session_start();
$approved = $_SESSION['approved'];
if ($approved != 'yes')
{
header ("Location: login_form.html");
}
include 'nav.html';
$myid = $_SESSION['loggedid'];
include 'connect.php';
$postedtopicid = $_POST['topicid'];
if ($postedtopicid)
{
$userid = $_POST['userid'];
$message = $_POST['message'];
$time = date("Y-m-d H:i:s",mktime());
$sql = mysql_query("insert into posts (message,timeofpost,memberid ,topicid) values ('$message','$time','$userid','$postedtopicid')");
if ($sql) echo "Post Entered
";
}
$topicid = $_GET['topicid'];
if ($topicid == "")
{
header("Location: index.php");
}
$sql = mysql_query("select * from posts where topicid = '$topicid'");
$num = mysql_num_rows($sql);
$numresultsperpage = 4;
$pages = ceil($num/$numresultsperpage);
$screen = $_GET['screen'];
if ($screen == "")
{
$screen = 0;
}
$start = $screen * $numresultsperpage;
$next = $screen + 1;
$previous = $screen - 1;
$sql = mysql_query("select users.name,users.email,DATE_FORMAT(posts.timeofpost, '%W, %M %d, %Y %h:%i:%s %p'), posts.message,posts.memberid, posts.id from users, posts where users.id = posts.memberid and posts.topicid = '$topicid' order by posts.id desc limit $start,$numresultsperpage");
while ($row = mysql_fetch_array($sql))
{
$posterid = $row[4];
$postid = $row[5];
$name = $row[0];
$email = $row[1];
$message = $row[3];
$date = $row[2];
echo "Message:$message
Posted by: $name
$email
On: $date
";
if ($myid == $posterid)
{
echo "Edit | Delete";
}
echo "
";
}
if ($screen > 0)
{
$url = "Previous"; }
for ($i=0;$i<$pages;$i++)
{
$pagenum = $i+1;
if ($screen == $i)
{
$url .= "| $pagenum";
}
else
{
$url .= "| $pagenum";
}
}
if ($screen < $pages - 1)
{
$url .= "| Next";
}
echo $url;
?>
Add to this string
