Foreign keys, bugfixes and output sanitation

This commit is contained in:
2026-08-28 10:22:05 +02:00
parent 9e35a1c099
commit 6896a00f31
26 changed files with 524 additions and 409 deletions
+35 -11
View File
@@ -455,18 +455,18 @@ echo '<div class="row">';
echo '<div class="col">';
echo '<table class="table">', "\n";
echo '<tr><th>', _('Short name'),"</th><td>", $equipment->shortname, "</td></tr>\n";
echo '<tr><th>', _('Short name'),"</th><td>", h($equipment->shortname), "</td></tr>\n";
echo '<tr><th>', _('Manufacturer'),"</th><td>", $opt_manufacturer[$equipment->manufacturer];
echo '&nbsp;<a title="', _('View'), '" href="company.php?f=view&id=', $equipment->manufacturer, '"><i class="bi-eye"></i></a>';
echo "</td></tr>\n";
echo '<tr><th>', _('Model'),"</th><td>", $equipment->model, "</td></tr>\n";
echo '<tr><th>', _('Serial'),"</th><td>", $equipment->serial, "</td></tr>\n";
echo '<tr><th>', _('Model'),"</th><td>", h($equipment->model), "</td></tr>\n";
echo '<tr><th>', _('Serial'),"</th><td>", h($equipment->serial), "</td></tr>\n";
echo '<tr><th>', _('Weight'),"</th><td>", format_float($equipment->weight, 2, 'kg'), "</td></tr>\n";
echo '<tr><th>', _('Price'),"</th><td>", format_currency($equipment->price), "</td></tr>\n";
echo '<tr><th>', _('Purchase date'),"</th><td>", $equipment->purchdate, "</td></tr>\n";
echo '<tr><th>', _('Supplier'),"</th><td>", $equipment->supplier ? $opt_supplier[$equipment->supplier] : 'n/a', "</td></tr>\n";
echo '<tr><th>', _('Category'),"</th><td>", $opt_ecat[$equipment->ecat], "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", nl2br($equipment->remarks), "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", h($equipment->remarks, br:true), "</td></tr>\n";
echo '<tr><th>', _('Flags'),"</th><td>", $equipment->flags, "</td></tr>\n";
echo "</table>\n";
@@ -545,6 +545,30 @@ echo '</div>'; // container
// Buttons at bottom of data area
form_view_buttons($g_scriptname, $id);
// Annotations
echo '<h3>', _('Annotations'), "</h3>\n";
$sql = "SELECT noteid, annotation "
. "FROM note "
. "WHERE notetype='equip' AND refid=?";
$sth = $pdo->prepare($sql);
$sth->execute([$id]);
if ($sth->rowCount() > 0) {
$n = 0;
foreach ($sth->fetchAll() as $row) {
$n += 1;
echo "<p>($n) {$row['annotation']}";
echo ' <a title="', _('Edit'), '" href="note.php?f=edit&id=', $row['noteid'], '"><i class="bi-pencil"></i></a>';
echo "</p>\n";
}
} else {
echo '<p>', _('No annotations for this equipment'), "</p>\n";
}
echo '<div class="container-fluid px-0 my-3">', "\n";
echo '<a href="note.php?f=add&t=equip&id=', $id, '" class="btn btn-primary" role="button">';
echo _('Add note'), "</a>\n";
echo "</div>\n";
// Maintenance records
echo '<h3>', _('Maintenances'), "</h3>";
@@ -649,20 +673,20 @@ $equipment = $sth->fetch(PDO::FETCH_OBJ);
<input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3">
<label for="ename" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="ename" name="ename" value="<?=$equipment->ename ?>">
<input type="text" class="form-control" id="ename" name="ename" value="<?=h($equipment->ename)?>">
</div>
<div class="mb-3">
<label for="shortname" class="form-label"><?=_('Short name')?></label>
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=$equipment->shortname ?>">
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=h($equipment->shortname)?>">
</div>
<?php form_create_select('manufacturer', _('Manufacturer'), $opt_manufacturer, $equipment->manufacturer); ?>
<div class="mb-3">
<label for="model" class="form-label"><?=_('Model')?></label>
<input type="text" class="form-control" id="model" name="model" value="<?=$equipment->model ?>">
<input type="text" class="form-control" id="model" name="model" value="<?=h($equipment->model)?>">
</div>
<div class="mb-3">
<label for="serial" class="form-label"><?=_('Serial')?></label>
<input type="text" class="form-control" id="serial" name="serial" value="<?=$equipment->serial ?>">
<input type="text" class="form-control" id="serial" name="serial" value="<?=h($equipment->serial)?>">
</div>
<div class="mb-3">
<label for="weight" class="form-label"><?=_('Weight, kg')?></label>
@@ -682,7 +706,7 @@ form_create_select('category', _('Category'), $g_opt_unknown + $opt_ecat, $equip
?>
<div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$equipment->remarks ?></textarea>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($equipment->remarks, br:true)?></textarea>
</div>
<?php
$opt_flags = db_load_enum('equipment', 'flags', true, true, false);
@@ -705,8 +729,8 @@ $equipment = $sth->fetch(PDO::FETCH_OBJ);
echo '<h2>', _('Delete equipment'),"</h2>\n";
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
echo '<p>Name: ', $equipment->ename, "</p>";
echo '<p>Remarks: ', $equipment->remarks, "</p>";
echo '<p>Name: ', h($equipment->ename), "</p>";
echo '<p>Remarks: ', h($equipment->remarks, br:true), "</p>";
echo '<p>', _('Deleting an equipment item is final. There is no way back. Only delete if you are absolute sure.'), "</p>\n";