$question=$db->query("SELECT * FROM questions WHERE id = '".$_GET["q"]."';")->fetchArray(SQLITE3_ASSOC);
if(!$question||!$question["id"]){
echo("Question not found.");
}
elseif($question["user"]!=$_SESSION["uid"]){
echo("You're not allowed to perform that task.");
}
else{
$db->exec("UPDATE questions SET answer = '".htmlspecialchars($_POST["answer_body"],ENT_QUOTES)."', a_date = ".strtotime("now")." WHERE id = ".$_GET["q"].";");
if($pretty_urls){
header("Location: /user/".$db->querySingle("SELECT username FROM users WHERE id = ".$question["user"].";"));
die();
}
else{
header("Location: /user.php?q=".$db->querySingle("SELECT username FROM users WHERE id = ".$question["user"].";"));
die();
}
}
}
}
$db=newSQLite3('../ask.db');
$question=$db->query("SELECT * FROM questions WHERE id = '".$_GET["q"]."';")->fetchArray(SQLITE3_ASSOC);