много ми е объркан кода ама много някои може ли да си отвори notepad и да отдели 5 минутки да го подреди ще съм му задължен :?
<tr>
<td class=''>
<hr width='595' size='1' color='#dadada' >
<br />
<br />
<br />
<div id="comment">
<form action="" method="post">
Име: <br />
<input type="text" name="name" id="name" maxlength="20" size="17" value="<?php echo ''.$_POST[name].''; ?>"><br />
Коментар:<br />
<textarea name="comment" cols="45" rows="4" class='' id="m" ><?php echo ''.$_POST[comment].''; ?></textarea><br />
Въведи изпълнителя:
<input type='text' name='code' size='5'>
<a href="javascript:reload_img('captcha2');">
<img src='<?php echo "$site_url"; ?>/captcha' border='0' id='captcha2' title="покажи друг" alt='Image captcha'></a>
</a>
<br />
<br />
<input name="submitcomment" type="submit" value="Изпрати">
<input name="submit" type="reset" value="Изчисти">
</div>
<br />
<br />
<?php
$idt = intval($_GET['id']);
$sql_query = mysql_query("SELECT * FROM `news` WHERE id='$idt'") or die(mysql_error());
while ($row = mysql_fetch_array($sql_query))
{
$active_write_comment = $row['active_write_comment'];
if ($active_write_comment == "0")
{
echo "<br />Неможе да пишете коментари.";
}
if ($active_write_comment == "1"){
$id = $_GET['id'];
if ($_POST['submitcomment'])
{
if ($_POST[name] == null){
echo "<font color='#aa0033'>Не си написал име.</font><br />";
}
else
{
if ($_POST[comment] == null){
echo "<font color='#aa0033'>Не си написал коментар.</font><br />";
}
else
{
$comment = $_POST['comment'];
if(strlen($comment) < 4){
echo "<font color='#aa0033'>Коментара е твърде кратък.</font><br /><br />";}
else {
if ($_POSTКод:!=$_COOKIE[imgcodepage]){ echo "<font color='#aa0033'>Грешен изпълнител.</font><br />"; } else { $sel = mysql_query("SELECT * FROM news_comment ORDER BY id DESC LIMIT 1") or die (mysql_error); $fetch = mysql_fetch_array($sel); $kom = $fetch['comment']; if ($kom == $_POST['comment']){ echo "<font color='#aa0033'>Коментара не може да е като предишния.</font><br />"; } else { $date = date("d.m.y H:i"); $time = time(); $sql_comment_active = mysql_query("SELECT * FROM options WHERE comment_active='1'") or die (mysql_error()); if(mysql_num_rows($sql_comment_active)==0){ $sql = mysql_query("INSERT INTO news_comment (id, news, nick, comment, comtoday, date, active_comment) VALUES (NULL, '$id', '$_POST[name]', '$_POST[comment]', '$time', '$date', '1')") or die(mysql_error()); $nums = mysql_query("SELECT * FROM `news` WHERE `id`='$_GET[id]'") or die (mysql_error()); while ($row = mysql_fetch_array($nums)) { $comments = htmlspecialchars($row['comments']); $comments++; $sql = ("UPDATE `news` SET comments='$comments' WHERE id='$row[id]'"); mysql_query($sql) or die (mysql_error()); } echo "Коментара е добавен успешно.<br />"; } else { $sql = mysql_query("INSERT INTO news_comment (id, news, nick, comment, comtoday, date, active_comment) VALUES (NULL, '$id', '$_POST[name]', '$_POST[comment]', '$time', '$date', '0')") or die(mysql_error()); $nums = mysql_query("SELECT * FROM `news` WHERE `id`='$_GET[id]'") or die (mysql_error()); while ($row = mysql_fetch_array($nums)) { $comments = htmlspecialchars($row['comments']); $comments++; $sql = ("UPDATE `news` SET comments='$comments' WHERE id='$row[id]'"); mysql_query($sql) or die (mysql_error()); } echo "След удобрение от администратор коментара ти ще бъде уробрен.<br />"; } } } } } } } } else { $errmsg = mysql_error(); echo "$errmsg"; } echo "<form><br>"; $query = mysql_query("SELECT * FROM `news_comment` WHERE `news`='$id' AND active_comment='1' ORDER BY id DESC") or die(mysql_error()); while ($raw = mysql_fetch_array($query)) { $nick = htmlspecialchars($raw['nick']); $comment = htmlspecialchars($raw['comment']); $comtoday = $raw['comtoday']; // забранени думи символи от хакери str_"I"replace независино думата дали е с големи или малки букви тя пак я замества $comment = str_ireplace("allowscriptaccess", "<font color=''>*****************</font> ", "$comment"); $comment = str_ireplace("javascript", "<font color=''>**********</font> ", "$comment"); // // забранени цензури $comment = str_replace("pedal", "<font color='#aa0033'>CENSURED</font> ", "$comment"); $comment = str_replace("sex", "<font color='#aa0033'>CENSURED</font> ", "$comment"); $comment = str_replace("kopele", "<font color='#aa0033'>CENSURED</font> ", "$comment"); $comment = str_replace("umri", "<font color='#aa0033'>CENSURED</font> ", "$comment"); $comment = str_replace("duhai", "<font color='#aa0033'>CENSURED</font> ", "$comment"); // $spam=mysql_query("SELECT * FROM options WHERE spam_news='1'") or die (mysql_error()); if(mysql_num_rows($spam)==0){ $comment = preg_replace("/(http\:\/\/|www\.)([^\s]+)/i", "<b>спам..</b>", $comment); } else{ $comment = preg_replace("/(http\:\/\/|www\.)([^\s]+)/i", "<a href='http://$2' target='_blank'>$1$2</a>", $comment); } echo "<tr><td> <div style='width: 402px; height: 27px; background: #DDDDDD;'> "; echo "<font size='2'> От:</font> <span style='font-family: comic sans ms,sans-serif;'>$nick </span> ".predi($comtoday,time(),true)." </div>"; // Символи на ред в коментарите $comment = "$comment"; $comment = wordwrap($comment, 65, "<br />", true); // echo "<span class=\"style2\"></span> <div style='width: 400px; border: 1px solid #DDDDDD;'> $comment <br /><br /> </div><br /></td> </tr>"; } } ?>[/quote]