diff --git a/www/index.html b/www/index.html index e68f7e8..08bcd91 100644 --- a/www/index.html +++ b/www/index.html @@ -43,7 +43,9 @@

Dynamic Web App

-

A more advanced project featuring dynamic routing and interaction with databases. This app demonstrates how to manage data flows and how to handle requests.

+

+ A more advanced project featuring dynamic routing and interaction with databases. This app demonstrates how to manage data flows and how to handle requests. Made with Tailwind. +

Website Code @@ -52,8 +54,8 @@

Notes

-

Lorem, ipsum dolor sit amet consectetur adipisicing elit. Nobis voluptatem aspernatur quam dicta dolorem nisi, quod tempora explicabo accusamus quidem enim unde velit fuga similique omnis deleniti distinctio quis. Architecto. - +

+ Made with Bootstrap.

Website diff --git a/www/notes/Response.php b/www/notes/Response.php new file mode 100644 index 0000000..ed8bffb --- /dev/null +++ b/www/notes/Response.php @@ -0,0 +1,8 @@ +query("SELECT * FROM notes WHERE user_id = 2")->fetchAll(); -$user = $db->query("SELECT name FROM users WHERE id = 2")->fetch(); +$notes = $db->query("SELECT * FROM notes WHERE user_id = ?", $currentUserId)->fetchAll(); +$user = $db->query("SELECT name FROM users WHERE id = ?", $currentUserId)->fetch(); require "views/index.view.php"; diff --git a/www/notes/controllers/note.php b/www/notes/controllers/note.php index 26382b5..806745f 100644 --- a/www/notes/controllers/note.php +++ b/www/notes/controllers/note.php @@ -1,7 +1,28 @@ query("SELECT * FROM notes WHERE id = ?", $_GET['id'])->fetch(); + + +$note = $db->query('SELECT * FROM notes WHERE id = :id', ...[ + 'id' => $_GET['id'], +])->fetch(); + +// No note found +if (!$note) { + abort(); +} + +// Note from another user +if ($note['user_id'] !== $currentUserId) { + abort(Response::FORBIDDEN); +} require "views/note.view.php"; diff --git a/www/notes/functions.php b/www/notes/functions.php index c78bec4..6e78650 100644 --- a/www/notes/functions.php +++ b/www/notes/functions.php @@ -4,4 +4,10 @@ function dd(mixed $var): void { highlight_string(""); die(); +} + +function abort(int $statusCode = Response::NOT_FOUND): void +{ + http_response_code($statusCode); + die(); } \ No newline at end of file diff --git a/www/notes/index.php b/www/notes/index.php index 6bf271a..75b3a7f 100644 --- a/www/notes/index.php +++ b/www/notes/index.php @@ -6,6 +6,6 @@ $config = require "config.php"; require "Database.php"; $db = new Database($config["DATABASE"]); - +$currentUserId = 3; require "router.php"; \ No newline at end of file