Foreign keys, bugfixes and output sanitation

This commit is contained in:
2026-08-28 10:22:05 +02:00
parent 9e35a1c099
commit 6896a00f31
26 changed files with 524 additions and 409 deletions
+27 -27
View File
@@ -271,28 +271,28 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
echo "<h2>", $company->compname, "</h2>\n";
echo '<table class="table">', "\n";
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", $company->compname, "</td></tr>\n";
echo '<tr><th scope="row">', _('Short name'),"</th><td>", $company->shortname, "</td></tr>\n";
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", h($company->compname), "</td></tr>\n";
echo '<tr><th scope="row">', _('Short name'),"</th><td>", h($company->shortname), "</td></tr>\n";
echo '<tr><th scope="row">', _('Type'),"</th><td>", $opt_comptype[$company->comptype], "</td></tr>\n";
echo '<tr><th scope="row">', _('Secondary type'),"</th><td>", $company->comptype2 ? $opt_comptype[$company->comptype2] : '-', "</td></tr>\n";
echo '<tr><th scope="row">', _('Street'),"</th><td>", $company->street, "</td></tr>\n";
echo '<tr><th scope="row">', _('Street'),"</th><td>", h($company->street), "</td></tr>\n";
echo '<tr><th scope="row">', _('Zip, City'),"</th><td>", $company->zip, ' ', $company->city, "</td></tr>\n";
echo '<tr><th scope="row">', _('Country'),"</th><td>", $company->country, "</td></tr>\n";
echo '<tr><th scope="row">', _('Contact'),"</th><td>", $company->contact, "</td></tr>\n";
echo '<tr><th scope="row">', _('Country'),"</th><td>", h($company->country), "</td></tr>\n";
echo '<tr><th scope="row">', _('Contact'),"</th><td>", h($company->contact), "</td></tr>\n";
echo '<tr><th scope="row">', _('Phone'),"</th><td>";
echo make_phonelink($company->phone),' ', $company->phone, "</td></tr>\n";
echo make_phonelink($company->phone),' ', h($company->phone), "</td></tr>\n";
echo '<tr><th scope="row">', _('Email'),"</th><td>";
echo make_maillink($company->email),' ', $company->email, "</td></tr>\n";
echo make_maillink($company->email),' ', h($company->email), "</td></tr>\n";
echo '<tr><th scope="row">', _('Web'),"</th><td>";
// echo '<a title="', _('Go to website'), '" href="',
echo make_weblink($company->web), ' ', $company->web, "</td></tr>\n";
echo make_weblink($company->web), ' ', h($company->web), "</td></tr>\n";
echo '<tr><th scope="row">', _('Customer no.'),"</th><td>", $company->customerno, "</td></tr>\n";
echo '<tr><th scope="row">', _('Contract no.'),"</th><td>", $company->contractno, "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", $company->remarks, "</td></tr>\n";
echo '<tr><th scope="row">', _('Customer no.'),"</th><td>", h($company->customerno), "</td></tr>\n";
echo '<tr><th scope="row">', _('Contract no.'),"</th><td>", h($company->contractno), "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", h($company->remarks, br:true), "</td></tr>\n";
echo '<tr><th scope="row">', _('Flags'),"</th><td>", $company->flags, "</td></tr>\n";
echo "</table>\n";
@@ -303,7 +303,7 @@ $sql = "SELECT eid, ename FROM equipment WHERE supplier=:id OR manufacturer=:id"
$sth = $pdo->prepare($sql);
$sth->execute([':id' => $id]);
if ($sth->rowCount() > 0) {
echo "<p>Referenced in equipment:</p>\n";
echo '<p>', _('Referenced in equipment'), ":</p>\n";
echo "<ul>\n";
foreach ($sth->fetchAll() as $row) {
echo "<li>", $row['ename'], ' ';
@@ -353,11 +353,11 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
<input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3">
<label for="compname" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="compname" name="compname" value="<?=$company->compname ?>">
<input type="text" class="form-control" id="compname" name="compname" value="<?=h($company->compname)?>">
</div>
<div class="mb-3">
<label for="shortname" class="form-label"><?=_('Short name')?></label>
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=$company->shortname ?>">
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=h($company->shortname)?>">
</div>
<div class="mb-3">
<label for="comptype" class="form-label"><?=_('Company type')?></label>
@@ -378,47 +378,47 @@ form_create_select('comptype2', _('Secondary company type'), $g_opt_none + $opt_
?>
<div class="mb-3">
<label for="street" class="form-label"><?=_('Street')?></label>
<input type="text" class="form-control" id="street" name="street" value="<?=$company->street ?>">
<input type="text" class="form-control" id="street" name="street" value="<?=h($company->street)?>">
</div>
<div class="mb-3">
<label for="zip" class="form-label"><?=_('Zip')?></label>
<input type="text" class="form-control" id="zip" name="zip" value="<?=$company->zip ?>">
<input type="text" class="form-control" id="zip" name="zip" value="<?=h($company->zip)?>">
</div>
<div class="mb-3">
<label for="city" class="form-label"><?=_('City')?></label>
<input type="text" class="form-control" id="city" name="city" value="<?=$company->city ?>">
<input type="text" class="form-control" id="city" name="city" value="<?=h($company->city)?>">
</div>
<div class="mb-3">
<label for="country" class="form-label"><?=_('Country')?></label>
<input type="text" class="form-control" id="country" name="country" value="<?=$company->country ?>">
<input type="text" class="form-control" id="country" name="country" value="<?=h($company->country)?>">
</div>
<div class="mb-3">
<label for="contact" class="form-label"><?=_('Contact')?></label>
<input type="text" class="form-control" id="contact" name="contact" value="<?=$company->contact ?>">
<input type="text" class="form-control" id="contact" name="contact" value="<?=h($company->contact)?>">
</div>
<div class="mb-3">
<label for="phone" class="form-label"><?=_('Phone')?></label>
<input type="text" class="form-control" id="phone" name="phone" value="<?=$company->phone ?>">
<input type="text" class="form-control" id="phone" name="phone" value="<?=h($company->phone)?>">
</div>
<div class="mb-3">
<label for="email" class="form-label"><?=_('Email')?></label>
<input type="text" class="form-control" id="email" name="email" value="<?=$company->email ?>">
<input type="text" class="form-control" id="email" name="email" value="<?=h($company->email)?>">
</div>
<div class="mb-3">
<label for="web" class="form-label"><?=_('Web')?></label>
<input type="text" class="form-control" id="web" name="web" value="<?=$company->web ?>">
<input type="text" class="form-control" id="web" name="web" value="<?=h($company->web)?>">
</div>
<div class="mb-3">
<label for="customerno" class="form-label"><?=_('Customer no.')?></label>
<input type="text" class="form-control" id="customerno" name="customerno" value="<?=$company->customerno ?>">
<input type="text" class="form-control" id="customerno" name="customerno" value="<?=h($company->customerno)?>">
</div>
<div class="mb-3">
<label for="contractno" class="form-label"><?=_('Contract no.')?></label>
<input type="text" class="form-control" id="contractno" name="contractno" value="<?=$company->contractno ?>">
<input type="text" class="form-control" id="contractno" name="contractno" value="<?=h($company->contractno)?>">
</div>
<div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$company->remarks ?></textarea>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($company->remarks, br:true)?></textarea>
</div>
<?php
$opt_flags = db_load_enum('company', 'flags', true, true, false);
@@ -439,8 +439,8 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
echo '<h2>', _('Delete Company'), "</h2>\n";
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
echo '<p>Name: ', $company->compname, "</p>";
echo '<p>Remarks: ', $company->remarks, "</p>";
echo '<p>Name: ', h($company->compname), "</p>";
echo '<p>Remarks: ', h($company->remarks, br:true), "</p>";
// Still used as a supplier or manufacturer for equipment?
$sql = "SELECT COUNT(*) FROM equipment WHERE supplier=:id OR manufacturer=:id";