Foreign keys, bugfixes and output sanitation
This commit is contained in:
@@ -245,14 +245,15 @@ elseif ($action == ACT_VIEW):
|
||||
|
||||
echo '<h2>', _('View Maintenance'), "</h2>\n";
|
||||
|
||||
// load maintenance record
|
||||
$sql = "SELECT m.activities, m.eid, m.remarks, m.series, m.maintstate, e.ename "
|
||||
. "FROM maintenance AS m LEFT OUTER JOIN equipment AS e USING (eid) "
|
||||
. "WHERE m.maintid=?";
|
||||
$sth = $pdo->prepare($sql);
|
||||
$sth->execute([$id]);
|
||||
$maint = $sth->fetch(PDO::FETCH_OBJ);
|
||||
|
||||
if (isset($maint->eid)) {
|
||||
if ($maint !== false && isset($maint->eid)) {
|
||||
// if available load document references
|
||||
$sql = "SELECT r.docid, d.filename, d.title, d.hash, d.extension "
|
||||
. "FROM docref AS r INNER JOIN document AS d USING (docid) "
|
||||
. "WHERE r.reftype='equipment' AND r.refid=?";
|
||||
@@ -260,6 +261,7 @@ if (isset($maint->eid)) {
|
||||
$sth->execute([$maint->eid]);
|
||||
$docs = $sth->fetchAll();
|
||||
} else {
|
||||
$maint = new stdClass();
|
||||
$maint->ename = _('n/a');
|
||||
unset($docs);
|
||||
}
|
||||
@@ -271,13 +273,13 @@ echo '<div class="col">';
|
||||
|
||||
echo '<table class="table">', "\n";
|
||||
echo '<tr><th>', _('Activities'),"</th><td>", $maint->activities, "</td></tr>\n";
|
||||
echo '<tr><th>', _('Equipment'),"</th><td>", $maint->ename;
|
||||
echo '<tr><th>', _('Equipment'),"</th><td>", h($maint->ename);
|
||||
if (isset($maint->eid) and $maint->eid>0) {
|
||||
// Link to equipment
|
||||
echo ' <a href="equipment.php?f=view&id=', $maint->eid, '"><i class="bi-eye"></i></a>';
|
||||
}
|
||||
echo "</td></tr>\n";
|
||||
echo '<tr><th>', _('Remarks'),"</th><td>", $maint->remarks, "</td></tr>\n";
|
||||
echo '<tr><th>', _('Remarks'),"</th><td>", h($maint->remarks), "</td></tr>\n";
|
||||
echo '<tr><th>', _('Series'),"</th><td>", $maint->series, "</td></tr>\n";
|
||||
echo '<tr><th scope="row">', _('State'),"</th><td>", get_enum($maint->maintstate), "</td></tr>\n";
|
||||
echo "</table>\n";
|
||||
@@ -343,12 +345,12 @@ echo '<h2>', _('Edit Maintenance'), "</h2>\n";
|
||||
<input type="hidden" name="id" value="<?=$id?>">
|
||||
<div class="mb-3">
|
||||
<label for="activities" class="form-label"><?=_('Activities')?></label>
|
||||
<input type="text" class="form-control" id="activities" name="activities" value="<?=$maint->activities ?>">
|
||||
<input type="text" class="form-control" id="activities" name="activities" value="<?=h($maint->activities)?>">
|
||||
</div>
|
||||
<?php form_create_select('eid', _('Equipment'), $opt_equipment, $maint->eid); ?>
|
||||
<div class="mb-3">
|
||||
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
|
||||
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$maint->remarks ?></textarea>
|
||||
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($maint->remarks, br:true)?></textarea>
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<label for="series" class="form-label"><?=_('Series')?></label>
|
||||
|
||||
Reference in New Issue
Block a user