Размер файла: 2.1Kb
- <?php
- include '../inc/db.php';
- include '../inc/1.php';
- if ($user['admin']==0){header("Location: /index.php");
- exit;}
- $time=time();
- function hc($in){
- return htmlspecialchars($in);
- }
- function me($in){
- return mysql_escape_string($in);
- }
- if (($user['admin']==1) && isset($_GET['del'])){
- $d=intval($_GET['del']);
- mysql_query("DELETE FROM `news` WHERE `id` = '$d'");
- echo "<div class='msg'>Удалено</div>";
- }
- if ($_POST['msg'] && ($user['admin']==1)){
- $msg=mysql_escape_string($_POST['msg']);
- mysql_query("INSERT INTO `news` (`id`, `msg`, `user`, `time`) values (NULL, '$msg', '".$user['id']."', '$time')");
- mysql_query("UPDATE `user` SET `news` = '0'");
- echo "<div class='msg'>Сообщение добавлено</div>";
- }
- mysql_query("UPDATE `user` SET `news` = '1' WHERE `id` = '$user[id]'");
- if (!$_GET['p'])$_GET['p']=1;
- $page=intval($_GET['p']);
- $start=($page*15-15);
- $q=mysql_query("SELECT * FROM `news` ORDER BY `time` DESC LIMIT $start, 15");
- $qq=mt_rand(1111, 9999);
- if ($user['admin']==1){
- if ($_GET['to'])echo "<div class='input'><form action='?' method='POST'>Новость:<br><textarea name='msg'>$to, </textarea><br><input type='submit' name='OK' value='Добавить'></form></div>";
- else
- echo "<div class='input'><form action='?' method='POST'>Новость:<br><textarea name='msg'></textarea><br><input type='submit' name='OK' value='Добавить'></form></div>";
- }
- $a=1;
- while ($f=mysql_fetch_assoc($q)){
- $ank=mysql_fetch_assoc(mysql_query("SELECT * FROM `user` WHERE `id` = '$f[user]'"));
- $ololo=smile(hc($f['msg']));
- echo "<div class='p".($a%2)."'>".im($ank['id'])." <a href='news.php?to=".hc($ank['name'])."'>".hc($ank['name'])."</a>".on($ank['id'])." (".vremja($f['time']).")<br>$ololo";
- if ($user['admin']==1)echo "<br><a href='?del=$f[id]'>[<font color='red'>x</font> Удалить]</a>";
- echo "</div>";
- $a++;
- }
- echo "<div align='center'>";
- if ($page>1)echo "<a href='news.php?p=".($page-1)."'>Назад</a> ";
- if (mysql_num_rows(mysql_query("SELECT * FROM `news`"))>($start+15)) echo "<a href='?p=".($page+1)."'>Далее</a>";
- include_once '../inc/foot.php';
- ?>
-