This is an object-oriented version of the CMS (Content Management System) project, designed to be simple and educational for students learning PHP OOP concepts.
cms-project-oops/
├── classes/ # All PHP classes
│ ├── Database.php # Database connection and operations
│ ├── Session.php # Session management
│ ├── User.php # User authentication and management
│ ├── Subject.php # Subject (category) management
│ ├── Page.php # Page management
│ ├── Navigation.php # Navigation menu generation
│ ├── FormValidator.php # Form validation utilities
│ └── Autoload.php # Class autoloader
├── includes/ # Configuration and layout files
│ ├── constants.php # Database configuration
│ ├── header.php # HTML header template
│ └── footer.php # HTML footer template
├── stylesheets/ # CSS styling
│ └── public.css # Main stylesheet
├── init.php # Application initialization
├── index.php # Public homepage
├── login.php # User login
├── staff.php # Admin dashboard
├── logout.php # User logout
├── content.php # Content management
├── new_user.php # Create new user
├── new_subject.php # Create new subject form
├── create_subject.php # Process subject creation
├── edit_subject.php # Edit subject
├── delete_subject.php # Delete subject
├── new_page.php # Create new page
├── edit_page.php # Edit page
├── delete_page.php # Delete page
├── page_form.php # Shared page form
└── README.md # This file
The project uses the same database as the original CMS (widget_corp):
- users: id, username, hashed_password
- subjects: id, menu_name, position, visible
- pages: id, subject_id, menu_name, position, visible, content
- Purpose: Handles all database operations
- Key Methods:
__construct(): Creates database connectionquery($sql): Executes SQL queriesescape_value($value): Prevents SQL injectionfetch_array($result): Gets result rowsnum_rows($result): Counts result rows
- Purpose: Manages user sessions and authentication
- Key Methods:
__construct(): Starts session and checks login statuslogin($user): Logs in a userlogout(): Logs out a useris_logged_in(): Checks if user is logged inset_message($msg): Sets flash messages
- Purpose: Handles user authentication and management
- Key Methods:
authenticate($username, $password): Validates login credentialscreate($username, $password): Creates new userfind_by_id($id): Finds user by ID
- Purpose: Manages subjects (categories)
- Key Methods:
get_all($public): Gets all subjects (public or admin view)find_by_id($id): Finds subject by IDcreate($menu_name, $position, $visible): Creates new subjectupdate($id, $menu_name, $position, $visible): Updates subjectdelete($id): Deletes subject and its pages
- Purpose: Manages pages within subjects
- Key Methods:
get_for_subject($subject_id, $public): Gets pages for a subjectfind_by_id($id): Finds page by IDget_default_for_subject($subject_id): Gets default page for subjectcreate($subject_id, $menu_name, $position, $visible, $content): Creates new pageupdate($id, $menu_name, $position, $visible, $content): Updates pagedelete($id): Deletes page
- Purpose: Generates navigation menus
- Key Methods:
admin_navigation($sel_subject, $sel_page): Admin navigation menupublic_navigation($sel_subject, $sel_page): Public navigation menufind_selected_page(): Determines current page/subject from URL
- Purpose: Handles form validation and output sanitization
- Key Methods:
check_required_fields($required_array): Validates required fieldscheck_max_field_lengths($field_length_array, $database): Validates field lengthsdisplay_errors($error_array): Shows validation errorssanitize_output($value): Sanitizes output for XSS preventionstrip_tags($value): Removes HTML tags from content
- Private properties and methods
- Public interfaces for external access
- Data hiding through proper access modifiers
- Each class has one specific purpose
- Database class handles only database operations
- Session class handles only session management
- FormValidator class handles only validation
- Database object is passed to other classes
- Classes depend on abstractions, not concrete implementations
- Database connection is injected into classes that need it
- Promotes loose coupling between classes
- FormValidator uses static methods for utility functions
- No need to instantiate the class for validation
- Setup Database: Ensure the
widget_corpdatabase exists with the required tables - Configure: Check
includes/constants.phpfor database settings - Access: Navigate to the project folder in your web browser
- Login: Use the login system to access admin features
- SQL Injection Prevention: Uses
escape_value()method - XSS Prevention: Uses
sanitize_output()for output - Session Security: Proper session management
- Input Validation: Form validation on all inputs
This OOP version demonstrates:
- How to structure PHP applications using classes
- Proper separation of concerns
- Database abstraction
- Session management
- Form validation
- Security best practices
- Code reusability through inheritance and composition
The OOP version offers:
- Better Organization: Code is organized into logical classes
- Reusability: Classes can be reused across different parts of the application
- Maintainability: Easier to maintain and extend
- Testability: Classes can be unit tested independently
- Scalability: Easier to add new features without affecting existing code
This structure is perfect for students learning PHP OOP concepts as it shows real-world application of object-oriented principles in a simple, understandable way.