UpdateEventController
extends AdminController
in package
Class UpdateEventController
This controller handles the logic for modifying existing events. Access is restricted to users with administrative privileges via inheritance from AdminController.
Refactored to use Data Mapper pattern with Event entities and EventRepository.
Main functionalities:
- Loading and pre-filling the update form (GET).
- Validating security tokens (CSRF) and input data (POST).
- Updating event details including name, date, time, location, theme, and description.
- Handling input errors and server-side exceptions during the update process.
Tags
Table of Contents
Constants
- REDIRECT_URL = 'index.php?page=event'
- REDIRECT_VIEW = 'events/updateEventPageView'
Properties
- $app : Application
- $auth : AuthManager
- $csrf : CsrfProtection
- $request : Request
- $response : Response
- $session : SessionManager
- $eventRepository : EventRepository
- $registrationRepository : EventRegistrationRepository
- $teamRepository : EventTeamRepository
Methods
- __construct() : mixed
- Initializes the controller, verifies admin access, and routes the request to either display the form or process the submission based on the HTTP method.
- handleRequest() : void
- Alternative entry point to handle the update request cycle.
- getCsrfTokenForJs() : string
- Get the CSRF token for JavaScript usage
- redirect() : never
- Redirect to a URL
- redirectWithError() : never
- Redirect with an error message
- redirectWithSuccess() : never
- Redirect with a success message
- render() : void
- Render a view with automatic variable injection
- setError() : void
- Set an error flash message
- setFlash() : void
- Set a flash message
- setInfo() : void
- Set an info flash message
- setSuccess() : void
- Set a success flash message
- setWarning() : void
- Set a warning flash message
- validateCsrf() : bool
- Validate the CSRF token from the request
- displayForm() : void
- Retrieves event data and renders the update form view.
- processUpdate() : void
- Validates and persists the updated event data into the database.
Constants
REDIRECT_URL
private
mixed
REDIRECT_URL
= 'index.php?page=event'
REDIRECT_VIEW
private
mixed
REDIRECT_VIEW
= 'events/updateEventPageView'
Properties
$app
protected
Application
$app
$auth
protected
AuthManager
$auth
$csrf
protected
CsrfProtection
$csrf
$request
protected
Request
$request
$response
protected
Response
$response
$session
protected
SessionManager
$session
$eventRepository
private
EventRepository
$eventRepository
$registrationRepository
private
EventRegistrationRepository
$registrationRepository
$teamRepository
private
EventTeamRepository
$teamRepository
Methods
__construct()
Initializes the controller, verifies admin access, and routes the request to either display the form or process the submission based on the HTTP method.
public
__construct() : mixed
handleRequest()
Alternative entry point to handle the update request cycle.
public
handleRequest() : void
getCsrfTokenForJs()
Get the CSRF token for JavaScript usage
protected
getCsrfTokenForJs() : string
This method is useful for embedding the token in JavaScript or as a meta tag for automatic AJAX injection.
Return values
string —The current CSRF token
redirect()
Redirect to a URL
protected
redirect(string $url) : never
Parameters
- $url : string
-
Destination URL
Return values
never —Terminates execution
redirectWithError()
Redirect with an error message
protected
redirectWithError(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Error message
Return values
never —Terminates execution
redirectWithSuccess()
Redirect with a success message
protected
redirectWithSuccess(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Success message
Return values
never —Terminates execution
render()
Render a view with automatic variable injection
protected
render(string $viewPath[, array<string, mixed> $data = [] ]) : void
This method automatically injects services and data that all views need, eliminating the need to directly access $_SESSION or global functions.
Automatically injected variables:
- $csrf: CsrfProtection service
- $auth: AuthManager service
- $request: Request object
- $flash: Flash messages array (success, error, warning, info)
- $user: Current user data (null if not logged in)
Parameters
- $viewPath : string
-
View path (e.g., 'users/loginPageView')
- $data : array<string, mixed> = []
-
View-specific data
setError()
Set an error flash message
protected
setError(string $message) : void
Parameters
- $message : string
-
Error message
setFlash()
Set a flash message
protected
setFlash(string $type, string $message) : void
Parameters
- $type : string
-
Message type (success, error, warning, info)
- $message : string
-
Message to display
setInfo()
Set an info flash message
protected
setInfo(string $message) : void
Parameters
- $message : string
-
Info message
setSuccess()
Set a success flash message
protected
setSuccess(string $message) : void
Parameters
- $message : string
-
Success message
setWarning()
Set a warning flash message
protected
setWarning(string $message) : void
Parameters
- $message : string
-
Warning message
validateCsrf()
Validate the CSRF token from the request
protected
validateCsrf([string|null $token = null ]) : bool
Supports both traditional POST body tokens and modern AJAX header tokens. Checks in order:
- Provided token parameter
- POST body 'csrf_token' field
- X-CSRF-Token HTTP header (for AJAX requests)
Parameters
- $token : string|null = null
-
Token to validate (if null, retrieves from POST or header)
Return values
bool —True if valid, false otherwise
displayForm()
Retrieves event data and renders the update form view.
private
displayForm(int $eventId) : void
Parameters
- $eventId : int
-
The unique identifier of the event to be modified.
processUpdate()
Validates and persists the updated event data into the database.
private
processUpdate(int $eventId) : void
This method performs CSRF verification, ensures all mandatory fields are present, and converts string inputs into DateTime objects before calling the model.
Parameters
- $eventId : int
-
The unique identifier of the event to update.