From 5bfad3966cea9fdcc5c53d06f35c60f32dc6c0f2 Mon Sep 17 00:00:00 2001 From: Hein Erik Date: Tue, 28 Apr 2026 10:10:13 +0200 Subject: [PATCH] add Multible Images to News --- admin.php | 299 +++++++++++++++++++++++------------------------------- 1 file changed, 126 insertions(+), 173 deletions(-) diff --git a/admin.php b/admin.php index 8c17efe..7f649c6 100644 --- a/admin.php +++ b/admin.php @@ -1,8 +1,7 @@ setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); - // News Tabelle + // News Tabelle initialisieren $db->exec("CREATE TABLE IF NOT EXISTS news ( id INTEGER PRIMARY KEY AUTOINCREMENT, date TEXT, department TEXT, title TEXT, content TEXT, full_text TEXT, image TEXT, link TEXT )"); + + // DB-Schema Updates (Falls noch alte Version) try { $db->exec("ALTER TABLE news ADD COLUMN full_text TEXT"); } catch(PDOException $e) {} + try { $db->exec("ALTER TABLE news ADD COLUMN image2 TEXT"); } catch(PDOException $e) {} + try { $db->exec("ALTER TABLE news ADD COLUMN image3 TEXT"); } catch(PDOException $e) {} + try { $db->exec("ALTER TABLE news ADD COLUMN image4 TEXT"); } catch(PDOException $e) {} + try { $db->exec("ALTER TABLE news ADD COLUMN title_index INTEGER DEFAULT 1"); } catch(PDOException $e) {} - // Benutzer Tabelle $db->exec("CREATE TABLE IF NOT EXISTS users ( id INTEGER PRIMARY KEY AUTOINCREMENT, username TEXT UNIQUE, password_hash TEXT, totp_secret TEXT )"); @@ -78,17 +81,14 @@ try { $userCount = $db->query("SELECT COUNT(*) FROM users")->fetchColumn(); // ============================================================================ -// 3. ERSTEINRICHTUNG (Wenn keine Nutzer existieren) +// 3. ERSTEINRICHTUNG // ============================================================================ if ($userCount == 0) { - $setup_msg = ""; $new_secret = MiniTOTP::generateSecret(); - if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['do_setup'])) { $user = trim($_POST['username']); $pass = $_POST['password']; $secret = $_POST['totp_secret']; - if (!empty($user) && !empty($pass)) { $stmt = $db->prepare("INSERT INTO users (username, password_hash, totp_secret) VALUES (?, ?, ?)"); $stmt->execute([$user, password_hash($pass, PASSWORD_DEFAULT), $secret]); @@ -99,15 +99,10 @@ if ($userCount == 0) { ?> Setup | SG 07 -

Ersteinrichtung

Erstelle den ersten Admin-Zugang.

+

Ersteinrichtung

QR Code

1. Scanne diesen QR-Code mit dem Google Authenticator oder Authy.

-
- - - - -
+
body{font-family:'Segoe UI',sans-serif;background:#f4f4f4;display:flex;justify-content:center;align-items:center;height:100vh;} .login-box{background:#fff;padding:40px;border-radius:8px;box-shadow:0 4px 20px rgba(0,0,0,0.1);max-width:350px;width:100%;text-align:center;border-top:5px solid #d32f2f;} input{width:100%;padding:12px;margin-bottom:15px;border:1px solid #ccc;border-radius:4px;box-sizing:border-box;} button{width:100%;padding:14px;background:#d32f2f;color:white;border:none;font-weight:bold;border-radius:4px;cursor:pointer;} button:hover{background:#9a0007;} .err{color:red;margin-bottom:15px;}
🔒

Admin Login

$login_error
"; ?> -
- - - - -
+
prepare("UPDATE news SET date=?, department=?, title=?, content=?, full_text=?, image=?, link=? WHERE id=?"); - if ($stmt->execute([$_POST['date'], $_POST['department'], $_POST['title'], $_POST['content'], $_POST['full_text'], $final_image_path, $_POST['link'], $_POST['news_id']])) { - $message = "
✓ News erfolgreich aktualisiert!
"; + $stmt = $db->prepare("UPDATE news SET date=?, department=?, title=?, content=?, full_text=?, image=?, image2=?, image3=?, image4=?, title_index=?, link=? WHERE id=?"); + if ($stmt->execute([$_POST['date'], $_POST['department'], $_POST['title'], $_POST['content'], $_POST['full_text'], $img1, $img2, $img3, $img4, $title_idx, $_POST['link'], $_POST['news_id']])) { + $message = "
✓ News (inkl. Galerie) erfolgreich aktualisiert!
"; } } // --- AKTION: NEWS SPEICHERN (NEU) --- if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['save_news'])) { - $final_image_path = ''; - - $uploaded_img = handleImageUpload(); - if ($uploaded_img) { - $final_image_path = $uploaded_img; - } elseif (isset($_POST['image_url']) && !empty($_POST['image_url'])) { - $final_image_path = str_replace(['http://new.sg07-stleon.de/', 'https://new.sg07-stleon.de/', 'new.sg07-stleon.de/', 'new.sg07-stleon.de\\'], '', trim($_POST['image_url'])); - } elseif (isset($_POST['placeholder_image']) && !empty($_POST['placeholder_image'])) { - $final_image_path = $_POST['placeholder_image']; - } + $img1 = handleSingleImage(1); + $img2 = handleSingleImage(2); + $img3 = handleSingleImage(3); + $img4 = handleSingleImage(4); + $title_idx = (int)$_POST['title_index']; - $stmt = $db->prepare("INSERT INTO news (date, department, title, content, full_text, image, link) VALUES (?, ?, ?, ?, ?, ?, ?)"); - if ($stmt->execute([$_POST['date'], $_POST['department'], $_POST['title'], $_POST['content'], $_POST['full_text'], $final_image_path, $_POST['link']])) { - $message = "
✓ News erfolgreich veröffentlicht!
"; + $stmt = $db->prepare("INSERT INTO news (date, department, title, content, full_text, image, image2, image3, image4, title_index, link) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)"); + if ($stmt->execute([$_POST['date'], $_POST['department'], $_POST['title'], $_POST['content'], $_POST['full_text'], $img1, $img2, $img3, $img4, $title_idx, $_POST['link']])) { + $message = "
✓ News (inkl. Galerie) erfolgreich veröffentlicht!
"; } } @@ -227,23 +225,6 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['delete_news'])) { } } -// --- AKTION: NEUEN BENUTZER ANLEGEN --- -$new_user_qr = ""; -if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['add_user'])) { - $new_user = trim($_POST['new_username']); - $new_pass = $_POST['new_password']; - $new_secret = MiniTOTP::generateSecret(); - - try { - $stmt = $db->prepare("INSERT INTO users (username, password_hash, totp_secret) VALUES (?, ?, ?)"); - $stmt->execute([$new_user, password_hash($new_pass, PASSWORD_DEFAULT), $new_secret]); - $url = MiniTOTP::getQRCodeUrl($new_user, $new_secret); - $new_user_qr = "

Benutzer '$new_user' angelegt!

Bitte lasse den neuen Benutzer jetzt sofort diesen QR Code scannen.

QR Code

Geheimer Schlüssel (falls QR nicht geht): $new_secret

"; - } catch(PDOException $e) { - $message = "
Fehler: Benutzername existiert evtl. schon.
"; - } -} - // Edit-Modus prüfen $is_edit = false; $edit_news = null; @@ -251,53 +232,80 @@ if (isset($_GET['edit_id'])) { $stmt = $db->prepare("SELECT * FROM news WHERE id = ?"); $stmt->execute([$_GET['edit_id']]); $edit_news = $stmt->fetch(PDO::FETCH_ASSOC); - if ($edit_news) { - $is_edit = true; - } + if ($edit_news) $is_edit = true; } -// Alle bestehenden News abrufen für die Übersichtstabelle $existing_news = $db->query("SELECT id, date, department, title FROM news ORDER BY id DESC")->fetchAll(PDO::FETCH_ASSOC); + +// HTML Block für einen der 4 Bilder-Uploads +function renderImageSlot($index, $is_edit, $edit_news) { + $img_key = $index === 1 ? 'image' : 'image'.$index; + $current_val = $is_edit ? ($edit_news[$img_key] ?? '') : ''; + $title_idx = $is_edit ? (int)($edit_news['title_index'] ?? 1) : 1; + $is_title = ($title_idx === $index); + + echo "
"; + echo "

Bild Slot $index

"; + + // Radio für Titelbild + echo "
"; + + if($is_edit && $current_val) { + echo ""; + echo "
"; + } + + echo ""; + echo ""; + + echo ""; + echo ""; + + echo ""; + echo ""; + echo "
"; +} ?> Admin Dashboard | SG 07 St. Leon - - -
-

SG 07 Dashboard

+

SG 07 Dashboard MULTIMEDIA EDITION

Hallo, Abmelden @@ -305,7 +313,6 @@ $existing_news = $db->query("SELECT id, date, department, title FROM news ORDER
-
@@ -314,7 +321,6 @@ $existing_news = $db->query("SELECT id, date, department, title FROM news ORDER
- @@ -328,31 +334,19 @@ $existing_news = $db->query("SELECT id, date, department, title FROM news ORDER - - +

Bilder-Galerie (Maximal 4)

+

Du musst nicht alle Slots füllen. Vergiss nicht das Titelbild auszuwählen!

- -
- +
-
- +

Bestehende News verwalten

@@ -401,67 +392,29 @@ $existing_news = $db->query("SELECT id, date, department, title FROM news ORDER Ändern -
+
- - - Noch keine News vorhanden. - -
- +