Foreign keys, bugfixes and output sanitation

This commit is contained in:
2026-08-28 10:22:05 +02:00
parent 9e35a1c099
commit 6896a00f31
26 changed files with 524 additions and 409 deletions
+3 -3
View File
@@ -307,14 +307,14 @@ $sth->execute([$id]);
$project = $sth->fetch(PDO::FETCH_OBJ);
echo "<h2>", $project->projname, "</h2>\n";
echo '<table class="table">', "\n";
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", $project->projname, "</td></tr>\n";
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", h($project->projname), "</td></tr>\n";
echo '<tr><th scope="row">', _('Responsible'),"</th><td>", $opt_user[$project->responsible], "</td></tr>\n";
echo '<tr><th scope="row">', _('Start date'),"</th><td>", $project->startdate, "</td></tr>\n";
echo '<tr><th scope="row">', _('Duration'),"</th><td>", $project->duration, "</td></tr>\n";
echo '<tr><th scope="row">', _('Costs plan'),"</th><td>", format_currency($project->costs_plan), "</td></tr>\n";
echo '<tr><th scope="row">', _('Costs final'),"</th><td>", format_currency($project->costs_final), "</td></tr>\n";
echo '<tr><th scope="row">', _('State'),"</th><td>", get_enum($project->projstate), "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", nl2br($project->remarks), "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", h($project->remarks, br:true), "</td></tr>\n";
echo "</table>\n";
form_view_buttons($g_scriptname, $id);
@@ -401,7 +401,7 @@ form_create_select('projstate', _('Status'), $opt_state, $project->projstate);
?>
<div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$project->remarks ?></textarea>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($project->remarks, br:true)?></textarea>
</div>
<button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button>
<a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a>