Current directory: /home/klas4s23/domains/585455.klas4s23.mid-ica.nl/public_html/Gastenboek/uploads
<?php
include 'connect.php';
if ($_SERVER["REQUEST_METHOD"] == "POST") {
// Verkrijg de ingevoerde gegevens
$naam = $_POST["naam"];
$bericht = $_POST["bericht"];
$file_path = '';
// Handle image upload
if (isset($_FILES['image']) && $_FILES['image']['error'] == 0) {
$file_tmp = $_FILES['image']['tmp_name'];
$file_type = $_FILES['image']['type'];
$file_name = uniqid() . '.' . pathinfo($_FILES['image']['name'], PATHINFO_EXTENSION);
$file_path = 'uploads/' . $file_name;
if (move_uploaded_file($file_tmp, $file_path)) {
// Image uploaded successfully
} else {
// Error uploading image
$file_path = '';
}
}
// Verbinding met de database
// Controleer op fouten in de verbinding
if ($conn->connect_error) {
die("Connection failed: " . $conn->connect_error);
}
// Gebruik prepared statements om SQL-injecties te voorkomen
$sql = "INSERT INTO berichten (naam, bericht, image) VALUES (?, ?, ?)";
$stmt = $conn->prepare($sql);
// Controleer op fouten bij het voorbereiden van de statement
if (!$stmt) {
die("Error preparing statement: " . $conn->error);
}
// Bind de parameters aan de statement
$stmt->bind_param("sss", $naam, $bericht, $file_path);
// Voer de statement uit
if ($stmt->execute()) {
header("Location: index.php"); // Herlaad de pagina
} else {
echo "Error: " . $sql . "<br>" . $conn->error;
}
// Sluit de statement en de databaseverbinding
$stmt->close();
$conn->close();
}
?>