Файл: liwar.ru/forum/nt.php
Строк: 34
<?php
include_once '../Yadro/PDO_connect.php';
$set = DB::$dbs->queryFetch("SELECT * FROM `set_modul`");
if($set['forum']==0){header('location:../');}
if(!isset($cms->us['id'])){header('location:/error.php?user');}
$podrazd = DB::$dbs->queryFetch("SELECT * FROM `forum_podrazd` where `id` = ? limit 1",array(abs(intval($_GET['id']))));
if($podrazd == 0){header('location:/forum');}
$razd = DB::$dbs->queryFetch("SELECT * FROM `forum_razd` where `id` = ? limit 1",array(abs(intval($podrazd['razd']))));
verh('Подраздел '.$podrazd['name'].'');
echo '<div class="player2"><div class="player2"><a href="/forum">Форум</a> | <a href="/forum/razd'.$razd['id'].'">'.$razd['name'].'</a> | '.$podrazd['name'].' | Новая тема<div class="separ6"></div></div>';
include '../Yadro/Functions.php';
if(isset($_POST['submit'])){
if($_SESSION['flood']>time()-30){ $cms->error = 'Антифлуд! Подождите '.$func->flood('sec',30,$_SESSION['flood']).'.'; }
$name = secure($_POST['name']);
$message = secure($_POST['message']);
if(!$name){$cms->error = 'Пустое название!'; }
if(!$message){$cms->error = 'Пустое сообщение!'; }
$uid = (isset($cms->us['id'])?$cms->us['id']:0);
if(!isset($cms->error)){
DB::$dbs->query("INSERT INTO `forum_themes` (`razd`,`podrazd`,`name`,`author`,`time`,`last_time`,`last_user`) VALUES (?,?,?,?,?,?,?)",array($podrazd['razd'],$podrazd['id'],$name,$uid,time(),time(),$uid));
$thema_id = DB::$dbs->lastInsertId();
DB::$dbs->query("INSERT INTO `forum_post` (`razd`,`podrazd`,`thema`,`user`,`message`,`time`) VALUES (?,?,?,?,?,?)",array($podrazd['razd'],$podrazd['id'],$thema_id,$uid,$message,time()));
$_SESSION['flood'] = time();
header('location:/forum/thema'.$thema_id.'');
}else{ echo'<div class="info_err">'.$cms->error.'</div>'; }}
echo '<div class="player"><form action="/forum/nt'.$podrazd['id'].'" method="post">
Название темы:<br><input name="name"/><br>
Сообщение:<br><textarea rows="3" name="message"></textarea>
<br><input type="submit" name="submit" value="Создать тему"/>
</form></div>
</div>';
niz();
?>