WebOrbiton
v1.0.0.1

StocketBase

87 lines · 2.6 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. if (count(get_included_files()) === 1) {
  6. http_response_code(403);
  7. exit;
  8. }
  9. ​
  10. if (!Auth::hasRoleAtLeast(Auth::ROLE_STORE_MANAGER)) {
  11. exit;
  12. }
  13. ​
  14. $title = trim((string) ($_POST['title'] ?? ''));
  15. $pageId = (int) ($_POST['page_id'] ?? 0) ?: null;
  16. $status = ($_POST['status'] ?? 'draft') === 'published' ? 'published' : 'draft';
  17. $showInMenu = isset($_POST['show_in_menu']) ? 1 : 0;
  18. ​
  19. if ($title === '') {
  20. exit;
  21. }
  22. ​
  23. require_once __DIR__ . '/../includes/slugger.php';
  24. ​
  25. $db = Database::site();
  26. $isHomePage = false;
  27. ​
  28. if ($pageId !== null) {
  29. $homeCheck = $db->prepare('SELECT is_home FROM pages WHERE id = :id LIMIT 1');
  30. $homeCheck->execute(['id' => $pageId]);
  31. $isHomePage = (int) $homeCheck->fetchColumn() === 1;
  32. }
  33. ​
  34. if ($isHomePage) {
  35. $blocksJson = BlockEditor::sanitize((string) ($_POST['blocks_json'] ?? '{"blocks":[]}'), false, true);
  36. $statement = $db->prepare('UPDATE pages SET title = :title, content_blocks = :content, status = :status, show_in_menu = 0 WHERE id = :id AND is_home = 1');
  37. $statement->execute([
  38. 'title' => mb_substr($title, 0, 255),
  39. 'content' => $blocksJson,
  40. 'status' => 'published',
  41. 'id' => $pageId,
  42. ]);
  43. ​
  44. return;
  45. }
  46. ​
  47. $blocksJson = BlockEditor::sanitize((string) ($_POST['blocks_json'] ?? '{"blocks":[]}'), true);
  48. $slug = Slugger::make($title);
  49. ​
  50. if ($pageId !== null) {
  51. $previousMenu = $db->prepare('SELECT show_in_menu FROM pages WHERE id = :id LIMIT 1');
  52. $previousMenu->execute(['id' => $pageId]);
  53. $wasInMenu = (int) $previousMenu->fetchColumn() === 1;
  54. ​
  55. $statement = $db->prepare(
  56. 'UPDATE pages SET title = :title, slug = :slug, content_blocks = :content, status = :status, show_in_menu = :show_in_menu WHERE id = :id'
  57. );
  58. $statement->execute([
  59. 'title' => $title,
  60. 'slug' => $slug,
  61. 'content' => $blocksJson,
  62. 'status' => $status,
  63. 'show_in_menu' => $showInMenu,
  64. 'id' => $pageId,
  65. ]);
  66. ​
  67. if ($showInMenu === 1 && !$wasInMenu) {
  68. SiteFront::appendToCustomMenu('page', $pageId);
  69. }
  70. } else {
  71. $statement = $db->prepare(
  72. 'INSERT INTO pages (author_id, title, slug, content_blocks, status, show_in_menu) VALUES (:author_id, :title, :slug, :content, :status, :show_in_menu)'
  73. );
  74. $statement->execute([
  75. 'author_id' => $currentUser['id'],
  76. 'title' => $title,
  77. 'slug' => $slug,
  78. 'content' => $blocksJson,
  79. 'status' => $status,
  80. 'show_in_menu' => $showInMenu,
  81. ]);
  82. ​
  83. if ($showInMenu === 1) {
  84. SiteFront::appendToCustomMenu('page', (int) $db->lastInsertId());
  85. }
  86. }
  87. ​