v2.0.0.0
Publisium
- <?php
-
- declare(strict_types=1);
-
- $articleId = (int) ($_POST['article_id'] ?? 0);
-
- if ($articleId <= 0) {
- exit;
- }
-
- $db = Database::site();
- $statement = $db->prepare('SELECT * FROM articles WHERE id = :id LIMIT 1');
- $statement->execute(['id' => $articleId]);
- $article = $statement->fetch();
-
- if (!$article) {
- exit;
- }
-
- $isOwner = (int) $article['author_id'] === (int) $currentUser['id'];
- $canDeleteAny = Auth::hasRoleAtLeast(Auth::ROLE_EDITOR_IN_CHIEF);
-
- if (!$isOwner && !$canDeleteAny) {
- exit;
- }
-
- if ($isOwner && !$canDeleteAny && $article['status'] !== 'draft') {
- exit;
- }
-
- if ($article['deleted_at'] !== null) {
- exit;
- }
-
- $trash = $db->prepare(
- "UPDATE articles SET trashed_status = status, status = 'draft', scheduled_at = NULL, deleted_at = NOW() WHERE id = :id AND deleted_at IS NULL"
- );
- $trash->execute(['id' => $articleId]);
-