@ -4,14 +4,7 @@ function admin_faq() {
$faqs_html = "";
$faqs_html = "";
$faqs = sql_select("SELECT * FROM `FAQ`");
$faqs = sql_select("SELECT * FROM `FAQ`");
foreach ($faqs as $faq) {
foreach ($faqs as $faq) {
$faqs_html .= sprintf(
$faqs_html .= sprintf('< tr > < td > < dl > < dt > %s< / dt > < dd > %s< / dd > < / dl > < / td > ' . '< td > < dl > < dt > %s< / dt > < dd > %s< / dd > < / dl > < / td > ' . '< td > < a href = "%s&action=edit&id=%s" > Edit< / a > < / td > < / tr > ', $faq['Frage_de'], $faq['Antwort_de'], $faq['Frage_en'], $faq['Antwort_en'], page_link_to('admin_faq'), $faq['FID']);
'< tr > < td > < dl > < dt > %s< / dt > < dd > %s< / dd > < / dl > < / td > '
. '< td > < dl > < dt > %s< / dt > < dd > %s< / dd > < / dl > < / td > '
. '< td > < a href = "%s&action=edit&id=%s" > Edit< / a > < / td > < / tr > ',
$faq['Frage_de'], $faq['Antwort_de'],
$faq['Frage_en'], $faq['Antwort_en'],
page_link_to('admin_faq'), $faq['FID']
);
}
}
return template_render('../templates/admin_faq.html', array (
return template_render('../templates/admin_faq.html', array (
'link' => page_link_to("admin_faq"),
'link' => page_link_to("admin_faq"),
@ -20,17 +13,12 @@ function admin_faq() {
} else {
} else {
switch ($_REQUEST['action']) {
switch ($_REQUEST['action']) {
case 'create' :
case 'create' :
$frage = strip_request_item_nl('frage');
$frage = strip_request_item_nl('frage');
$antwort = strip_request_item_nl('antwort');
$antwort = strip_request_item_nl('antwort');
$question = strip_request_item_nl('question');
$question = strip_request_item_nl('question');
$answer = strip_request_item_nl('answer');
$answer = strip_request_item_nl('answer');
sql_query("INSERT INTO `FAQ` SET `Frage_de`='" . sql_escape($frage)
sql_query("INSERT INTO `FAQ` SET `Frage_de`='" . sql_escape($frage) . "', `Frage_en`='" . sql_escape($question) . "', `Antwort_de`='" . sql_escape($antwort) . "', `Antwort_en`='" . sql_escape($answer) . "'");
. "', `Frage_en`='" . sql_escape($question)
. "', `Antwort_de`='" . sql_escape($antwort)
. "', `Antwort_en`='" . sql_escape($answer)
. "'"
);
header("Location: " . page_link_to("admin_faq"));
header("Location: " . page_link_to("admin_faq"));
break;
break;
@ -39,34 +27,29 @@ function admin_faq() {
if (isset ($_REQUEST['id']) & & preg_match("/^[0-9]{1,11}$/", $_REQUEST['id']))
if (isset ($_REQUEST['id']) & & preg_match("/^[0-9]{1,11}$/", $_REQUEST['id']))
$id = $_REQUEST['id'];
$id = $_REQUEST['id'];
else
else
return error("Incomplete call, missing FAQ ID.");
return error("Incomplete call, missing FAQ ID.", true );
$faq = sql_select("SELECT * FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
$faq = sql_select("SELECT * FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
if (count($faq) > 0) {
if (count($faq) > 0) {
list ($faq) = $faq;
list ($faq) = $faq;
$frage = strip_request_item_nl('frage');
$frage = strip_request_item_nl('frage');
$antwort = strip_request_item_nl('antwort');
$antwort = strip_request_item_nl('antwort');
$question = strip_request_item_nl('question');
$question = strip_request_item_nl('question');
$answer = strip_request_item_nl('answer');
$answer = strip_request_item_nl('answer');
sql_query("UPDATE `FAQ` SET `Frage_de`='" . sql_escape($frage)
sql_query("UPDATE `FAQ` SET `Frage_de`='" . sql_escape($frage) . "', `Frage_en`='" . sql_escape($question) . "', `Antwort_de`='" . sql_escape($antwort) . "', `Antwort_en`='" . sql_escape($answer) . "' WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
. "', `Frage_en`='" . sql_escape($question)
. "', `Antwort_de`='" . sql_escape($antwort)
. "', `Antwort_en`='" . sql_escape($answer)
. "' WHERE `FID`=" . sql_escape($id) . " LIMIT 1"
);
header("Location: " . page_link_to("admin_faq"));
header("Location: " . page_link_to("admin_faq"));
} else
} else
return error("No FAQ found.");
return error("No FAQ found.", true);
break;
break;
case 'edit' :
case 'edit' :
if (isset ($_REQUEST['id']) & & preg_match("/^[0-9]{1,11}$/", $_REQUEST['id']))
if (isset ($_REQUEST['id']) & & preg_match("/^[0-9]{1,11}$/", $_REQUEST['id']))
$id = $_REQUEST['id'];
$id = $_REQUEST['id'];
else
else
return error("Incomplete call, missing FAQ ID.");
return error("Incomplete call, missing FAQ ID.", true );
$faq = sql_select("SELECT * FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
$faq = sql_select("SELECT * FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
if (count($faq) > 0) {
if (count($faq) > 0) {
@ -81,14 +64,14 @@ function admin_faq() {
'answer' => $faq['Antwort_en']
'answer' => $faq['Antwort_en']
));
));
} else
} else
return error("No FAQ found.");
return error("No FAQ found.", true );
break;
break;
case 'delete' :
case 'delete' :
if (isset ($_REQUEST['id']) & & preg_match("/^[0-9]{1,11}$/", $_REQUEST['id']))
if (isset ($_REQUEST['id']) & & preg_match("/^[0-9]{1,11}$/", $_REQUEST['id']))
$id = $_REQUEST['id'];
$id = $_REQUEST['id'];
else
else
return error("Incomplete call, missing FAQ ID.");
return error("Incomplete call, missing FAQ ID.", true );
$faq = sql_select("SELECT * FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
$faq = sql_select("SELECT * FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
if (count($faq) > 0) {
if (count($faq) > 0) {
@ -97,7 +80,7 @@ function admin_faq() {
sql_query("DELETE FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
sql_query("DELETE FROM `FAQ` WHERE `FID`=" . sql_escape($id) . " LIMIT 1");
header("Location: " . page_link_to("admin_faq"));
header("Location: " . page_link_to("admin_faq"));
} else
} else
return error("No FAQ found.");
return error("No FAQ found.", true );
break;
break;
}
}
}
}