UpdateArticleController
extends AdminController
in package
UpdateArticleController - Article Update for Administrators
Handles the update of existing articles with image upload to Cloudinary. Only accessible to users with BDE (admin) status.
Refactored to use Data Mapper pattern with Article entities and ArticleRepository.
Features:
- Article form display with pre-filled data
- Form validation (CSRF, required fields)
- Optional image upload to Cloudinary (keeps existing if not provided)
- Article data update via repository
- Success/error feedback with flash messages
Tags
Table of Contents
Properties
- $app : Application
- $auth : AuthManager
- $csrf : CsrfProtection
- $request : Request
- $response : Response
- $session : SessionManager
Methods
- __construct() : void
- Constructor - Handle article update form display and submission
- getCsrfTokenForJs() : string
- Get the CSRF token for JavaScript usage
- redirect() : never
- Redirect to a URL
- redirectWithError() : never
- Redirect with an error message
- redirectWithSuccess() : never
- Redirect with a success message
- render() : void
- Render a view with automatic variable injection
- setError() : void
- Set an error flash message
- setFlash() : void
- Set a flash message
- setInfo() : void
- Set an info flash message
- setSuccess() : void
- Set a success flash message
- setWarning() : void
- Set a warning flash message
- validateCsrf() : bool
- Validate the CSRF token from the request
- displayUpdateForm() : void
- Display the article update form with pre-filled data
- getArticleFromRequest() : Article|null
- Get article from request using slug
- updateArticle() : void
- Update an existing article
Properties
$app
protected
Application
$app
$auth
protected
AuthManager
$auth
$csrf
protected
CsrfProtection
$csrf
$request
protected
Request
$request
$response
protected
Response
$response
$session
protected
SessionManager
$session
Methods
__construct()
Constructor - Handle article update form display and submission
public
__construct() : void
GET request: Displays the article update form with pre-filled data POST request with action=submitUpdate: Processes the form submission
Requires 'slug' query parameter to identify the article to update.
getCsrfTokenForJs()
Get the CSRF token for JavaScript usage
protected
getCsrfTokenForJs() : string
This method is useful for embedding the token in JavaScript or as a meta tag for automatic AJAX injection.
Return values
string —The current CSRF token
redirect()
Redirect to a URL
protected
redirect(string $url) : never
Parameters
- $url : string
-
Destination URL
Return values
never —Terminates execution
redirectWithError()
Redirect with an error message
protected
redirectWithError(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Error message
Return values
never —Terminates execution
redirectWithSuccess()
Redirect with a success message
protected
redirectWithSuccess(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Success message
Return values
never —Terminates execution
render()
Render a view with automatic variable injection
protected
render(string $viewPath[, array<string, mixed> $data = [] ]) : void
This method automatically injects services and data that all views need, eliminating the need to directly access $_SESSION or global functions.
Automatically injected variables:
- $csrf: CsrfProtection service
- $auth: AuthManager service
- $request: Request object
- $flash: Flash messages array (success, error, warning, info)
- $user: Current user data (null if not logged in)
Parameters
- $viewPath : string
-
View path (e.g., 'users/loginPageView')
- $data : array<string, mixed> = []
-
View-specific data
setError()
Set an error flash message
protected
setError(string $message) : void
Parameters
- $message : string
-
Error message
setFlash()
Set a flash message
protected
setFlash(string $type, string $message) : void
Parameters
- $type : string
-
Message type (success, error, warning, info)
- $message : string
-
Message to display
setInfo()
Set an info flash message
protected
setInfo(string $message) : void
Parameters
- $message : string
-
Info message
setSuccess()
Set a success flash message
protected
setSuccess(string $message) : void
Parameters
- $message : string
-
Success message
setWarning()
Set a warning flash message
protected
setWarning(string $message) : void
Parameters
- $message : string
-
Warning message
validateCsrf()
Validate the CSRF token from the request
protected
validateCsrf([string|null $token = null ]) : bool
Supports both traditional POST body tokens and modern AJAX header tokens. Checks in order:
- Provided token parameter
- POST body 'csrf_token' field
- X-CSRF-Token HTTP header (for AJAX requests)
Parameters
- $token : string|null = null
-
Token to validate (if null, retrieves from POST or header)
Return values
bool —True if valid, false otherwise
displayUpdateForm()
Display the article update form with pre-filled data
private
displayUpdateForm() : void
Retrieves the article by slug and renders the update form. Redirects to home if article not found or slug is invalid.
getArticleFromRequest()
Get article from request using slug
private
getArticleFromRequest() : Article|null
Retrieves the article slug from GET or POST parameters and fetches the article. Supports both 'slug' and 'id' parameters for backward compatibility.
Return values
Article|null —Article entity if found, null otherwise
updateArticle()
Update an existing article
private
updateArticle() : void
Validates form data, optionally uploads new image to Cloudinary, and updates article in database. Redirects back to form on validation error or to home on success.
Required form fields:
- article-title: Article title
- article-description: Article content/description
- author: Author's full name
- article-image: Image file (optional, only updates if provided)
Return values
void —Redirects to appropriate page with flash message