-
Notifications
You must be signed in to change notification settings - Fork 0
/
post.php
34 lines (26 loc) · 873 Bytes
/
post.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
<?php
session_start();
$con=mysqli_connect("localhost","root","root","HopkinsClubs");
if (mysqli_connect_errno()) {
echo "Failed to connect to MySQL: " . mysqli_connect_error();
}
$username = $_SESSION["username"];
$password = $_SESSION["password"];
$result = mysqli_query($con, "SELECT * FROM Users WHERE username='$username'");
$row = mysqli_fetch_array($result);
if ($row['password'] == $password) {
$title = mysqli_real_escape_string($con, $_POST['title']);
$post = mysqli_real_escape_string($con, $_POST['post']);
$id = mysqli_real_escape_string($con, $_POST['id']);
$sql="INSERT INTO Posts (pageid, title, author, post)
VALUES ('$id', '$title', '$username', '$post')";
if (!mysqli_query($con, $sql)) {
die('Error: ' . mysqli_error($con));
}
header("Location: club.php?id=" . $id);
}
else {
echo "An error has occured.";
}
mysqli_close($con);
?>