diff --git a/threadr/board/board.php b/threadr/board/board.php index 6aed3ac..ce91911 100644 --- a/threadr/board/board.php +++ b/threadr/board/board.php @@ -3,11 +3,13 @@ $pdo = new PDO('mysql:host=%DB_SERVER%;dbname=%DB_NAME%', '%DB_USERNAME%', '%DB_ $statement = $pdo->prepare("SELECT * FROM posts WHERE board_id=:bid ORDER BY post_time asc"); $statement->execute(array("bid"=>$id)); foreach($statement->fetchAll() as $ROW) { + + // get post creator $statement = $pdo->prepare("SELECT * FROM users WHERE id=:uid"); $statement->execute(array("uid"=>$ROW[user_id])); - $post_creator = $statement->fetch(); + // get post content and make sure it doesn't mess with the website $post_title = htmlspecialchars($ROW['title']); $post_creator_name = htmlspecialchars($post_creator['name']); $post_time = htmlspecialchars($ROW['post_time']); @@ -17,6 +19,9 @@ foreach($statement->fetchAll() as $ROW) { $newlines = array("\r\n", "\n\r", "\r", "\n"); // two-character newlines first to prevent placing two line breaks instead of one $post_content = str_replace($newlines, "
", $post_content); + // post id of the original post this is a reply to, negative numbers mean no reply + $reply_to = $ROW['reply_to']; + echo "

$post_title