trim($_POST['title'] ?? ''), 'content' => trim($_POST['content'] ?? ''), 'excerpt' => trim($_POST['excerpt'] ?? ''), 'slug' => trim($_POST['slug'] ?? '') ?: generate_slug($_POST['title'] ?? ''), 'category_id' => intval($_POST['category_id'] ?? 1), 'template' => $_POST['template'] ?? 'flow', 'status' => $_POST['status'] ?? 'published' ]; // Sanitize rich-text content to prevent XSS $data['content'] = sanitize_html($data['content']); if (empty($data['title']) || empty($data['content'])) { $message = '
标题和内容不能为空
'; } else { // Check slug uniqueness (only if slug changed or new post) $existing = []; if (!empty($_POST['id'])) { $existing = get_post_by_id(intval($_POST['id'])) ?? []; } $slug_check = $data['slug']; $db = get_db(); $exclude_id = $existing['id'] ?? 0; $stmt = $db->prepare("SELECT id FROM posts WHERE slug = ? AND deleted_at IS NULL AND id != ?"); $stmt->bind_param('si', $slug_check, $exclude_id); $stmt->execute(); $res = $stmt->get_result(); if ($res->num_rows > 0) { $data['slug'] = $data['slug'] . '-' . time(); } if (!empty($_POST['id'])) { update_post(intval($_POST['id']), $data); $message = '
文章已更新
'; } else { create_post($data); $message = '
文章已创建
'; } } } if (!empty($_GET['edit'])) { $edit_post = get_post_by_id(intval($_GET['edit'])) ?? []; } if (!empty($_GET['delete'])) { csrf_verify('BOTH'); delete_post(intval($_GET['delete'])); $message = '
文章已删除
'; } $categories = get_categories(); ?> 文章管理 - ZhangPu Blog

取消

文章管理 (共 篇)

标题 分类 模板 状态 浏览 发布时间 操作
编辑 查看 删除
暂无文章
1): ?>