$username=$_SESSION["username"];
$newid=intval($_GET["id"]);
if($newid=="")
{
function str_count($str,$col)
{
if (strlen($str) > $col)
{
$str = mb_substr($str,0,$col);
}
return ($str);
}
$sql="select * from dos_news order by id desc";
$res=mysql_query($sql);
while ($row=mysql_fetch_array($res))
{
$iid=$row["id"];
echo "
";
echo $row["data"];
echo "";
echo " - ";
echo $row["newstitl"];
echo "...
Читать далее (комментариев: ";
echo mysql_num_rows(mysql_query("SELECT id FROM dos_newscom WHERE idnew='$iid'")); echo ")
";
}
}else{
$neew=mysql_query("SELECT * FROM dos_news WHERE id='$newid'");
$neew=mysql_fetch_array($neew);
echo "
";
echo $neew[newstitl];
echo "
";
echo "
";
if(isset($_POST["delete"]))
{
$delid=$_POST["id"];
$username=$_SESSION["username"];
$ob=mysql_fetch_array(mysql_query("SELECT user_status FROM tb_users WHERE username='$username'"));
$ussst=$ob["user_status"];
if($ussst=='admin')
{
mysql_query("DELETE FROM dos_newscom where id='$delid'");
echo "
Комментарий успешно удалён!";
}else{
echo "
Ошибка!";
}
}
if(isset($_POST["comment"]))
{
$comment=$_POST["comment"];
function limpiarez($mess)
{
$mess=str_replace(";"," ",$mess);
$mess=str_replace("$"," ",$mess);
$mess=str_replace("'"," ",$mess);
$mess=str_replace(">"," ",$mess);
$mess=str_replace("<"," ",$mess);
$mess=strip_tags($mess);
return $mess;
}
$comment=limpiarez($comment);
if($comment!='')
{
$date=time();
mysql_query("INSERT INTO dos_newscom (idnew, data, user, comment) VALUES ('$newid', '$date', '$username', '$comment')");
echo "Ваш комментарий успешно добавлен"; ?>
}else{
echo "
Нельзя оставлять пустые комментарии";
}
}
$res=mysql_query("select count(*) as kolvo from dos_newscom where idnew='$newid'");
$res=mysql_fetch_array($res);
$allcomments=$res["kolvo"];
if($allcomments=='0')
{
echo "
Комментариев к данной статье нет";
}
$pages=$allcomments/15;
$pages1=floor($pages);
if($pages>$pages1)
{
$pages=$pages1+1;
}
if($_POST["page"]!="")
{
$page=$_POST["page"];
}else{
$page='1';
}
if($allcomments!='0')
{
echo "
Текущая страница $page из $pages";
?>
}
$p1=15*($page-1);
$p2=15*$page-1;
$result=mysql_query("SELECT * FROM dos_newscom WHERE idnew='$newid'order by data desc limit $p1,$p2");
while ($rowe=mysql_fetch_array($result))
{
$usernapisal=$rowe["user"];
$sqlz=mysql_query("SELECT * FROM tb_users WHERE username='$usernapisal'");
$vivod=mysql_fetch_array($sqlz);
$avatar=$vivod["avatar"];
$yourcomment=$rowe["comment"];
$yourdata=$rowe["data"];
$normdate=date("d.m.y H:i", $yourdata);
echo "
";
}
if(!(isset($_SESSION["username"]) && isset($_SESSION["password"])))
{
echo "
";
}else{ ?>
}
}
?>