursor: pointer;
|
cursor: pointer;
|
||||||
}
|
}
|
||||||
}
|
|
||||||
/* Deutlichere Hover-Effekte für die Navigation */
|
|
||||||
|
|
||||||
.nav__dropdown-toggle,
|
}
|
||||||
.nav__link {
|
|
||||||
border-radius: 6px;
|
|
||||||
transition:
|
|
||||||
background-color 0.2s ease,
|
|
||||||
color 0.2s ease,
|
|
||||||
transform 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
.nav__dropdown-toggle:hover,
|
|
||||||
.nav__link:hover {
|
|
||||||
background-color: #ffffff;
|
|
||||||
color: #1d4ed8;
|
|
||||||
transform: translateY(-2px);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Sichtbare Reaktion beim Anklicken */
|
|
||||||
.nav__dropdown-toggle:active,
|
|
||||||
.nav__link:active {
|
|
||||||
transform: translateY(1px);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Deutlichere Effekte für Anmelden, Registrieren usw. */
|
|
||||||
.nav__button {
|
|
||||||
transition:
|
|
||||||
background-color 0.2s ease,
|
|
||||||
color 0.2s ease,
|
|
||||||
transform 0.2s ease,
|
|
||||||
box-shadow 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
.nav__button:hover {
|
|
||||||
background-color: #2563eb;
|
|
||||||
color: #ffffff;
|
|
||||||
transform: translateY(-2px);
|
|
||||||
box-shadow: 0 4px 10px rgba(0, 0, 0, 0.3);
|
|
||||||
}
|
|
||||||
|
|
||||||
.nav__button:active {
|
|
||||||
transform: translateY(1px);
|
|
||||||
box-shadow: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Deutlichere Hervorhebung der Einträge im Dropdown-Menü */
|
|
||||||
.nav__dropdown-menu a {
|
|
||||||
display: block;
|
|
||||||
transition:
|
|
||||||
background-color 0.2s ease,
|
|
||||||
color 0.2s ease,
|
|
||||||
padding-left 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
.nav__dropdown-menu a:hover {
|
|
||||||
background-color: #dbeafe;
|
|
||||||
color: #1d4ed8;
|
|
||||||
padding-left: 1.4rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Effekt für den Suchbutton */
|
|
||||||
.nav__search-button {
|
|
||||||
transition:
|
|
||||||
background-color 0.2s ease,
|
|
||||||
color 0.2s ease,
|
|
||||||
transform 0.2s ease;
|
|
||||||
}
|
|
||||||
|
|
||||||
.nav__search-button:hover {
|
|
||||||
background-color: #2563eb;
|
|
||||||
color: #ffffff;
|
|
||||||
}
|
|
||||||
|
|
||||||
.nav__search-button:active {
|
|
||||||
transform: scale(0.95);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Sichtbare Markierung bei Tastaturbedienung */
|
|
||||||
.nav a:focus-visible,
|
|
||||||
.nav button:focus-visible,
|
|
||||||
.nav input:focus-visible,
|
|
||||||
.nav label:focus-visible {
|
|
||||||
outline: 3px solid #fbbf24;
|
|
||||||
outline-offset: 3px;
|
|
||||||
}
|
|
||||||
@@ -89,6 +89,12 @@
|
|||||||
Es ist ein Datenbankfehler aufgetreten. Bitte versuche es erneut.
|
Es ist ein Datenbankfehler aufgetreten. Bitte versuche es erneut.
|
||||||
</p>
|
</p>
|
||||||
<?php endif; ?>
|
<?php endif; ?>
|
||||||
|
<?php if (isset($_SESSION["message"]) && $_SESSION["message"] == "invalid_csrf_token"): ?>
|
||||||
|
<p class="alert-message is-error">
|
||||||
|
Deine Sitzung ist abgelaufen oder die Anfrage konnte nicht überprüft werden.
|
||||||
|
Bitte lade die Seite neu und versuche es erneut.
|
||||||
|
</p>
|
||||||
|
<?php endif; ?>
|
||||||
<?php
|
<?php
|
||||||
unset($_SESSION["message"]);
|
unset($_SESSION["message"]);
|
||||||
?>
|
?>
|
||||||
@@ -0,0 +1,88 @@
|
|||||||
|
<?php
|
||||||
|
/**
|
||||||
|
* CSRF-Schutz nach dem Synchronizer-Token-Pattern.
|
||||||
|
*
|
||||||
|
* Pro Session wird ein einziges, zufälliges Token erzeugt,
|
||||||
|
* das in jedem Formular als verstecktes Feld mitgeschickt und bei jeder
|
||||||
|
* zustandsändernden Anfrage serverseitig mit dem Session-Token verglichen
|
||||||
|
* wird.
|
||||||
|
*
|
||||||
|
* @author Niklas Ortmann
|
||||||
|
*/
|
||||||
|
|
||||||
|
if (session_status() === PHP_SESSION_NONE) {
|
||||||
|
session_start();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Gibt das aktuelle CSRF-Token der Session zurück.
|
||||||
|
*
|
||||||
|
* Existiert noch kein Token, wird eines erzeugt und in der Session
|
||||||
|
* gespeichert.
|
||||||
|
*
|
||||||
|
* @return string Das CSRF-Token
|
||||||
|
*/
|
||||||
|
function csrf_token(): string
|
||||||
|
{
|
||||||
|
if (empty($_SESSION["csrf_token"]) || !is_string($_SESSION["csrf_token"])) {
|
||||||
|
$_SESSION["csrf_token"] = bin2hex(random_bytes(32));
|
||||||
|
}
|
||||||
|
|
||||||
|
return $_SESSION["csrf_token"];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Gibt ein verstecktes Formularfeld mit dem aktuellen CSRF-Token aus.
|
||||||
|
*
|
||||||
|
* Wird in jedem Formular benötigt, das eine zustandsändernde
|
||||||
|
* Aktion auslöst.
|
||||||
|
*
|
||||||
|
* @return void
|
||||||
|
*/
|
||||||
|
function csrf_field(): void
|
||||||
|
{
|
||||||
|
echo '<input type="hidden" name="csrf_token" value="'
|
||||||
|
. htmlspecialchars(csrf_token())
|
||||||
|
. '">';
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Prüft, ob das per POST gesendete CSRF-Token zum Session-Token passt.
|
||||||
|
*
|
||||||
|
* Der Vergleich erfolgt zeitkonstant über hash_equals(), um
|
||||||
|
* Timing-Angriffe auf den Vergleich selbst auszuschließen.
|
||||||
|
*
|
||||||
|
* @return bool true, wenn das Token gültig ist
|
||||||
|
*/
|
||||||
|
function csrf_verify(): bool
|
||||||
|
{
|
||||||
|
$sentToken = $_POST["csrf_token"] ?? "";
|
||||||
|
$sessionToken = $_SESSION["csrf_token"] ?? "";
|
||||||
|
|
||||||
|
if (!is_string($sentToken) || $sentToken === "" || $sessionToken === "") {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
return hash_equals($sessionToken, $sentToken);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Bricht die Anfrage ab und leitet mit einer Fehlermeldung um,
|
||||||
|
* wenn das mitgesendete CSRF-Token ungültig oder nicht vorhanden ist.
|
||||||
|
*
|
||||||
|
* Muss am Anfang jeder zustandsändernden POST-Aktion aufgerufen werden,
|
||||||
|
* bevor irgendeine Änderung an Daten vorgenommen wird.
|
||||||
|
*
|
||||||
|
* @param string $redirectTo Ziel-URL, zu der bei ungültigem Token
|
||||||
|
* weitergeleitet wird
|
||||||
|
* @return void
|
||||||
|
*/
|
||||||
|
function csrf_require_valid(string $redirectTo = "index.php"): void
|
||||||
|
{
|
||||||
|
if (!csrf_verify()) {
|
||||||
|
http_response_code(403);
|
||||||
|
$_SESSION["message"] = "invalid_csrf_token";
|
||||||
|
header("Location: " . $redirectTo);
|
||||||
|
exit();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@
|
|||||||
if (session_status() === PHP_SESSION_NONE) {
|
if (session_status() === PHP_SESSION_NONE) {
|
||||||
session_start();
|
session_start();
|
||||||
}
|
}
|
||||||
|
include_once "includes/csrf.php";
|
||||||
include_once "php/controller/index-controller.php";
|
include_once "php/controller/index-controller.php";
|
||||||
?>
|
?>
|
||||||
<!DOCTYPE html>
|
<!DOCTYPE html>
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ if (session_status() === PHP_SESSION_NONE) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
require_once "../model/CommentManager.php";
|
require_once "../model/CommentManager.php";
|
||||||
require_once "../model/UserManager.php";
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Prüft, ob die Anfrage durch JavaScript per AJAX gesendet wurde.
|
* Prüft, ob die Anfrage durch JavaScript per AJAX gesendet wurde.
|
||||||
@@ -41,6 +40,7 @@ function sendCommentResponse(
|
|||||||
$additionalData
|
$additionalData
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
|
|
||||||
exit();
|
exit();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -162,29 +162,13 @@ try {
|
|||||||
$parentCommentId
|
$parentCommentId
|
||||||
);
|
);
|
||||||
|
|
||||||
$userManager = UserManager::getInstance();
|
|
||||||
$user = $userManager->findUser($_SESSION["user_email"]);
|
|
||||||
|
|
||||||
$authorName = $_SESSION["user_email"];
|
|
||||||
|
|
||||||
if ($user !== null) {
|
|
||||||
$vorname = trim($user["vorname"] ?? "");
|
|
||||||
$nachname = trim($user["nachname"] ?? "");
|
|
||||||
|
|
||||||
$fullName = trim($vorname . " " . $nachname);
|
|
||||||
|
|
||||||
if ($fullName !== "") {
|
|
||||||
$authorName = $fullName;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
sendCommentResponse(
|
sendCommentResponse(
|
||||||
true,
|
true,
|
||||||
"Der Kommentar wurde erfolgreich gespeichert.",
|
"Der Kommentar wurde erfolgreich gespeichert.",
|
||||||
$articleId,
|
$articleId,
|
||||||
[
|
[
|
||||||
"commentId" => $commentId,
|
"commentId" => $commentId,
|
||||||
"author" => $authorName,
|
"author" => $_SESSION["user_email"],
|
||||||
"content" => $content,
|
"content" => $content,
|
||||||
"created" => date("Y-m-d H:i:s"),
|
"created" => date("Y-m-d H:i:s"),
|
||||||
"parentCommentId" => $parentCommentId
|
"parentCommentId" => $parentCommentId
|
||||||
|
|||||||
@@ -310,20 +310,21 @@ class DatabaseArticleManager implements ArticleManagerDAO {
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
$db = $this->getConnection();
|
$db = $this->getConnection();
|
||||||
|
|
||||||
$sql = "SELECT id, title, content, author, category, tags, created
|
$sql = "SELECT id, title, content, author, category, tags, created
|
||||||
FROM articles
|
FROM articles
|
||||||
WHERE title LIKE :keyword
|
WHERE title LIKE :keyword
|
||||||
OR content LIKE :keyword
|
OR content LIKE :keyword
|
||||||
OR tags LIKE :keyword;";
|
OR tags LIKE :keyword";
|
||||||
|
|
||||||
$command = $db->prepare($sql);
|
$command = $db->prepare($sql);
|
||||||
if (!$command) {
|
if (!$command) {
|
||||||
throw new InternalServerErrorException("internal_error");
|
throw new InternalServerErrorException("internal_error");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Wildcards für die SQL-Suche hinzufügen
|
// Wildcards für die Suche hinzufügen
|
||||||
$searchParam = '%' . $cleankeyword . '%';
|
$searchParam = '%' . $cleankeyword . '%';
|
||||||
|
|
||||||
$success = $command->execute([
|
$success = $command->execute([
|
||||||
":keyword" => $searchParam
|
":keyword" => $searchParam
|
||||||
]);
|
]);
|
||||||
@@ -336,11 +337,10 @@ class DatabaseArticleManager implements ArticleManagerDAO {
|
|||||||
$filteredArticles = [];
|
$filteredArticles = [];
|
||||||
|
|
||||||
foreach ($rows as $row) {
|
foreach ($rows as $row) {
|
||||||
$articleId = intval($row['id']);
|
$likes = $this->getLikesForArticle(intval($row['id']));
|
||||||
$likes = $this->getLikesForArticle($articleId);
|
|
||||||
|
|
||||||
$filteredArticles[] = new Article(
|
$filteredArticles[] = new Article(
|
||||||
$articleId,
|
intval($row['id']),
|
||||||
$row['title'] ?? '',
|
$row['title'] ?? '',
|
||||||
$row['content'] ?? '',
|
$row['content'] ?? '',
|
||||||
$row['author'] ?? '',
|
$row['author'] ?? '',
|
||||||
@@ -358,7 +358,6 @@ class DatabaseArticleManager implements ArticleManagerDAO {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Holt alle User-IDs, die einen bestimmten Beitrag geliked haben.
|
* Holt alle User-IDs, die einen bestimmten Beitrag geliked haben.
|
||||||
*
|
*
|
||||||
|
|||||||
Reference in New Issue
Block a user