Foreign keys, bugfixes and output sanitation

This commit is contained in:
2026-08-28 10:22:05 +02:00
parent 9e35a1c099
commit 6896a00f31
26 changed files with 524 additions and 409 deletions
+34 -4
View File
@@ -12,7 +12,8 @@
* # Date Changes by
* ------ ------------ ---------------------------------------------- -----
* 0.1.0 2024-03-12 Started development tho
' 0.2.0 2026-08-18 First public release tho
* 0.2.0 2026-08-18 First public release tho
* 0.2.1 2026-08-28 Foreign keys, bugfixes and output sanitation tho
*
*/
@@ -48,7 +49,7 @@ define('ROLE_SAILOR', 'sailor');
// ========== PAGE START CODE =================================================
// global version string
$g_version = 'v0.2.0';
$g_version = 'v0.2.1';
$g_scriptname = basename($_SERVER['SCRIPT_NAME']);
@@ -936,6 +937,21 @@ function db_get_opt_proj($vid, $exclude=[], $default=NULL) {
return $list;
}
function db_get_opt_cable($vid, $default=NULL) {
global $pdo;
if (isset($default)) {
$list = $default;
} else {
$list = array();
}
$sql = "SELECT cableid, cablename FROM cable WHERE vid=? ORDER BY cablename";
$sth = $pdo->query($sql);
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
$list[$row[0]] = h($row[1]);
}
return $list;
}
function db_get_filter($user, $sno, $fields = []) {
// if fields supplied empting missing field are created
global $pdo;
@@ -1233,6 +1249,18 @@ function format_currency($val) {
}
}
function format_date($date) {
global $user;
// $user->datefmt;
/*'Y-m-d' => _('YYYY-MM-DD'). $curdate->format(' - Y-m-d'),
'Y/m/d' => _('YYYY/MM/DD'). $curdate->format(' - Y/m/d'),
'd.m.Y' => _('DD.MM.YYYY'). $curdate->format(' - d.m.Y'),
'd/m/Y' => _('DD/MM/YYYY'). $curdate->format(' - d/m/Y'),
'm-d-Y' => _('MM/DD/YYYY'). $curdate->format(' - m-d-Y') */
return '';
}
function format_color($color) {
$colstr = '<span style="';
$style = "padding:2px 4px;border-radius:4px;background-color:#".$color;
@@ -1296,9 +1324,11 @@ function format_measurement($n, $unit, $v1, $v2, $v3) {
// ========== COMMON FUNCTIONS ================================================
function h($value) {
function h($value, $br=false) {
// escape value coming from db for safe html output
return htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
// optional convert line breaks to <br> tags
$value = htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
return $br ? nl2br($value) : $value;
}
function header_location($location, $message=NULL) {