Fix blog comment management

This commit is contained in:
Léo Serre 2018-11-18 21:59:55 +01:00
parent f32e528d01
commit 2258aa3fe0
4 changed files with 98 additions and 88 deletions

View File

@ -174,7 +174,6 @@ SET default_with_oids = false;
CREATE TABLE public.content_comments ( CREATE TABLE public.content_comments (
id integer DEFAULT nextval('public.content_comments_sequence'::regclass) NOT NULL, id integer DEFAULT nextval('public.content_comments_sequence'::regclass) NOT NULL,
permalink character varying(255),
version integer, version integer,
creation_date timestamp without time zone, creation_date timestamp without time zone,
update_date timestamp without time zone, update_date timestamp without time zone,

View File

@ -136,8 +136,8 @@ switch ($controller->splitted_url[1]) {
$blogComment = new Kabano\BlogComment(); $blogComment = new Kabano\BlogComment();
$blogComment->locale = $user->locale; $blogComment->locale = $user->locale;
$blogComment->author = $user->id; $blogComment->author = $user->id;
$blogComment->article = $blogArticle->id; $blogComment->content = $blogArticle->id;
$blogComment->content = $_POST['comment']; $blogComment->comment = $_POST['comment'];
$blogComment->insert(); $blogComment->insert();
} }
} }
@ -146,10 +146,9 @@ switch ($controller->splitted_url[1]) {
if (isset($controller->splitted_url[2]) && $controller->splitted_url[2]=="delete_comment") { if (isset($controller->splitted_url[2]) && $controller->splitted_url[2]=="delete_comment") {
if (isset($controller->splitted_url[3]) && is_numeric($controller->splitted_url[3])) { if (isset($controller->splitted_url[3]) && is_numeric($controller->splitted_url[3])) {
$blogComment = new Kabano\BlogComment(); $blogComment = new Kabano\BlogComment();
$blogComment->id = $controller->splitted_url[3]; if($blogComment->checkId($controller->splitted_url[3]))
$blogComment->populate(); if ($user->rankIsHigher("moderator") || $user->id == $blogComment->author)
if ($user->rankIsHigher("moderator") || $user->id == $blogComment->author) $blogComment->delete();
$blogComment->delete();
} }
} }
@ -157,10 +156,9 @@ switch ($controller->splitted_url[1]) {
if (isset($controller->splitted_url[2]) && $controller->splitted_url[2]=="restore_comment") { if (isset($controller->splitted_url[2]) && $controller->splitted_url[2]=="restore_comment") {
if (isset($controller->splitted_url[3]) && is_numeric($controller->splitted_url[3])) { if (isset($controller->splitted_url[3]) && is_numeric($controller->splitted_url[3])) {
$blogComment = new Kabano\BlogComment(); $blogComment = new Kabano\BlogComment();
$blogComment->id = $controller->splitted_url[3]; if($blogComment->checkId($controller->splitted_url[3]))
$blogComment->populate(); if ($user->rankIsHigher("moderator") || $user->id == $blogComment->author)
if ($user->rankIsHigher("moderator") || $user->id == $blogComment->author) $blogComment->restore();
$blogComment->restore();
} }
} }
@ -172,15 +170,10 @@ switch ($controller->splitted_url[1]) {
$blogArticles_comments->listComments($blogArticle->id, ($user->rankIsHigher("premium"))); $blogArticles_comments->listComments($blogArticle->id, ($user->rankIsHigher("premium")));
$i = 0; $i = 0;
foreach ($blogArticles_comments->ids as $row) { foreach ($blogArticles_comments->objs as $comment) {
$blogArticles_comments_list[$i] = new Kabano\BlogComment(); $comment->md2html();
$blogArticles_comments_list[$i]->id = $row; $comment->author_obj = new Kabano\User();
$blogArticles_comments_list[$i]->populate(); $comment->author_obj->checkId($comment->author);
$blogArticles_comments_list[$i]->md2html();
$blogArticles_comments_list[$i]->author_obj = new Kabano\User();
$blogArticles_comments_list[$i]->author_obj->id = $blogArticles_comments_list[$i]->author;
$blogArticles_comments_list[$i]->author_obj->populate();
$i++;
} }
} }

View File

@ -349,45 +349,60 @@ class BlogArticles
class BlogComment class BlogComment
{ {
public $id = 0; public $id = NULL;
public $locale = NULL; public $version = 0;
public $lastedit = NULL; public $creation_date = NULL;
public $archive = NULL; public $update_date = NULL;
public $content = NULL;
public $author = NULL; public $author = NULL;
public $article = NULL; public $is_public = NULL;
public $is_archive = NULL;
public $content = NULL;
public $comment = NULL;
public $locale = NULL;
/*****
** Connect to correct account using ID and stores its ID
*****/
public function checkID($id) {
global $config;
$con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass'])
or die ("Could not connect to server\n");
$query = "SELECT * FROM content_comments WHERE id=$1";
pg_prepare($con, "prepare1", $query)
or die ("Cannot prepare statement\n");
$result = pg_execute($con, "prepare1", array($id))
or die ("Cannot execute statement\n");
pg_close($con);
if(pg_num_rows($result) == 1) {
$row = pg_fetch_assoc($result);
$this->populate($row);
return 1;
}
else {
return 0;
}
}
/***** /*****
** Populate the object using its ID ** Populate the object using its ID
*****/ *****/
public function populate() { public function populate($row) {
global $config; $this->id = $row['id'];
$this->version = $row['version'];
if($this->id != 0) { $this->creation_date = $row['creation_date'];
$con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass']) $this->update_date = $row['update_date'];
or die ("Could not connect to server\n"); $this->author = $row['author'];
$this->is_public = $row['is_public'];
$query = "SELECT * FROM blog_comments WHERE id=$1"; $this->is_archive = $row['is_archive'];
$this->content = $row['content'];
pg_prepare($con, "prepare1", $query) $this->comment = $row['comment'];
or die ("Cannot prepare statement\n"); $this->locale = $row['locale'];
$result = pg_execute($con, "prepare1", array($this->id))
or die ("Cannot execute statement\n");
pg_close($con);
$blog_comment = pg_fetch_assoc($result);
$this->locale = $blog_comment['locale'];
$this->lastedit = $blog_comment['lastedit'];
$this->archive = $blog_comment['archive'];
$this->content = $blog_comment['content'];
$this->author = $blog_comment['author'];
$this->article = $blog_comment['article'];
}
else {
die("Cannot populate a blog article without ID");
}
} }
/***** /*****
@ -399,14 +414,16 @@ class BlogComment
$con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass']) $con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass'])
or die ("Could not connect to server\n"); or die ("Could not connect to server\n");
$query = "INSERT INTO blog_comments (content, lastedit, archive, locale, author, article) VALUES $query = "INSERT INTO content_comments (version, creation_date, update_date, author, is_public, is_archive, content, comment, locale) VALUES
($1, $2, FALSE, $3, $4, $5)"; ('0', $1, $2, $3, TRUE, FALSE, $4, $5, $6) RETURNING id";
pg_prepare($con, "prepare2", $query) pg_prepare($con, "prepare1", $query)
or die ("Cannot prepare statement\n"); or die ("Cannot prepare statement\n");
$result = pg_execute($con, "prepare2", array($this->content, date('r'), $this->locale, $this->author, $this->article)) $result = pg_execute($con, "prepare1", array(date('r'), date('r'), $this->author, $this->content, $this->comment, $this->locale))
or die ("Cannot execute statement\n"); or die ("Cannot execute statement\n");
$this->id = pg_fetch_assoc($result)['id'];
pg_close($con); pg_close($con);
} }
@ -420,11 +437,11 @@ class BlogComment
$con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass']) $con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass'])
or die ("Could not connect to server\n"); or die ("Could not connect to server\n");
$query = "UPDATE blog_comments SET archive = TRUE WHERE id = $1"; $query = "UPDATE content_comments SET is_public = FALSE WHERE id = $1";
pg_prepare($con, "prepare2", $query) pg_prepare($con, "prepare1", $query)
or die ("Cannot prepare statement\n"); or die ("Cannot prepare statement\n");
$result = pg_execute($con, "prepare2", array($this->id)) $result = pg_execute($con, "prepare1", array($this->id))
or die ("Cannot execute statement\n"); or die ("Cannot execute statement\n");
pg_close($con); pg_close($con);
@ -436,20 +453,20 @@ class BlogComment
} }
/***** /*****
** DeArchive a comment ** Restore a comment
*****/ *****/
public function undelete() { public function restore() {
global $config; global $config;
global $user; global $user;
$con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass']) $con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass'])
or die ("Could not connect to server\n"); or die ("Could not connect to server\n");
$query = "UPDATE blog_comments SET archive = FALSE WHERE id = $1"; $query = "UPDATE content_comments SET is_public = TRUE WHERE id = $1";
pg_prepare($con, "prepare2", $query) pg_prepare($con, "prepare1", $query)
or die ("Cannot prepare statement\n"); or die ("Cannot prepare statement\n");
$result = pg_execute($con, "prepare2", array($this->id)) $result = pg_execute($con, "prepare1", array($this->id))
or die ("Cannot execute statement\n"); or die ("Cannot execute statement\n");
pg_close($con); pg_close($con);
@ -461,18 +478,18 @@ class BlogComment
} }
/***** /*****
** Converts the Markdown content to HTML ** Converts the Markdown comment to HTML
*****/ *****/
public function md2html() { public function md2html() {
$this->content_html = \Michelf\MarkdownExtra::defaultTransform($this->content); $this->comment_html = \Michelf\MarkdownExtra::defaultTransform($this->comment);
} }
/***** /*****
** Converts the Markdown content to text ** Converts the Markdown comment to text
*****/ *****/
public function md2txt() { public function md2txt() {
$this->md2html(); $this->md2html();
$this->content_txt = strip_tags($this->content_html); $this->comment_txt = strip_tags($this->comment_html);
} }
} }
@ -487,7 +504,7 @@ class BlogComment
class BlogComments class BlogComments
{ {
public $ids = array(); public $objs = array();
public $number = NULL; public $number = NULL;
/***** /*****
@ -499,10 +516,10 @@ class BlogComments
$con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass']) $con = pg_connect("host=".$config['SQL_host']." dbname=".$config['SQL_db']." user=".$config['SQL_user']." password=".$config['SQL_pass'])
or die ("Could not connect to server\n"); or die ("Could not connect to server\n");
$query = "SELECT id FROM blog_comments WHERE article = $1 "; $query = "SELECT * FROM content_comments WHERE content = $1 ";
if ($archive == 0) if ($archive == 0)
$query .= "AND archive IS FALSE "; $query .= "AND is_archive IS FALSE AND is_public IS TRUE ";
$query .= "ORDER BY lastedit DESC"; $query .= "ORDER BY update_date DESC";
pg_prepare($con, "prepare1", $query) pg_prepare($con, "prepare1", $query)
or die ("Cannot prepare statement\n"); or die ("Cannot prepare statement\n");
@ -515,7 +532,8 @@ class BlogComments
for($i = 0; $i < pg_num_rows($result); $i++) { for($i = 0; $i < pg_num_rows($result); $i++) {
$row = pg_fetch_assoc($result, $i); $row = pg_fetch_assoc($result, $i);
$this->ids[$i] = $row['id']; $this->objs[$i] = new BlogComment;
$this->objs[$i]->populate($row);
} }
} }
} }

View File

@ -66,31 +66,31 @@
</form> </form>
</div> </div>
<? if(isset($blogArticles_comments_list)) { <? if($blogArticle->is_commentable == 't') {
foreach ($blogArticles_comments_list as $row) { ?> foreach ($blogArticles_comments->objs as $comment) { ?>
<article <? if($row->archive == 't') echo 'class="comment_archive" '; ?>> <article <? if($comment->is_archive == 't' || $comment->is_public == 'f') echo 'class="comment_archive" '; ?>>
<div class="comment_title"> <div class="comment_title">
<? if ($row->author_obj->avatar=='t') { ?> <? if ($comment->author_obj->is_avatar_present=='t') { ?>
<img alt="Avatar" class="icon avatar" src="<?=$config['rel_root_folder']?>medias/avatars/<?=$row->author_obj->id?>_s.jpg"> <img alt="Avatar" class="icon avatar" src="<?=$config['rel_root_folder']?>medias/avatars/<?=$comment->author_obj->id?>_s.jpg">
<? } else { ?> <? } else { ?>
<i class="icon fas fa-user-secret"></i> <i class="icon fas fa-user-secret"></i>
<? } ?> <? } ?>
<? if ($user->rankIsHigher("blocked")) { ?> <? if ($user->rankIsHigher("blocked")) { ?>
<a class="username" href="<?=$config['rel_root_folder']?>user/p/<?=$row->author_obj->id?>"><?=$row->author_obj->name?></a> <a class="username" href="<?=$config['rel_root_folder']?>user/p/<?=$comment->author_obj->id?>"><?=$comment->author_obj->name?></a>
<? } else { ?> <? } else { ?>
<?=$row->author_obj->name?> <?=$comment->author_obj->name?>
<? } ?> <? } ?>
le <? echo strftime('%e %B %G, %kh%Mm%Ss',strtotime($row->lastedit)) ?> <small><abbr title="Temps Universel Coordonné">UTC</abbr></small> le <? echo strftime('%e %B %G, %kh%Mm%Ss',strtotime($comment->update_date)) ?> <small><abbr title="Temps Universel Coordonné">UTC</abbr></small>
<? if (($user->rankIsHigher("moderator") || $user->id == $row->author) && $row->archive == 'f') { ?> <? if (($user->rankIsHigher("moderator") || $user->id == $comment->author) && $comment->is_public == 't') { ?>
<span class="delete_link"><a href="<?=$config['rel_root_folder']?>blog/<?=$blogArticle->permalink?>/delete_comment/<?=$row->id?>"><i class="fas fa-trash"></i> Effacer le commentaire</a></span> <span class="delete_link"><a href="<?=$config['rel_root_folder']?>blog/<?=$blogArticle->permalink?>/delete_comment/<?=$comment->id?>"><i class="fas fa-trash"></i> Effacer le commentaire</a></span>
<? } ?> <? } ?>
<? if (($user->rankIsHigher("moderator") || $user->id == $row->author) && $row->archive == 't') { ?> <? if (($user->rankIsHigher("moderator") || $user->id == $comment->author) && $comment->is_public == 'f') { ?>
<span class="delete_link"><a href="<?=$config['rel_root_folder']?>blog/<?=$blogArticle->permalink?>/restore_comment/<?=$row->id?>"><i class="fas fa-eye"></i> Restaurer le commentaire</a></span> <span class="delete_link"><a href="<?=$config['rel_root_folder']?>blog/<?=$blogArticle->permalink?>/restore_comment/<?=$comment->id?>"><i class="fas fa-eye"></i> Restaurer le commentaire</a></span>
<? } ?> <? } ?>
</div> </div>
<div class="comment_content"> <div class="comment_content">
<?=$row->content_html?> <?=$comment->comment_html?>
</div> </div>
</article> </article>