76 lines
2.8 KiB
PHP
76 lines
2.8 KiB
PHP
<?php
|
|
require_once 'db/config.php';
|
|
|
|
$id = $_GET['id'] ?? null;
|
|
$product = null;
|
|
|
|
if ($id) {
|
|
$stmt = db()->prepare("SELECT * FROM products WHERE id = ? AND deleted_at IS NULL");
|
|
$stmt->execute([$id]);
|
|
$product = $stmt->fetch();
|
|
}
|
|
|
|
$page_title = $id ? "Edit Product" : "Add Product";
|
|
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
// CSRF Validation
|
|
if (!validate_csrf($_POST['csrf_token'] ?? '')) {
|
|
die("CSRF token validation failed.");
|
|
}
|
|
|
|
$name = $_POST['name'] ?? '';
|
|
$description = $_POST['description'] ?? '';
|
|
$price = $_POST['price'] ?? 0;
|
|
|
|
if ($id) {
|
|
$stmt = db()->prepare("UPDATE products SET name = ?, description = ?, price = ? WHERE id = ?");
|
|
$stmt->execute([$name, $description, $price, $id]);
|
|
} else {
|
|
$stmt = db()->prepare("INSERT INTO products (name, description, price) VALUES (?, ?, ?)");
|
|
$stmt->execute([$name, $description, $price]);
|
|
}
|
|
header("Location: products.php");
|
|
exit;
|
|
}
|
|
|
|
require_once 'includes/header.php';
|
|
?>
|
|
|
|
<div class="row justify-content-center">
|
|
<div class="col-lg-6">
|
|
<div class="d-flex align-items-center mb-4">
|
|
<a href="products.php" class="btn btn-sm btn-outline-secondary me-3"><i class="bi bi-arrow-left"></i></a>
|
|
<h2 class="fw-bold m-0"><?= e($page_title) ?></h2>
|
|
</div>
|
|
|
|
<div class="card p-4">
|
|
<form method="POST">
|
|
<input type="hidden" name="csrf_token" value="<?= csrf_token() ?>">
|
|
|
|
<div class="mb-3">
|
|
<label class="form-label fw-semibold">Product Name <span class="text-danger">*</span></label>
|
|
<input type="text" name="name" class="form-control" required value="<?= e($product['name'] ?? '') ?>">
|
|
</div>
|
|
|
|
<div class="mb-3">
|
|
<label class="form-label fw-semibold">Description</label>
|
|
<textarea name="description" class="form-control" rows="3"><?= e($product['description'] ?? '') ?></textarea>
|
|
</div>
|
|
|
|
<div class="mb-4">
|
|
<label class="form-label fw-semibold">Base Price ($)</label>
|
|
<input type="number" step="0.01" name="price" class="form-control" required value="<?= e($product['price'] ?? '0.00') ?>">
|
|
</div>
|
|
|
|
<hr class="my-4">
|
|
|
|
<div class="d-flex justify-content-end gap-2">
|
|
<a href="products.php" class="btn btn-outline-secondary">Cancel</a>
|
|
<button type="submit" class="btn btn-primary px-4">Save Product</button>
|
|
</div>
|
|
</form>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<?php require_once 'includes/footer.php'; ?>
|