<?
include_once '../../sys/inc/start.php';
include_once '../../sys/inc/compress.php';
include_once '../../sys/inc/sess.php';
include_once '../../sys/inc/home.php';
include_once '../../sys/inc/settings.php';
include_once '../../sys/inc/db_connect.php';
include_once '../../sys/inc/ipua.php';
include_once '../../sys/inc/fnc.php';
include_once '../../sys/inc/user.php';
$set['title']='Редактирование';
include_once '../../sys/inc/thead.php';
aut(); // форма авторизации
if (isset ($user) && $user['group_access'] < 5)
header("Location: /");
title();
if (isset($_GET['id']) && mysql_result(mysql_query("SELECT COUNT(*) FROM `rules_p` WHERE `id` = '".intval($_GET['id'])."'"),0)==1)
{
$post=mysql_fetch_assoc(mysql_query("SELECT * FROM `rules_p` WHERE `id` = '".intval($_GET['id'])."' LIMIT 1"));
$ank=mysql_fetch_assoc(mysql_query("SELECT * FROM `user` WHERE `id` = $post[id_user] LIMIT 1"));
if (isset($_POST['change']) && isset($_GET['id']) && isset($_POST['name']) && $_POST['name']!=NULL)
{
$id=intval($_GET['id']);
$name=esc(stripcslashes(htmlspecialchars($_POST['name'])));
mysql_query("UPDATE `rules_p` SET `msg` = '$name' WHERE `id` = '$id' LIMIT 1");
msg('Пункт меню успешно изменен');
header("Location: post.php?id=$post[id_news]");
}
}
if (isset($_GET['id']) && mysql_result(mysql_query("SELECT COUNT(*) FROM `rules` WHERE `id` = '".intval($_GET['id'])."'"),0)==1)
{
$post=mysql_fetch_assoc(mysql_query("SELECT * FROM `rules` WHERE `id` = '".intval($_GET['id'])."' LIMIT 1"));
$ank=mysql_fetch_assoc(mysql_query("SELECT * FROM `user` WHERE `id` = $post[id_user] LIMIT 1"));
if (isset($_POST['change']) && isset($_GET['id']))
{
$id=intval($_GET['id']);
$name=my_esc($_POST['msg']);
$url=esc($_POST['url'],1);
$name_url=esc($_POST['name_url'],1);
$title=esc($_POST['title'],1);
mysql_query("UPDATE `rules` SET `msg` = '$name' WHERE `id` = '$id' LIMIT 1");
mysql_query("UPDATE `rules` SET `title` = '$title' WHERE `id` = '$id' LIMIT 1");
mysql_query("UPDATE `rules` SET `url` = '$url' WHERE `id` = '$id' LIMIT 1");
mysql_query("UPDATE `rules` SET `name_url` = '$name_url' WHERE `id` = '$id' LIMIT 1");
msg('Пункт меню успешно изменен');
header("Location: index.php");
}
}
if (isset($_GET['id']) && $_GET['id']==$post['id'] && isset($_GET['act']) && $_GET['act']=='edit')
{
echo "<form action=\"?id=$post[id]&act=edit&$passgen\" method=\"post\">";
echo "Редактирование поста:<br />\n";
echo "<textarea name=\"name\">".$post['msg']."</textarea><br />\n";
echo "<input class=\"submit\" name=\"change\" type=\"submit\" value=\"Изменить\" /><br />\n";
echo "</form>";
echo "<a href='?'>Отмена</a><br />";
}
if (isset($_GET['id']) && $_GET['id']==$post['id'] && isset($_GET['act']) && $_GET['act']=='edits')
{
echo "<form action=\"?id=$post[id]&act=edits&$passgen\" method=\"post\">";
echo "Название ссылки:<br />\n<input name=\"name_url\" size=\"16\" value=\"$post[name_url]\" type=\"text\" /><br />\n";
echo "Адрес ссылки:<br />\n<input name=\"url\" size=\"16\" value=\"$post[url]\" type=\"text\" /><br />\n";
echo "Название пункта:<br />\n<input name=\"title\" size=\"16\" value=\"$post[title]\" type=\"text\" /><br />\n";
echo "Редактирование текста:<br />\n";
echo "<textarea name=\"msg\">$post[msg]</textarea><br />\n";
echo "<input class=\"submit\" name=\"change\" type=\"submit\" value=\"Изменить\" /><br />\n";
echo "</form>";
echo "<a href='?'>Отмена</a><br />";
}
echo "<div class='navig'><a href='index.php'>Помощь</a></div>\n";
include_once '../../sys/inc/tfoot.php';
?>