Foreign keys, bugfixes and output sanitation
This commit is contained in:
+5
-5
@@ -231,7 +231,7 @@ echo '<tr><th>', _('Location (x, y, z)'),"</th><td>(", $storage->x, ', ', $stora
|
||||
echo '<tr><th>', _('Width (wx, wy, wz)'),"</th><td>(", $storage->wx, ', ', $storage->wy, ', ', $storage->wz, ")</td></tr>\n";
|
||||
echo '<tr><th>', _('Angle'),"</th><td>", $storage->angle, "°</td></tr>\n";
|
||||
echo '<tr><th>', _('Color'),"</th><td>", $storage->color, "</td></tr>\n";
|
||||
echo '<tr><th>', _('Remarks'),"</th><td>", $storage->remarks, "</td></tr>\n";
|
||||
echo '<tr><th>', _('Remarks'),"</th><td>", h($storage->remarks), "</td></tr>\n";
|
||||
echo "</table>\n";
|
||||
|
||||
form_view_buttons($g_scriptname, $id);
|
||||
@@ -314,7 +314,7 @@ $storage = $sth->fetch(PDO::FETCH_OBJ);
|
||||
<input type="hidden" name="id" value="<?=$id?>">
|
||||
<div class="mb-3">
|
||||
<label for="sname" class="form-label"><?=_('Name')?></label>
|
||||
<input type="text" class="form-control" id="sname" name="sname" value="<?=$storage->sname ?>">
|
||||
<input type="text" class="form-control" id="sname" name="sname" value="<?=h($storage->sname)?>">
|
||||
</div>
|
||||
<?php
|
||||
form_create_select('stype', _('Type'), $opt_stype, $storage->stype);
|
||||
@@ -358,7 +358,7 @@ form_create_select('stype', _('Type'), $opt_stype, $storage->stype);
|
||||
<?php form_create_select('capaunit', _('Capacity Unit'), $opt_capaunit, $storage->capaunit); ?>
|
||||
<div class="mb-3">
|
||||
<label for="remarks" class="form-label"><?=_('Remarks')?></label>
|
||||
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$storage->remarks ?></textarea>
|
||||
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($storage->remarks, br:true)?></textarea>
|
||||
</div>
|
||||
<button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button>
|
||||
<a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a>
|
||||
@@ -377,8 +377,8 @@ $storage = $sth->fetch(PDO::FETCH_OBJ);
|
||||
echo '<h2>', _('Delete Storage'), "</h2>\n";
|
||||
|
||||
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
|
||||
echo '<p>Name: ', $storage->sname, "</p>";
|
||||
echo '<p>Remarks: ', $storage->remarks, "</p>";
|
||||
echo '<p>Name: ', h($storage->sname), "</p>";
|
||||
echo '<p>Remarks: ', h($storage->remarks, br:true), "</p>";
|
||||
|
||||
echo '<p>', _('Deleting a storage is final. There is no way back. Only delete if you are absolute sure.'), "</p>\n";
|
||||
|
||||
|
||||
Reference in New Issue
Block a user