Foreign keys, bugfixes and output sanitation
This commit is contained in:
+27
-27
@@ -271,28 +271,28 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
|
||||
echo "<h2>", $company->compname, "</h2>\n";
|
||||
|
||||
echo '<table class="table">', "\n";
|
||||
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", $company->compname, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Short name'),"</th><td>", $company->shortname, "</td></tr>\n";
|
||||
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", h($company->compname), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Short name'),"</th><td>", h($company->shortname), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Type'),"</th><td>", $opt_comptype[$company->comptype], "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Secondary type'),"</th><td>", $company->comptype2 ? $opt_comptype[$company->comptype2] : '-', "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Street'),"</th><td>", $company->street, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Street'),"</th><td>", h($company->street), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Zip, City'),"</th><td>", $company->zip, ' ', $company->city, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Country'),"</th><td>", $company->country, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Contact'),"</th><td>", $company->contact, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Country'),"</th><td>", h($company->country), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Contact'),"</th><td>", h($company->contact), "</td></tr>\n";
|
||||
|
||||
echo '<tr><th scope="row">', _('Phone'),"</th><td>";
|
||||
echo make_phonelink($company->phone),' ', $company->phone, "</td></tr>\n";
|
||||
echo make_phonelink($company->phone),' ', h($company->phone), "</td></tr>\n";
|
||||
|
||||
echo '<tr><th scope="row">', _('Email'),"</th><td>";
|
||||
echo make_maillink($company->email),' ', $company->email, "</td></tr>\n";
|
||||
echo make_maillink($company->email),' ', h($company->email), "</td></tr>\n";
|
||||
|
||||
echo '<tr><th scope="row">', _('Web'),"</th><td>";
|
||||
// echo '<a title="', _('Go to website'), '" href="',
|
||||
echo make_weblink($company->web), ' ', $company->web, "</td></tr>\n";
|
||||
echo make_weblink($company->web), ' ', h($company->web), "</td></tr>\n";
|
||||
|
||||
echo '<tr><th scope="row">', _('Customer no.'),"</th><td>", $company->customerno, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Contract no.'),"</th><td>", $company->contractno, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", $company->remarks, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Customer no.'),"</th><td>", h($company->customerno), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Contract no.'),"</th><td>", h($company->contractno), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", h($company->remarks, br:true), "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('Flags'),"</th><td>", $company->flags, "</td></tr>\n";
|
||||
echo "</table>\n";
|
||||
|
||||
@@ -303,7 +303,7 @@ $sql = "SELECT eid, ename FROM equipment WHERE supplier=:id OR manufacturer=:id"
|
||||
$sth = $pdo->prepare($sql);
|
||||
$sth->execute([':id' => $id]);
|
||||
if ($sth->rowCount() > 0) {
|
||||
echo "<p>Referenced in equipment:</p>\n";
|
||||
echo '<p>', _('Referenced in equipment'), ":</p>\n";
|
||||
echo "<ul>\n";
|
||||
foreach ($sth->fetchAll() as $row) {
|
||||
echo "<li>", $row['ename'], ' ';
|
||||
@@ -353,11 +353,11 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
|
||||
<input type="hidden" name="id" value="<?=$id?>">
|
||||
<div class="mb-3">
|
||||
<label for="compname" class="form-label"><?=_('Name')?></label>
|
||||
<input type="text" class="form-control" id="compname" name="compname" value="<?=$company->compname ?>">
|
||||
<input type="text" class="form-control" id="compname" name="compname" value="<?=h($company->compname)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="shortname" class="form-label"><?=_('Short name')?></label>
|
||||
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=$company->shortname ?>">
|
||||
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=h($company->shortname)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="comptype" class="form-label"><?=_('Company type')?></label>
|
||||
@@ -378,47 +378,47 @@ form_create_select('comptype2', _('Secondary company type'), $g_opt_none + $opt_
|
||||
?>
|
||||
<div class="mb-3">
|
||||
<label for="street" class="form-label"><?=_('Street')?></label>
|
||||
<input type="text" class="form-control" id="street" name="street" value="<?=$company->street ?>">
|
||||
<input type="text" class="form-control" id="street" name="street" value="<?=h($company->street)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="zip" class="form-label"><?=_('Zip')?></label>
|
||||
<input type="text" class="form-control" id="zip" name="zip" value="<?=$company->zip ?>">
|
||||
<input type="text" class="form-control" id="zip" name="zip" value="<?=h($company->zip)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="city" class="form-label"><?=_('City')?></label>
|
||||
<input type="text" class="form-control" id="city" name="city" value="<?=$company->city ?>">
|
||||
<input type="text" class="form-control" id="city" name="city" value="<?=h($company->city)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="country" class="form-label"><?=_('Country')?></label>
|
||||
<input type="text" class="form-control" id="country" name="country" value="<?=$company->country ?>">
|
||||
<input type="text" class="form-control" id="country" name="country" value="<?=h($company->country)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="contact" class="form-label"><?=_('Contact')?></label>
|
||||
<input type="text" class="form-control" id="contact" name="contact" value="<?=$company->contact ?>">
|
||||
<input type="text" class="form-control" id="contact" name="contact" value="<?=h($company->contact)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="phone" class="form-label"><?=_('Phone')?></label>
|
||||
<input type="text" class="form-control" id="phone" name="phone" value="<?=$company->phone ?>">
|
||||
<input type="text" class="form-control" id="phone" name="phone" value="<?=h($company->phone)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="email" class="form-label"><?=_('Email')?></label>
|
||||
<input type="text" class="form-control" id="email" name="email" value="<?=$company->email ?>">
|
||||
<input type="text" class="form-control" id="email" name="email" value="<?=h($company->email)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="web" class="form-label"><?=_('Web')?></label>
|
||||
<input type="text" class="form-control" id="web" name="web" value="<?=$company->web ?>">
|
||||
<input type="text" class="form-control" id="web" name="web" value="<?=h($company->web)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="customerno" class="form-label"><?=_('Customer no.')?></label>
|
||||
<input type="text" class="form-control" id="customerno" name="customerno" value="<?=$company->customerno ?>">
|
||||
<input type="text" class="form-control" id="customerno" name="customerno" value="<?=h($company->customerno)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="contractno" class="form-label"><?=_('Contract no.')?></label>
|
||||
<input type="text" class="form-control" id="contractno" name="contractno" value="<?=$company->contractno ?>">
|
||||
<input type="text" class="form-control" id="contractno" name="contractno" value="<?=h($company->contractno)?>">
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
|
||||
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$company->remarks ?></textarea>
|
||||
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($company->remarks, br:true)?></textarea>
|
||||
</div>
|
||||
<?php
|
||||
$opt_flags = db_load_enum('company', 'flags', true, true, false);
|
||||
@@ -439,8 +439,8 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
|
||||
|
||||
echo '<h2>', _('Delete Company'), "</h2>\n";
|
||||
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
|
||||
echo '<p>Name: ', $company->compname, "</p>";
|
||||
echo '<p>Remarks: ', $company->remarks, "</p>";
|
||||
echo '<p>Name: ', h($company->compname), "</p>";
|
||||
echo '<p>Remarks: ', h($company->remarks, br:true), "</p>";
|
||||
|
||||
// Still used as a supplier or manufacturer for equipment?
|
||||
$sql = "SELECT COUNT(*) FROM equipment WHERE supplier=:id OR manufacturer=:id";
|
||||
|
||||
Reference in New Issue
Block a user