HEX
Server: Apache/2.4.52 (Ubuntu)
System: Linux spn-python 5.15.0-89-generic #99-Ubuntu SMP Mon Oct 30 20:42:41 UTC 2023 x86_64
User: arjun (1000)
PHP: 8.1.2-1ubuntu2.20
Disabled: NONE
Upload Files
File: /var/www/html/shootinschool/wp-content/plugins/shootin-school-plugin/supervisors/playerforum.php
<?php

function ins_render_siab_player_forum_instructor()
{
    ob_start();
    global $wpdb;
    // echo  $_GET['id'];
    $comments = $wpdb->get_results("SELECT * FROM " . DB_FORUM . " WHERE playerID = " . $_GET['id'] . " AND forum_type = 1", ARRAY_A);
    // echo "<pre>";
    // print_r($comments);
    $user_id = get_current_user_id();
?>

         <!-- new class  -->
         <div id="wpbody" role="main" class="wpbody-nw">
            <div id="wpbody-content">
               <div class="wrap alert-nw">
                  <div class="css_loader">Loading…</div>
                  <div class="alert alert-info" role="alert">
                  <?php   $playerDetails = $wpdb->get_row("SELECT * FROM " . DB_CHILD_DETAILS . " WHERE id = " . $_GET['id'], ARRAY_A);?>
                     <h3> Player Forum </h3>
                     <small>Discussion About Player : <?php echo $playerDetails['first_name']." ".$playerDetails['last_name']; ?></small>
                  </div>
               </div>
               <?php if (!empty($comments)) {

?>
               <div class="forms-box-main">
                  <div class="title-md">Discussions</div>
                  <?php foreach ($comments as $comment) {
                    $commentedUser = get_userdata($comment['created_by']);

                    $commentedDate = date('M-d-Y h:i:A', strtotime($comment['created_at']));

                ?>
                  <div class="item-start">
                     <strong><?php echo $commentedUser->data->display_name; ?></strong>
                     <small><?php echo $commentedDate; ?></small>
                     <div class="para">
                     <?php echo $comment['comment']; ?>
                     </div>
                  </div>
                  <?php }
            }else{
               ?> <p class="notFound"> No Records Found<p>
            <?php } ?>
                 
               </div>
               
              
               
             
            <div id="respond" class="comment-respond">
                <h3 id="reply-title" class="comment-reply-title">Add Your Update</h3>
                <form id="chatForm">


                    <div class="form-group comment-form-comment">
                        <input type="hidden" value="<?php echo $_GET['id']; ?>" name="playerID" name="playerID">
                        <input type="hidden" value="<?php echo $user_id; ?>" name="customerID" name="customerID">
                        <input type="hidden" value="1" name="forum_type" name="forum_type">
                        <input type="hidden" value="3" name="userType" name="userType">
                        <textarea id="comment" class="form-control" name="comment" rows="9" aria-required="true" required></textarea>
                    </div>
                    <p class="form-submit">
                        <input type="button" onclick="AddComemnt_admin()"  id="btn_submit" value="Send Message">

                    </p>
                </form>
            </div><!-- #respond -->
              
              
            </div>
            <!-- wpbody-content -->

            <div class="clear"></div>
         </div>
         <!-- wpbody -->
         <div class="clear"></div>
     
    
    <script type="text/javascript">
        function AddComemnt_admin() {

            if (jQuery("#chatForm").parsley().validate()) {
                jQuery(".css_loader").show();
                jQuery('#btn_submit').prop('disabled', true);
                var formData = new FormData();
                console.log(formData);
                formData.append("data", jQuery('#chatForm').serialize());
                formData.append("action", 'add_comment_instructor');
                jQuery.ajax({
                    url: ajaxurl,
                    method: "post",
                    dataType: "json",
                    processData: false,
                    contentType: false,
                    data: formData,
                    success: function(response) {
                        jQuery(".css_loader").hide();
                        jQuery('#btn_submit').prop('disabled', false);
                        if (response.status) {
                            toastr.success(response.message);
                            setTimeout(function() {
                                location.reload();
                            }, 1000);

                        } else {
                            // jQuery('#addchild_error_modalBody').html('<p><strong>'+response.message+'</strong></p>');
                            // jQuery('#addchild_error_modal').modal('show');
                        }
                    },
                    error: function(data) {
                        toastr.error(data.message);
                    }
                });
            }
        }
    </script>
<?php

}


add_action('wp_ajax_nopriv_add_comment_instructor', 'add_comment_instructor');
add_action('wp_ajax_add_comment_instructor', 'add_comment_instructor');
function add_comment_instructor()
{

    filter_var_array($_POST, FILTER_SANITIZE_STRING);

    global $wpdb;

    $user_id = get_current_user_id();

    parse_str($_POST['data'], $form_data); //This will convert the string to array

    if (!empty($form_data)) {
        $args = array(
            "forum_type" => $form_data['forum_type'],
            "customerID" => $form_data['customerID'],
            "playerID"   => $form_data['playerID'],
            "comment"    => $form_data['comment'],
            "userType"   => $form_data['userType'],
            "staus"     => 0,
            "created_at" => date('Y-m-d H:i:s'),
            "created_by" => $user_id,
            "updated_at" => date('Y-m-d H:i:s'),
            "updated_by" => $user_id,
        );

        $sql = $wpdb->insert(DB_FORUM, $args);
        echo json_encode(['status' => true, 'message' => "Comments added successfully"]);
        die();
    }
}