=1){ $postId = preg_replace("/^post-/i", "", $tmpUri); $postId = preg_replace("/-.+$/i", "", $postId); $nick = mysqli_real_escape_string($conn, trim(strip_tags($_POST['nick']))); $comment = mysqli_real_escape_string($conn, trim(strip_tags($_POST['comment']))); if (strlen($nick)<1 || strlen($comment)<1){ $_POST['commentStamp'] = ""; } else { $z = "select * from mblog_post where id='".mysqli_real_escape_string($conn, $postId)."'"; $q = mysqli_query($conn, $z); $r = mysqli_fetch_assoc($q); if (strlen($r['id'])>0){ $hash = md5($nick.$comment.mysqli_escape_string($conn, $_SERVER['REMOTE_ADDR'])); $z = "insert into mblog_comment (post_id, nick, comment, ip, hash) values ("; $z .= "'".mysqli_real_escape_string($conn, $postId)."', "; $z .= "'".$nick."', "; $z .= "'".mysqli_real_escape_string($conn, trim($_POST['comment']))."', "; $z .= "'".mysqli_real_escape_string($conn, $_SERVER['REMOTE_ADDR'])."', "; $z .= "'".$hash."'"; $z .= ");"; $q = mysqli_query($conn, $z); mail("info@mobile-solutions.pl", "gabrysiowo komentarz [".ami(mysqli_real_escape_string($conn, $_SERVER['REMOTE_ADDR']))."]", "dodano komentarz [[".ami($nick)."]]"); } } } if ((isAuthenticated()==-1 || isAuthenticated()==0)) { $displayContent = getAuthPage(isAuthenticated()); } else if ($tmpUri=='kontakt'){ $displayContent = getPage('kontakt'); } else if ($tmpUri=='o-mnie'){ $displayContent = getPage('o-mnie'); } else if (preg_match("/^archiwum-[0-9]{4}-[0-9]{2}$/i", $tmpUri)) { $date = preg_replace("/archiwum-/i", "", $tmpUri); $displayContent = getArchivePosts($date); } else if (preg_match("/^tag-[0-9]+-.+$/i", $tmpUri)) { $tag = preg_replace("/^tag-/i", "", $tmpUri); $tag = preg_replace("/-.+$/", "", $tag); $displayContent = getTagPosts($tag); } else if (preg_match("/^post-[0-9]+-.+$/i", $tmpUri)) { $post = preg_replace("/^post-/i", "", $tmpUri); $post = preg_replace("/-.+$/", "", $post); $displayContent = displayPost($post); } if (strlen($displayContent)<1) { //assume that this is main page $displayContent = getMainMenuPosts(); } ?> <? print $GLOBAL_SETTINGS['documentTitle']; ?>