WebOrbiton
v2.0.0.0

Publisium

71 lines · 2.3 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. $db = Database::site();
  6. $canManageAny = Auth::hasRoleAtLeast(Auth::ROLE_EDITOR_IN_CHIEF);
  7. ​
  8. $loadTrashed = static function (int $id) use ($db): ?array {
  9. $statement = $db->prepare('SELECT * FROM articles WHERE id = :id AND deleted_at IS NOT NULL LIMIT 1');
  10. $statement->execute(['id' => $id]);
  11. ​
  12. return $statement->fetch() ?: null;
  13. };
  14. ​
  15. $canTouch = static fn (array $article): bool => $canManageAny || (int) $article['author_id'] === (int) $currentUser['id'];
  16. ​
  17. $purge = static function (int $id) use ($db): void {
  18. $db->prepare('DELETE FROM article_versions WHERE article_id = :id')->execute(['id' => $id]);
  19. $db->prepare('DELETE FROM article_tags WHERE article_id = :id')->execute(['id' => $id]);
  20. $db->prepare('DELETE FROM articles WHERE id = :id')->execute(['id' => $id]);
  21. };
  22. ​
  23. $articleId = (int) ($_POST['article_id'] ?? 0);
  24. ​
  25. if ($action === 'restore_article') {
  26. $article = $articleId > 0 ? $loadTrashed($articleId) : null;
  27. if ($article === null || !$canTouch($article)) {
  28. return 0;
  29. }
  30. ​
  31. $restoredStatus = in_array($article['trashed_status'], ['published', 'pending_review', 'rejected'], true) ? $article['trashed_status'] : 'draft';
  32. ​
  33. $db->prepare('UPDATE articles SET status = :status, deleted_at = NULL, trashed_status = NULL WHERE id = :id')
  34. ->execute(['status' => $restoredStatus, 'id' => $articleId]);
  35. ActivityLog::record('article.restore', 'article', $articleId, (string) $article['title']);
  36. ​
  37. return $articleId;
  38. }
  39. ​
  40. if ($action === 'purge_article') {
  41. $article = $articleId > 0 ? $loadTrashed($articleId) : null;
  42. if ($article === null || !$canTouch($article)) {
  43. return 0;
  44. }
  45. ​
  46. $purge($articleId);
  47. ActivityLog::record('article.purge', 'article', $articleId, (string) $article['title']);
  48. ​
  49. return 0;
  50. }
  51. ​
  52. if ($action === 'empty_trash') {
  53. $statement = $canManageAny
  54. ? $db->query('SELECT id FROM articles WHERE deleted_at IS NOT NULL')
  55. : $db->prepare('SELECT id FROM articles WHERE deleted_at IS NOT NULL AND author_id = :author');
  56. ​
  57. if (!$canManageAny) {
  58. $statement->execute(['author' => $currentUser['id']]);
  59. }
  60. ​
  61. $ids = $statement->fetchAll(PDO::FETCH_COLUMN);
  62. foreach ($ids as $id) {
  63. $purge((int) $id);
  64. }
  65. ActivityLog::record('article.empty_trash', 'article', null, count($ids) . ' articles');
  66. ​
  67. return 0;
  68. }
  69. ​
  70. return 0;
  71. ​