<?php
// *** Make sure the file isn't accessed directly
if(!preg_match("/index.php/i", $_SERVER['SCRIPT_FILENAME'])){
//Give out an "access denied" error
echo "access denied";
//Block all other code
exit();
}
if (@$login->is_logged_in_as("mainadmin")) {
$submit = isset($_POST['subSavePage']) ? $_POST['subSavePage'] : "";
$page_key = isset($_POST['pk']) ? $_POST['pk'] : "";
$page = new StaticPages($page_key);
if ($submit == BUTTON_CREATE) {
$params = Array();
$params['page_key'] = get_random_string(10);
if(isset($_POST['page_title'])) $params['page_title'] = $_POST['page_title'];
if(isset($_POST['page_text'])) $params['page_text'] = $_POST['page_text'];
if(isset($_POST['category_id'])) $params['category_id'] = $_POST['category_id'];
if(isset($_POST['category_link'])) $params['category_link'] = $_POST['category_link'];
if($page->pageCreate($params)) {
draw_success_message(POST_CREATED);
$page = new StaticPages();
}else{
draw_important_message($page->error);
}
}
draw_title_bar(POST_ADD_NEW);
?>
<form name='frmStaticPage' method='post'>
<table width="100%" border="0" cellspacing="0" cellpadding="2" class="main_text">
<tr>
<td>
* Post Header: <br>
<input name="page_title" value="<?php echo $page->getTitle();?>" size="50">
<br><br>
Category Link (link which user will see - max 18 chars): <br>
<input name="category_link" value="<?php echo $page->getCategoryLink();?>" size="50">
<br><br>
Belongs To category: <br>
<?php
$all_categories = Category::getAll();
echo "<select name='category_id'><option value=''>--select--</option>";
for($i = 0; $i < $all_categories[1]; $i++){
echo "<option value='".$all_categories[0][$i]['id']."'";
echo ($all_categories[0][$i]['id']==$page->getCategoryId()) ? " selected " : "";
echo ">".$all_categories[0][$i]['category_name']."</option>";
}
echo "</select>";
?>
<br><br>
Post Text: <br>
<textarea name="page_text" id="my_page_text" rows=20 cols=70><?php if ($page->getText()!="") echo htmlspecialchars($page->getText()); ?></textarea>
</td>
</tr>
<tr>
<td align="center">
<input class="form_button" type="submit" name="subSavePage" value="<?php echo BUTTON_CREATE; ?>">
</td>
</tr>
</table>
</form>
<?php
} else draw_important_message(NOT_AUTHORIZED);
?>