/
news_edit_page.php
152 lines (133 loc) · 4.22 KB
/
news_edit_page.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
<?php
# MantisBT - a php based bugtracking system
# MantisBT is free software: you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation, either version 2 of the License, or
# (at your option) any later version.
#
# MantisBT is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with MantisBT. If not, see <http://www.gnu.org/licenses/>.
/**
* @package MantisBT
* @copyright Copyright (C) 2000 - 2002 Kenzaburo Ito - kenito@300baud.org
* @copyright Copyright (C) 2002 - 2009 MantisBT Team - mantisbt-dev@lists.sourceforge.net
* @link http://www.mantisbt.org
*/
/**
* MantisBT Core API's
*/
require_once( 'core.php' );
$t_core_path = config_get( 'core_path' );
require_once( $t_core_path.'news_api.php' );
require_once( $t_core_path.'string_api.php' );
news_ensure_enabled();
$f_news_id = gpc_get_int( 'news_id' );
$f_action = gpc_get_string( 'action', '' );
# If deleting item redirect to delete script
if ( 'delete' == $f_action ) {
form_security_validate( 'news_delete' );
$row = news_get_row( $f_news_id );
# This check is to allow deleting of news items that were left orphan due to bug #3723
if ( project_exists( $row['project_id'] ) ) {
access_ensure_project_level( config_get( 'manage_news_threshold' ), $row['project_id'] );
}
helper_ensure_confirmed( lang_get( 'delete_news_sure_msg' ), lang_get( 'delete_news_item_button' ) );
news_delete( $f_news_id );
form_security_purge( 'news_delete' );
print_header_redirect( 'news_menu_page.php', true );
}
# Retrieve news item data and prefix with v_
$row = news_get_row( $f_news_id );
if ( $row ) {
extract( $row, EXTR_PREFIX_ALL, 'v' );
}
access_ensure_project_level( config_get( 'manage_news_threshold' ), $v_project_id );
$v_headline = string_attribute( $v_headline );
$v_body = string_textarea( $v_body );
html_page_top( lang_get( 'edit_news_title' ) );
# Edit News Form BEGIN
?>
<br />
<div align="center">
<form method="post" action="news_update.php">
<?php echo form_security_field( 'news_update' ); ?>
<table class="width75" cellspacing="1">
<tr>
<td class="form-title">
<input type="hidden" name="news_id" value="<?php echo $v_id ?>" />
<?php echo lang_get( 'headline' ) ?>
</td>
<td class="right">
<?php print_bracket_link( 'news_menu_page.php', lang_get( 'go_back' ) ) ?>
</td>
</tr>
<tr class="row-1">
<td class="category" width="25%">
<span class="required">*</span><?php echo lang_get( 'headline' ) ?>
</td>
<td width="75%">
<input type="text" name="headline" size="64" maxlength="64" value="<?php echo $v_headline ?>" />
</td>
</tr>
<tr class="row-2">
<td class="category">
<span class="required">*</span><?php echo lang_get( 'body' ) ?>
</td>
<td>
<textarea name="body" cols="60" rows="10"><?php echo $v_body ?></textarea>
</td>
</tr>
<tr class="row-1">
<td class="category">
<?php echo lang_get( 'post_to' ) ?>
</td>
<td>
<select name="project_id">
<?php
$t_sitewide = false;
if ( access_has_project_level( ADMINISTRATOR ) ) {
$t_sitewide = true;
}
print_project_option_list( $v_project_id, $t_sitewide );
?>
</select>
</td>
</tr>
<tr class="row-2">
<td class="category">
<?php echo lang_get( 'announcement' ) ?><br />
<span class="small"><?php echo lang_get( 'stays_on_top' ) ?></span>
</td>
<td>
<input type="checkbox" name="announcement" <?php check_checked( $v_announcement, 1 ); ?> />
</td>
</tr>
<tr class="row-1">
<td class="category" width="25%">
<?php echo lang_get( 'view_status' ) ?>
</td>
<td width="75%">
<select name="view_state">
<?php print_enum_string_option_list( 'view_state', $v_view_state ) ?>
</select>
</td>
</tr>
<tr>
<td>
<span class="required">* <?php echo lang_get( 'required' ) ?></span>
</td>
<td class="center">
<input type="submit" class="button" value="<?php echo lang_get( 'update_news_button' ) ?>" />
</td>
</tr>
</table>
</form>
</div>
<?php
# Edit News Form END
html_page_bottom( __FILE__ );