Part on Escaping Chars finished

This commit is contained in:
Patryk Hegenberg 2022-12-19 20:55:48 +01:00
parent c0aeac2632
commit a597943b45
3 changed files with 8 additions and 3 deletions

View file

@ -1,6 +1,11 @@
<?php
$heading = 'Create Note';
$username = 'appUser';
$password = 'password';
$config = require('config.php');
$db = new Database($config['database'], $username, $password);
if($_SERVER['REQUEST_METHOD'] === 'POST'){
dd($_POST);
$db->query("INSERT INTO notes (body, user_id) VALUES (:body, :user_id)", ['body' => $_POST['body'], 'user_id' => 1]);
}
require 'views/note-create.view.php';

View file

@ -6,7 +6,7 @@
<p class="mb-6">
<a href="/notes" class="text-blue-500 hover:underline">go back</a>
</p>
<p><?= $note['body'] ?></p>
<p><?= htmlspecialchars($note['body']) ?></p>
</div>
</main>
<?php require ('partials/footer.php') ?>

View file

@ -7,7 +7,7 @@
<?php foreach ($notes as $note) : ?>
<li>
<a href="/note?id=<?= $note['id'] ?>" class="text-blue-500 hover:underline">
<?= $note['body'] ?>
<?= htmlspecialchars($note['body']) ?>
</a>
</li>
<?php endforeach; ?>