123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687 |
- <?php
-
- require_once 'config.php';
- require_once 'dbh.inc.php';
- require_once 'checkLogin.php';
-
-
-
-
- if(isset($_POST['newMilestone'])) {
-
-
-
- $experienceID = mysqli_real_escape_string($connection, trim($_POST['id_experience']));
- $milestoneTitle = mysqli_real_escape_string($connection, trim($_POST['mil_title']));
- $milestoneDate = mysqli_real_escape_string($connection, trim($_POST['mil_date']));
-
-
-
-
- if($experienceID === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify experience ID."));
- exit();
- } else if(mysqli_query($connection, "SELECT * FROM experience WHERE id = $experienceID;")->num_rows !== 1) {
- http_response_code(400);
- echo json_encode(array("error" => "Given experience ID ($experienceID) not in database."));
- exit();
- }
-
-
-
- if($milestoneTitle === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify milestone title."));
- exit();
- } else if(mb_strlen($milestoneTitle) > 256) {
- http_response_code(400);
- echo json_encode(array("error" => "Milestone title too long (max. is 256 characters)."));
- exit();
- }
-
-
-
-
-
-
- function validDate($date) {
- $d = date_create_from_format("Y-m-d", $date);
- return $d && date_format($d, "Y-m-d") === $date;
- }
-
- if($milestoneDate === "") {
- http_response_code(400);
- echo json_encode(array("error" => "Please specify milestone date."));
- exit();
- } else if(!validDate($milestoneDate)) {
- http_response_code(400);
- echo json_encode(array("error" => "Milestone date ($milestoneDate) given in wrong format (use YYYY-MM-DD instead)."));
- exit();
- }
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- $query = "INSERT INTO milestone (title, date, id_experience) VALUES ('".$milestoneTitle."','".$milestoneDate."','".$experienceID."');";
- if(!mysqli_query($connection, $query)) die("Error: Couldn't create milestone<br>".mysqli_error($connection));
-
-
-
-
-
- }
-
- ?>
|