WebOrbiton
v2.0.0.0

Publisium

39 lines · 853 B
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. $articleId = (int) ($_POST['article_id'] ?? 0);
  6. ​
  7. if ($articleId <= 0) {
  8. exit;
  9. }
  10. ​
  11. $db = Database::site();
  12. $statement = $db->prepare('SELECT * FROM articles WHERE id = :id LIMIT 1');
  13. $statement->execute(['id' => $articleId]);
  14. $article = $statement->fetch();
  15. ​
  16. if (!$article) {
  17. exit;
  18. }
  19. ​
  20. $isOwner = (int) $article['author_id'] === (int) $currentUser['id'];
  21. $canDeleteAny = Auth::hasRoleAtLeast(Auth::ROLE_EDITOR_IN_CHIEF);
  22. ​
  23. if (!$isOwner && !$canDeleteAny) {
  24. exit;
  25. }
  26. ​
  27. if ($isOwner && !$canDeleteAny && $article['status'] !== 'draft') {
  28. exit;
  29. }
  30. ​
  31. if ($article['deleted_at'] !== null) {
  32. exit;
  33. }
  34. ​
  35. $trash = $db->prepare(
  36. "UPDATE articles SET trashed_status = status, status = 'draft', scheduled_at = NULL, deleted_at = NOW() WHERE id = :id AND deleted_at IS NULL"
  37. );
  38. $trash->execute(['id' => $articleId]);
  39. ​