diff options
Diffstat (limited to 'lib/deck/rment.php')
-rw-r--r-- | lib/deck/rment.php | 18 |
1 files changed, 18 insertions, 0 deletions
diff --git a/lib/deck/rment.php b/lib/deck/rment.php new file mode 100644 index 0000000..d3a87e0 --- /dev/null +++ b/lib/deck/rment.php @@ -0,0 +1,18 @@ +<?php + +require("lib/markdown.php"); + +assert_redir(count($args) >= 3, 'deck'); +$cardid = intval($args[2]); + +$card = mysql_fetch_assoc(sql( + "SELECT decks.id AS deckid, decks.owner AS deckowner, decks.name AS deckname, cards.name AS name, cards.text_md AS text, cards.number AS number ". + "FROM cards LEFT JOIN decks ON decks.id = cards.deck ". + "WHERE cards.id = $cardid")); +assert_error($card && $card["deckowner"] == $user['id'], + "This card does not exist, or you are not allowed to edit it."); + +token_validate("Do you really want to delete this card ?", "view-deck-". $card['deckid']); +sql("DELETE FROM cards WHERE id = $cardid"); +sql("UPDATE cards SET number = number - 1 WHERE number > " . $card['number'] . " AND deck = " . $card['deckid']); +header("Location: view-deck-" . $card['deckid']); |