Lorem, ipsum dolor sit amet consectetur adipisicing elit. Nobis voluptatem aspernatur quam dicta dolorem nisi, quod tempora explicabo accusamus quidem enim unde velit fuga similique omnis deleniti distinctio quis. Architecto.
-
+
Website
diff --git a/www/notes/Response.php b/www/notes/Response.php
new file mode 100644
index 0000000..ed8bffb
--- /dev/null
+++ b/www/notes/Response.php
@@ -0,0 +1,8 @@
+query("SELECT * FROM notes WHERE user_id = 2")->fetchAll();
-$user = $db->query("SELECT name FROM users WHERE id = 2")->fetch();
+$notes = $db->query("SELECT * FROM notes WHERE user_id = ?", $currentUserId)->fetchAll();
+$user = $db->query("SELECT name FROM users WHERE id = ?", $currentUserId)->fetch();
require "views/index.view.php";
diff --git a/www/notes/controllers/note.php b/www/notes/controllers/note.php
index 26382b5..806745f 100644
--- a/www/notes/controllers/note.php
+++ b/www/notes/controllers/note.php
@@ -1,7 +1,28 @@
query("SELECT * FROM notes WHERE id = ?", $_GET['id'])->fetch();
+
+
+$note = $db->query('SELECT * FROM notes WHERE id = :id', ...[
+ 'id' => $_GET['id'],
+])->fetch();
+
+// No note found
+if (!$note) {
+ abort();
+}
+
+// Note from another user
+if ($note['user_id'] !== $currentUserId) {
+ abort(Response::FORBIDDEN);
+}
require "views/note.view.php";
diff --git a/www/notes/functions.php b/www/notes/functions.php
index c78bec4..6e78650 100644
--- a/www/notes/functions.php
+++ b/www/notes/functions.php
@@ -4,4 +4,10 @@ function dd(mixed $var): void
{
highlight_string("");
die();
+}
+
+function abort(int $statusCode = Response::NOT_FOUND): void
+{
+ http_response_code($statusCode);
+ die();
}
\ No newline at end of file
diff --git a/www/notes/index.php b/www/notes/index.php
index 6bf271a..75b3a7f 100644
--- a/www/notes/index.php
+++ b/www/notes/index.php
@@ -6,6 +6,6 @@ $config = require "config.php";
require "Database.php";
$db = new Database($config["DATABASE"]);
-
+$currentUserId = 3;
require "router.php";
\ No newline at end of file