From 6896a00f3103e2c3c91e68cfd071c1786a9e9aec Mon Sep 17 00:00:00 2001 From: Thomas Hooge Date: Fri, 28 Aug 2026 10:22:05 +0200 Subject: [PATCH] Foreign keys, bugfixes and output sanitation --- CHANGELOG | 17 + INSTALL | 2 +- README | 2 + WTFPL_badge.svg | 8 + install.sh | 1 + webgui/box.php | 8 +- webgui/cable.php | 6 +- webgui/company.php | 54 +- webgui/documents.php | 10 +- webgui/equipment.php | 46 +- webgui/fuse.php | 6 +- webgui/globals.inc | 38 +- webgui/index.php | 2 +- webgui/inventory.php | 6 +- webgui/locale/de_DE.po | 651 +++++++++++++------------ webgui/locale/de_DE/LC_MESSAGES/yms.m | Bin 0 -> 23580 bytes webgui/locale/de_DE/LC_MESSAGES/yms.mo | Bin 23364 -> 23580 bytes webgui/maintenance.php | 14 +- webgui/measurement.php | 18 +- webgui/note.php | 8 +- webgui/projects.php | 6 +- webgui/provisions.php | 4 +- webgui/storage.php | 10 +- webgui/task.php | 5 +- yms/ui/main.ui | 2 +- ymsgui.py | 9 +- 26 files changed, 524 insertions(+), 409 deletions(-) create mode 100644 CHANGELOG create mode 100644 WTFPL_badge.svg create mode 100644 webgui/locale/de_DE/LC_MESSAGES/yms.m diff --git a/CHANGELOG b/CHANGELOG new file mode 100644 index 0000000..d797929 --- /dev/null +++ b/CHANGELOG @@ -0,0 +1,17 @@ +CHANGELOG +========= + +0.2.1 - 2026-08-28 +------------------ + + * fix and improve install script + * fix messagebox call in ymsgui + * customizable main menu + * sanitized html input fields + * added foreign keys and constraints to database + * added manpage + +0.2.0 - 2026-08-18 +------------------ + + * initial public release diff --git a/INSTALL b/INSTALL index 1812834..dc67059 100644 --- a/INSTALL +++ b/INSTALL @@ -15,7 +15,7 @@ Yacht Management Software (YMS) Installation - Python GTK3 - python3-gi - gir1.2-gtk-3.0 - - gir-rsvg-2.0 + - gir1.2-rsvg-2.0 1.3 Web GUI - Webserver diff --git a/README b/README index a751c56..3935547 100644 --- a/README +++ b/README @@ -11,6 +11,8 @@ This is work in progress: Many features can be incomplete, buggy or missing. Use at your own risk! +Please read installation instructions in INSTALL + If inserting a new user you have also to insert a setting value to assign boat 0. diff --git a/WTFPL_badge.svg b/WTFPL_badge.svg new file mode 100644 index 0000000..a6a8a76 --- /dev/null +++ b/WTFPL_badge.svg @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/install.sh b/install.sh index 3df3ad5..1878fcd 100755 --- a/install.sh +++ b/install.sh @@ -82,6 +82,7 @@ install -m 0644 \ install -m 0644 \ "${SOURCEDIR}/COPYING" \ "${DOCDIR}/COPYING" +install -d "${MANDIR}" install -m 0644 \ "${SOURCEDIR}/yms.1" \ "${MANDIR}/yms.1" diff --git a/webgui/box.php b/webgui/box.php index bdf6437..816ba4e 100644 --- a/webgui/box.php +++ b/webgui/box.php @@ -184,7 +184,7 @@ echo '', _('Weight'), '', format_float($box->weight, 2, 'kg'), echo '', _('Storage'),"", $box->sname, ' '; echo ''; echo "\n"; -echo '', _('Remarks'),"", $box->remarks, "\n"; +echo '', _('Remarks'),"", h($box->remarks, br:true), "\n"; echo "\n"; form_view_buttons($g_scriptname, $id); @@ -293,12 +293,12 @@ echo '

', _('Edit Box'), "

\n";
- +
boxtype); ?>
- +
@@ -311,7 +311,7 @@ echo '

', _('Edit Box'), "

\n"; sid); ?>
- +
', _('Cross section'),"", format_float($cable->xsection, echo '', _('Weight'),"", format_float($cable->weight, 2, 'kg/m'), "\n"; echo '', _('Color'),"", format_color($cable->color), "\n"; echo '', _('Condition'),"", $opt_cablecond[$cable->cablecond], "\n"; -echo "", _('Remarks'), "", nl2br($cable->remarks), "\n"; +echo "", _('Remarks'), "", h($cable->remarks, br:true), "\n"; echo "\n"; form_view_buttons($g_scriptname, $id); @@ -233,7 +233,7 @@ echo '

', _('Edit cable'), "

\n";
- +
cabletype); @@ -267,7 +267,7 @@ form_create_select('cablecond', _('Condition'), $opt_cablecond, $cable->cablecon ?>
- +
fetch(PDO::FETCH_OBJ); echo "

", $company->compname, "

\n"; echo '', "\n"; -echo '\n"; -echo '\n"; +echo '\n"; +echo '\n"; echo '\n"; echo '\n"; -echo '\n"; +echo '\n"; echo '\n"; -echo '\n"; -echo '\n"; +echo '\n"; +echo '\n"; echo '\n"; +echo make_phonelink($company->phone),' ', h($company->phone), "\n"; echo '\n"; +echo make_maillink($company->email),' ', h($company->email), "\n"; echo '\n"; +echo make_weblink($company->web), ' ', h($company->web), "\n"; -echo '\n"; -echo '\n"; -echo '\n"; +echo '\n"; +echo '\n"; +echo '\n"; echo '\n"; echo "
', _('Name'),"", $company->compname, "
', _('Short name'),"", $company->shortname, "
', _('Name'),"", h($company->compname), "
', _('Short name'),"", h($company->shortname), "
', _('Type'),"", $opt_comptype[$company->comptype], "
', _('Secondary type'),"", $company->comptype2 ? $opt_comptype[$company->comptype2] : '-', "
', _('Street'),"", $company->street, "
', _('Street'),"", h($company->street), "
', _('Zip, City'),"", $company->zip, ' ', $company->city, "
', _('Country'),"", $company->country, "
', _('Contact'),"", $company->contact, "
', _('Country'),"", h($company->country), "
', _('Contact'),"", h($company->contact), "
', _('Phone'),""; -echo make_phonelink($company->phone),' ', $company->phone, "
', _('Email'),""; -echo make_maillink($company->email),' ', $company->email, "
', _('Web'),""; // echo '
', _('Customer no.'),"", $company->customerno, "
', _('Contract no.'),"", $company->contractno, "
', _('Remarks'),"", $company->remarks, "
', _('Customer no.'),"", h($company->customerno), "
', _('Contract no.'),"", h($company->contractno), "
', _('Remarks'),"", h($company->remarks, br:true), "
', _('Flags'),"", $company->flags, "
\n"; @@ -303,7 +303,7 @@ $sql = "SELECT eid, ename FROM equipment WHERE supplier=:id OR manufacturer=:id" $sth = $pdo->prepare($sql); $sth->execute([':id' => $id]); if ($sth->rowCount() > 0) { - echo "

Referenced in equipment:

\n"; + echo '

', _('Referenced in equipment'), ":

\n"; echo "