Файл: modules/news/edit_news.php
Строк: 54
<?php
$locate = 'in_news';
if($user['level'] < '6') { go('/'); }
if(isset($_GET['news_id'])) {
$news_id = abs(intval($_GET['news_id']));
if(isset($_POST['edit']) && $_GET['act'] == 'edit') {
$name = substr(input($_POST['name']), 0, 100);
$text = substr(input($_POST['text']), 0, 10000);
$db->query("UPDATE `news` SET `name` = '".$name."', `text` = '". $text ."' WHERE `id` = '".$news_id."'");
// print_r($db->errorInfo());
go('/news/article/'.$news_id.'/');
}
$title = $lang->word('edit_news');
require_once(SYS.'/view/header.php');
$tpl->div('title', $lang->word('edit_news'));
$news_e = $db->query("SELECT * FROM `news` WHERE `id` = '".$news_id."'")->fetch();
echo '<form action="/news/edit_news/?act=edit&news_id='.$news_id.'" method="post">
<div class="menu">
<b>'. $lang->word('form_album_name') .'</b>:<br/>
<input name="name" type="text" value="'. $news_e['name'] .'" /><br/>
<b>'. $lang->word('text') .'</b>:<br/>
<textarea name="text" rows="5" cols="26">'. $news_e['text'] .'</textarea><br/>
<input name="edit" type="submit" value="'. $lang->word('save') .'" /><br/>
</div>
</form>';
$tpl->div('block', img('news.png') .'<a href="/news/">'. $lang->word('news') .'</a><br/>' . HICO .'<a href="/">'. $lang->word('home').'</a>');
require_once(SYS.'/view/footer.php');
} else { go('/news/'); }
?>