📄 chk_ms.php
字号:
<?php
require_once('libs/session.inc');
require_once('libs/config.inc');
require_once('libs/dbmanager.inc');
require_once('libs/function.inc');
$conn = DBManager::getConnection();
?>
<?php
if($_POST[message] == msword){
$msface = $_POST[face];
$mstext = $_POST[msnr];
$msshop = $_POST[msshop];
$mstime = date('Y年m月d日 H:i:s');
if(!empty($_SESSION['username'])){
$msowner = $_SESSION['username'];
$msname = $_SESSION['username'];
$sex = checklei($_SESSION['username'],$tablepre.user,username,usersex); $mshead = $_POST[myhead];
}
else{
$mshead = substr(strrchr($_POST[myhead],"/"),1);
$msname = $_POST[petname];
$msowner = "vistor";
$sex = $_POST[sex];
}
if($msname == ""||strlen($msname)>30){
msgbox("你的呢称为空!或已大于30个字符!",Back,"");
}
elseif(preg_match("/^$|^c:\\con\\con$| |[,\"\s\t\<\>]|^游客|^Guest/is", $msname)) {
msgbox("呢称包含非法字符!",Back,"");
}
elseif($sex == ""){
msgbox("请选择性别!",Back,"");
}
elseif($mstext == ""){
msgbox("评论内容不能为空!",Back,"");
}
elseif(strlen($mstext)>102400)
{
msgbox("评论内容不能超过 100K !",Back,"");
}
else{
$add = $conn->query("INSERT INTO ".$tablepre."msword (`msname`,`mssex`,`mshead`,`msface`,`mstext`,`msshop`,`msowner`,`mstime`) VALUES ('$msname','$sex','$mshead','$msface','$mstext','$msshop','$msowner','$mstime')");
if($add == true){
msgbox("发表评论成功!",Back,"");
}
}
}
elseif($_POST[message] == mword){
$msface = $_POST[face];
$mstext = $_POST[msnr];
$mstime = date('Y年m月d日 H:i:s');
if(!empty($_SESSION['username'])){
$msowner = $_SESSION['username'];
$msname = $_SESSION['username'];
$sex = checklei($_SESSION['username'],$tablepre.user,username,usersex); $mshead = $_POST[myhead];
}
else{
$mshead = substr(strrchr($_POST[myhead],"/"),1);
$msname = $_POST[petname];
$msowner = "vistor";
$sex = $_POST[sex];
}
if($msname == ""||strlen($msname)>30){
msgbox("你的呢称为空!或已大于30个字符!",Back,"");
}
elseif(preg_match("/^$|^c:\\con\\con$| |[,\"\s\t\<\>]|^游客|^Guest/is", $msname)) {
msgbox("呢称包含非法字符!",Back,"");
}
elseif($sex == ""){
msgbox("请选择性别!",Back,"");
}
elseif($mstext == ""){
msgbox("留言内容不能为空!",Back,"");
}
elseif(strlen($mstext)>102400)
{
msgbox("留言内容不能超过 100K !",Back,"");
}
else{
$add = $conn->query("INSERT INTO ".$tablepre."message (`mname`,`msex`,`mhead`,`mface`,`mnr`,`mperson`,`mtime`) VALUES ('$msname','$sex','$mshead','$msface','$mstext','$msowner','$mstime')");
if($add == true){
msgbox("留言成功!",GoUrl,"msbook.php");
}
}
}
?>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -