Foreign keys, bugfixes and output sanitation

This commit is contained in:
2026-08-28 10:22:05 +02:00
parent 9e35a1c099
commit 6896a00f31
26 changed files with 524 additions and 409 deletions
+17
View File
@@ -0,0 +1,17 @@
CHANGELOG
=========
0.2.1 - 2026-08-28
------------------
* fix and improve install script
* fix messagebox call in ymsgui
* customizable main menu
* sanitized html input fields
* added foreign keys and constraints to database
* added manpage
0.2.0 - 2026-08-18
------------------
* initial public release
+1 -1
View File
@@ -15,7 +15,7 @@ Yacht Management Software (YMS) Installation
- Python GTK3 - Python GTK3
- python3-gi - python3-gi
- gir1.2-gtk-3.0 - gir1.2-gtk-3.0
- gir-rsvg-2.0 - gir1.2-rsvg-2.0
1.3 Web GUI 1.3 Web GUI
- Webserver - Webserver
+2
View File
@@ -11,6 +11,8 @@ This is work in progress:
Many features can be incomplete, buggy or missing. Many features can be incomplete, buggy or missing.
Use at your own risk! Use at your own risk!
Please read installation instructions in INSTALL
If inserting a new user you have also to insert a setting value If inserting a new user you have also to insert a setting value
to assign boat 0. to assign boat 0.
+8
View File
@@ -0,0 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" id="Layer_2" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" width="151px" height="52.725px" viewBox="0 0 151 52.725" enable-background="new 0 0 151 52.725" xml:space="preserve">
<rect x="0.5" y="0.5" fill="#FFFFFF" stroke="#000000" stroke-miterlimit="10" width="150" height="51.725"/>
<path d="M61.714,6.535v0.277c6.063,4.344,10.033,11.473,10.033,19.55c0,7.237-3.192,13.712-8.216,18.109H150.5V6.535H61.714z"/>
<path fill="#FFFFFF" d="M88.588,16.993c-0.197,5.428-0.342,10.861-0.549,16.287h-0.027c-0.554-3.347-1.633-6.645-2.498-9.917h-2.005c-0.795,3.289-1.729,6.586-2.332,9.917h-0.028c0-5.426-0.369-10.867-0.575-16.287h-2.36l1.016,18.856h2.992l2.225-8.911h0.027c0.646,2.994,1.447,5.946,2.223,8.911h3.156l0.935-18.856H88.588z M99.652,19.312v16.537h-2.773V19.312h-4.775v-2.319h12.299v2.319H99.652z M110.221,19.256v6.258h6.532v2.263h-6.532v8.073h-2.662V16.993h9.553v2.263H110.221z M131.33,22.608c0,4.453-3.627,6.81-7.795,6.424c0,2.271,0,4.545,0,6.816h-2.663V16.993C125.359,16.742,131.33,16.541,131.33,22.608z M128.559,22.832c0-2.192-1.271-3.687-3.515-3.687c-1.435,0-1.51-0.167-1.51,1.157c0,2.119,0,4.237,0,6.356C126.254,27.184,128.559,25.727,128.559,22.832z M135.393,35.849V16.993h2.662v16.51h6.725v2.347H135.393z"/>
<path d="M43.725,4.708c-3.029,0-5.909,0.628-8.526,1.752c-2.617-1.124-5.497-1.752-8.527-1.752c-11.957,0-21.646,9.696-21.646,21.654s9.689,21.653,21.646,21.653c3.03,0,5.91-0.628,8.527-1.753c2.617,1.125,5.497,1.753,8.526,1.753c11.957,0,21.654-9.695,21.654-21.653S55.682,4.708,43.725,4.708z M43.745,41.475c-3.266,0-6.285-1.052-8.746-2.825c-2.46,1.773-5.486,2.825-8.751,2.825c-8.275,0-14.98-6.712-14.98-14.988c0-8.273,6.706-14.979,14.98-14.979c3.267,0,6.29,1.049,8.751,2.825c2.462-1.775,5.479-2.825,8.746-2.825c8.275,0,14.986,6.705,14.986,14.979C58.73,34.763,52.02,41.475,43.745,41.475z M41.6,17.558c2.452,5.629,2.501,13.314,0.003,13.541c-2.499,0.229-3.219-0.606-2.935-9.438l-7.099-0.034c0.532,8.717-1.084,10.232-3.269,9.274c-2.186-0.955-2.088-5.994,0.167-13.344h-7.123c-4.807,9.948-0.784,16.725,2.393,18.133c3.179,1.403,8.376,2.299,11.264-2.911c2.371,4.459,7.759,4.718,11.344,3.067c3.583-1.653,7.059-9.188,2.499-18.289L41.6,17.558L41.6,17.558z"/>
</svg>

After

Width:  |  Height:  |  Size: 2.3 KiB

+1
View File
@@ -82,6 +82,7 @@ install -m 0644 \
install -m 0644 \ install -m 0644 \
"${SOURCEDIR}/COPYING" \ "${SOURCEDIR}/COPYING" \
"${DOCDIR}/COPYING" "${DOCDIR}/COPYING"
install -d "${MANDIR}"
install -m 0644 \ install -m 0644 \
"${SOURCEDIR}/yms.1" \ "${SOURCEDIR}/yms.1" \
"${MANDIR}/yms.1" "${MANDIR}/yms.1"
+4 -4
View File
@@ -184,7 +184,7 @@ echo '<tr><th>', _('Weight'), '</th><td>', format_float($box->weight, 2, 'kg'),
echo '<tr><th>', _('Storage'),"</th><td>", $box->sname, '&nbsp;'; echo '<tr><th>', _('Storage'),"</th><td>", $box->sname, '&nbsp;';
echo '<a title="', _('View'), '" href="storage.php?f=view&id=', $box->sid, '"><i class="bi-eye"></i></a>'; echo '<a title="', _('View'), '" href="storage.php?f=view&id=', $box->sid, '"><i class="bi-eye"></i></a>';
echo "</td></tr>\n"; echo "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", $box->remarks, "</td></tr>\n"; echo '<tr><th>', _('Remarks'),"</th><td>", h($box->remarks, br:true), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
@@ -293,12 +293,12 @@ echo '<h2>', _('Edit Box'), "</h2>\n";
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="label" class="form-label"><?=_('Label')?></label> <label for="label" class="form-label"><?=_('Label')?></label>
<input type="text" class="form-control" id="label" name="label" value="<?=$box->label ?>"> <input type="text" class="form-control" id="label" name="label" value="<?=h($box->label)?>">
</div> </div>
<?php form_create_select('boxtype', _('Box type'), $opt_none + $opt_boxtype, $box->boxtype); ?> <?php form_create_select('boxtype', _('Box type'), $opt_none + $opt_boxtype, $box->boxtype); ?>
<div class="mb-3"> <div class="mb-3">
<label for="content" class="form-label"><?=_('Content')?></label> <label for="content" class="form-label"><?=_('Content')?></label>
<input type="text" class="form-control" id="content" name="content" value="<?=$box->content ?>"> <input type="text" class="form-control" id="content" name="content" value="<?=h($box->content)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="color"><?=_('Color')?></label> <label for="color"><?=_('Color')?></label>
@@ -311,7 +311,7 @@ echo '<h2>', _('Edit Box'), "</h2>\n";
<?php form_create_select('sid', _('Storage'), $opt_storage, $box->sid); ?> <?php form_create_select('sid', _('Storage'), $opt_storage, $box->sid); ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$box->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($box->remarks, br:true)?></textarea>
</div> </div>
<?php <?php
+3 -3
View File
@@ -211,7 +211,7 @@ echo '<tr><th>', _('Cross section'),"</th><td>", format_float($cable->xsection,
echo '<tr><th>', _('Weight'),"</th><td>", format_float($cable->weight, 2, 'kg/m'), "</td></tr>\n"; echo '<tr><th>', _('Weight'),"</th><td>", format_float($cable->weight, 2, 'kg/m'), "</td></tr>\n";
echo '<tr><th>', _('Color'),"</th><td>", format_color($cable->color), "</td></tr>\n"; echo '<tr><th>', _('Color'),"</th><td>", format_color($cable->color), "</td></tr>\n";
echo '<tr><th>', _('Condition'),"</th><td>", $opt_cablecond[$cable->cablecond], "</td></tr>\n"; echo '<tr><th>', _('Condition'),"</th><td>", $opt_cablecond[$cable->cablecond], "</td></tr>\n";
echo "<tr><th>", _('Remarks'), "</th><td>", nl2br($cable->remarks), "</td></tr>\n"; echo "<tr><th>", _('Remarks'), "</th><td>", h($cable->remarks, br:true), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
@@ -233,7 +233,7 @@ echo '<h2>', _('Edit cable'), "</h2>\n";
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="mname" class="form-label"><?=_('Name')?></label> <label for="mname" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="cablename" name="cablename" value="<?=$cable->cablename;?>"> <input type="text" class="form-control" id="cablename" name="cablename" value="<?=h($cable->cablename)?>">
</div> </div>
<?php <?php
form_create_select('cabletype', _('Type'), $g_opt_none + $opt_cabletype, $cable->cabletype); form_create_select('cabletype', _('Type'), $g_opt_none + $opt_cabletype, $cable->cabletype);
@@ -267,7 +267,7 @@ form_create_select('cablecond', _('Condition'), $opt_cablecond, $cable->cablecon
?> ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$cable->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($cable->remarks, br:true)?></textarea>
</div> </div>
<?php <?php
+27 -27
View File
@@ -271,28 +271,28 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
echo "<h2>", $company->compname, "</h2>\n"; echo "<h2>", $company->compname, "</h2>\n";
echo '<table class="table">', "\n"; echo '<table class="table">', "\n";
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", $company->compname, "</td></tr>\n"; echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", h($company->compname), "</td></tr>\n";
echo '<tr><th scope="row">', _('Short name'),"</th><td>", $company->shortname, "</td></tr>\n"; echo '<tr><th scope="row">', _('Short name'),"</th><td>", h($company->shortname), "</td></tr>\n";
echo '<tr><th scope="row">', _('Type'),"</th><td>", $opt_comptype[$company->comptype], "</td></tr>\n"; echo '<tr><th scope="row">', _('Type'),"</th><td>", $opt_comptype[$company->comptype], "</td></tr>\n";
echo '<tr><th scope="row">', _('Secondary type'),"</th><td>", $company->comptype2 ? $opt_comptype[$company->comptype2] : '-', "</td></tr>\n"; echo '<tr><th scope="row">', _('Secondary type'),"</th><td>", $company->comptype2 ? $opt_comptype[$company->comptype2] : '-', "</td></tr>\n";
echo '<tr><th scope="row">', _('Street'),"</th><td>", $company->street, "</td></tr>\n"; echo '<tr><th scope="row">', _('Street'),"</th><td>", h($company->street), "</td></tr>\n";
echo '<tr><th scope="row">', _('Zip, City'),"</th><td>", $company->zip, ' ', $company->city, "</td></tr>\n"; echo '<tr><th scope="row">', _('Zip, City'),"</th><td>", $company->zip, ' ', $company->city, "</td></tr>\n";
echo '<tr><th scope="row">', _('Country'),"</th><td>", $company->country, "</td></tr>\n"; echo '<tr><th scope="row">', _('Country'),"</th><td>", h($company->country), "</td></tr>\n";
echo '<tr><th scope="row">', _('Contact'),"</th><td>", $company->contact, "</td></tr>\n"; echo '<tr><th scope="row">', _('Contact'),"</th><td>", h($company->contact), "</td></tr>\n";
echo '<tr><th scope="row">', _('Phone'),"</th><td>"; echo '<tr><th scope="row">', _('Phone'),"</th><td>";
echo make_phonelink($company->phone),' ', $company->phone, "</td></tr>\n"; echo make_phonelink($company->phone),' ', h($company->phone), "</td></tr>\n";
echo '<tr><th scope="row">', _('Email'),"</th><td>"; echo '<tr><th scope="row">', _('Email'),"</th><td>";
echo make_maillink($company->email),' ', $company->email, "</td></tr>\n"; echo make_maillink($company->email),' ', h($company->email), "</td></tr>\n";
echo '<tr><th scope="row">', _('Web'),"</th><td>"; echo '<tr><th scope="row">', _('Web'),"</th><td>";
// echo '<a title="', _('Go to website'), '" href="', // echo '<a title="', _('Go to website'), '" href="',
echo make_weblink($company->web), ' ', $company->web, "</td></tr>\n"; echo make_weblink($company->web), ' ', h($company->web), "</td></tr>\n";
echo '<tr><th scope="row">', _('Customer no.'),"</th><td>", $company->customerno, "</td></tr>\n"; echo '<tr><th scope="row">', _('Customer no.'),"</th><td>", h($company->customerno), "</td></tr>\n";
echo '<tr><th scope="row">', _('Contract no.'),"</th><td>", $company->contractno, "</td></tr>\n"; echo '<tr><th scope="row">', _('Contract no.'),"</th><td>", h($company->contractno), "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", $company->remarks, "</td></tr>\n"; echo '<tr><th scope="row">', _('Remarks'),"</th><td>", h($company->remarks, br:true), "</td></tr>\n";
echo '<tr><th scope="row">', _('Flags'),"</th><td>", $company->flags, "</td></tr>\n"; echo '<tr><th scope="row">', _('Flags'),"</th><td>", $company->flags, "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
@@ -303,7 +303,7 @@ $sql = "SELECT eid, ename FROM equipment WHERE supplier=:id OR manufacturer=:id"
$sth = $pdo->prepare($sql); $sth = $pdo->prepare($sql);
$sth->execute([':id' => $id]); $sth->execute([':id' => $id]);
if ($sth->rowCount() > 0) { if ($sth->rowCount() > 0) {
echo "<p>Referenced in equipment:</p>\n"; echo '<p>', _('Referenced in equipment'), ":</p>\n";
echo "<ul>\n"; echo "<ul>\n";
foreach ($sth->fetchAll() as $row) { foreach ($sth->fetchAll() as $row) {
echo "<li>", $row['ename'], ' '; echo "<li>", $row['ename'], ' ';
@@ -353,11 +353,11 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="compname" class="form-label"><?=_('Name')?></label> <label for="compname" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="compname" name="compname" value="<?=$company->compname ?>"> <input type="text" class="form-control" id="compname" name="compname" value="<?=h($company->compname)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="shortname" class="form-label"><?=_('Short name')?></label> <label for="shortname" class="form-label"><?=_('Short name')?></label>
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=$company->shortname ?>"> <input type="text" class="form-control" id="shortname" name="shortname" value="<?=h($company->shortname)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="comptype" class="form-label"><?=_('Company type')?></label> <label for="comptype" class="form-label"><?=_('Company type')?></label>
@@ -378,47 +378,47 @@ form_create_select('comptype2', _('Secondary company type'), $g_opt_none + $opt_
?> ?>
<div class="mb-3"> <div class="mb-3">
<label for="street" class="form-label"><?=_('Street')?></label> <label for="street" class="form-label"><?=_('Street')?></label>
<input type="text" class="form-control" id="street" name="street" value="<?=$company->street ?>"> <input type="text" class="form-control" id="street" name="street" value="<?=h($company->street)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="zip" class="form-label"><?=_('Zip')?></label> <label for="zip" class="form-label"><?=_('Zip')?></label>
<input type="text" class="form-control" id="zip" name="zip" value="<?=$company->zip ?>"> <input type="text" class="form-control" id="zip" name="zip" value="<?=h($company->zip)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="city" class="form-label"><?=_('City')?></label> <label for="city" class="form-label"><?=_('City')?></label>
<input type="text" class="form-control" id="city" name="city" value="<?=$company->city ?>"> <input type="text" class="form-control" id="city" name="city" value="<?=h($company->city)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="country" class="form-label"><?=_('Country')?></label> <label for="country" class="form-label"><?=_('Country')?></label>
<input type="text" class="form-control" id="country" name="country" value="<?=$company->country ?>"> <input type="text" class="form-control" id="country" name="country" value="<?=h($company->country)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="contact" class="form-label"><?=_('Contact')?></label> <label for="contact" class="form-label"><?=_('Contact')?></label>
<input type="text" class="form-control" id="contact" name="contact" value="<?=$company->contact ?>"> <input type="text" class="form-control" id="contact" name="contact" value="<?=h($company->contact)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="phone" class="form-label"><?=_('Phone')?></label> <label for="phone" class="form-label"><?=_('Phone')?></label>
<input type="text" class="form-control" id="phone" name="phone" value="<?=$company->phone ?>"> <input type="text" class="form-control" id="phone" name="phone" value="<?=h($company->phone)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="email" class="form-label"><?=_('Email')?></label> <label for="email" class="form-label"><?=_('Email')?></label>
<input type="text" class="form-control" id="email" name="email" value="<?=$company->email ?>"> <input type="text" class="form-control" id="email" name="email" value="<?=h($company->email)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="web" class="form-label"><?=_('Web')?></label> <label for="web" class="form-label"><?=_('Web')?></label>
<input type="text" class="form-control" id="web" name="web" value="<?=$company->web ?>"> <input type="text" class="form-control" id="web" name="web" value="<?=h($company->web)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="customerno" class="form-label"><?=_('Customer no.')?></label> <label for="customerno" class="form-label"><?=_('Customer no.')?></label>
<input type="text" class="form-control" id="customerno" name="customerno" value="<?=$company->customerno ?>"> <input type="text" class="form-control" id="customerno" name="customerno" value="<?=h($company->customerno)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="contractno" class="form-label"><?=_('Contract no.')?></label> <label for="contractno" class="form-label"><?=_('Contract no.')?></label>
<input type="text" class="form-control" id="contractno" name="contractno" value="<?=$company->contractno ?>"> <input type="text" class="form-control" id="contractno" name="contractno" value="<?=h($company->contractno)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$company->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($company->remarks, br:true)?></textarea>
</div> </div>
<?php <?php
$opt_flags = db_load_enum('company', 'flags', true, true, false); $opt_flags = db_load_enum('company', 'flags', true, true, false);
@@ -439,8 +439,8 @@ $company = $sth->fetch(PDO::FETCH_OBJ);
echo '<h2>', _('Delete Company'), "</h2>\n"; echo '<h2>', _('Delete Company'), "</h2>\n";
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n"; echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
echo '<p>Name: ', $company->compname, "</p>"; echo '<p>Name: ', h($company->compname), "</p>";
echo '<p>Remarks: ', $company->remarks, "</p>"; echo '<p>Remarks: ', h($company->remarks, br:true), "</p>";
// Still used as a supplier or manufacturer for equipment? // Still used as a supplier or manufacturer for equipment?
$sql = "SELECT COUNT(*) FROM equipment WHERE supplier=:id OR manufacturer=:id"; $sql = "SELECT COUNT(*) FROM equipment WHERE supplier=:id OR manufacturer=:id";
+5 -5
View File
@@ -488,7 +488,7 @@ if ($document->doctype == 'picture') {
echo '<div class="image-gallery">'; echo '<div class="image-gallery">';
echo '<a href="#" data-bs-toggle="modal" data-bs-target="#imageModal">'; echo '<a href="#" data-bs-toggle="modal" data-bs-target="#imageModal">';
// echo '<img width="', $g_thumb_size, '" src="dl.php?id=', $document->docid, '&t=s" alt="', $document->title, '">'; // echo '<img width="', $g_thumb_size, '" src="dl.php?id=', $document->docid, '&t=s" alt="', $document->title, '">';
echo '<img width="', $g_thumb_size, '" src="dl.php?id=', $document->docid, '" alt="', $document->title, '">'; echo '<img width="', $g_thumb_size, '" src="dl.php?id=', $document->docid, '" alt="', h($document->title), '">';
echo '</a>'; echo '</a>';
echo '</div>'; // gallery echo '</div>'; // gallery
?> ?>
@@ -535,11 +535,11 @@ if ($document->docsize == 0) {
} }
echo '<tr><th scope="row">', _('Mimetype'),"</th><td>", $document->mimetype, "</td></tr>\n"; echo '<tr><th scope="row">', _('Mimetype'),"</th><td>", $document->mimetype, "</td></tr>\n";
echo '<tr><th scope="row">', _('Filename'),"</th><td>", $document->filename, "</td></tr>\n"; echo '<tr><th scope="row">', _('Filename'),"</th><td>", h($document->filename), "</td></tr>\n";
echo '<tr><th scope="row">', _('File size'),"</th><td>", format_filesize($document->docsize), "</td></tr>\n"; echo '<tr><th scope="row">', _('File size'),"</th><td>", format_filesize($document->docsize), "</td></tr>\n";
echo '<tr><th scope="row">', _('Upload date'),"</th><td>", $document->doctime, "</td></tr>\n"; echo '<tr><th scope="row">', _('Upload date'),"</th><td>", $document->doctime, "</td></tr>\n";
echo '<tr><th scope="row">', _('Title'),"</th><td>", $document->title, "</td></tr>\n"; echo '<tr><th scope="row">', _('Title'),"</th><td>", h($document->title), "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", $document->remarks, "</td></tr>\n"; echo '<tr><th scope="row">', _('Remarks'),"</th><td>", h($document->remarks, br:true), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
echo "</div>\n", '<div class="col text-center">', "\n"; // column break echo "</div>\n", '<div class="col text-center">', "\n"; // column break
@@ -780,7 +780,7 @@ if ($document->mimetype == 'application/pdf') {
?> ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$document->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($document->remarks, br:true)?></textarea>
</div> </div>
<button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button> <button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button>
<a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a> <a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a>
+35 -11
View File
@@ -455,18 +455,18 @@ echo '<div class="row">';
echo '<div class="col">'; echo '<div class="col">';
echo '<table class="table">', "\n"; echo '<table class="table">', "\n";
echo '<tr><th>', _('Short name'),"</th><td>", $equipment->shortname, "</td></tr>\n"; echo '<tr><th>', _('Short name'),"</th><td>", h($equipment->shortname), "</td></tr>\n";
echo '<tr><th>', _('Manufacturer'),"</th><td>", $opt_manufacturer[$equipment->manufacturer]; echo '<tr><th>', _('Manufacturer'),"</th><td>", $opt_manufacturer[$equipment->manufacturer];
echo '&nbsp;<a title="', _('View'), '" href="company.php?f=view&id=', $equipment->manufacturer, '"><i class="bi-eye"></i></a>'; echo '&nbsp;<a title="', _('View'), '" href="company.php?f=view&id=', $equipment->manufacturer, '"><i class="bi-eye"></i></a>';
echo "</td></tr>\n"; echo "</td></tr>\n";
echo '<tr><th>', _('Model'),"</th><td>", $equipment->model, "</td></tr>\n"; echo '<tr><th>', _('Model'),"</th><td>", h($equipment->model), "</td></tr>\n";
echo '<tr><th>', _('Serial'),"</th><td>", $equipment->serial, "</td></tr>\n"; echo '<tr><th>', _('Serial'),"</th><td>", h($equipment->serial), "</td></tr>\n";
echo '<tr><th>', _('Weight'),"</th><td>", format_float($equipment->weight, 2, 'kg'), "</td></tr>\n"; echo '<tr><th>', _('Weight'),"</th><td>", format_float($equipment->weight, 2, 'kg'), "</td></tr>\n";
echo '<tr><th>', _('Price'),"</th><td>", format_currency($equipment->price), "</td></tr>\n"; echo '<tr><th>', _('Price'),"</th><td>", format_currency($equipment->price), "</td></tr>\n";
echo '<tr><th>', _('Purchase date'),"</th><td>", $equipment->purchdate, "</td></tr>\n"; echo '<tr><th>', _('Purchase date'),"</th><td>", $equipment->purchdate, "</td></tr>\n";
echo '<tr><th>', _('Supplier'),"</th><td>", $equipment->supplier ? $opt_supplier[$equipment->supplier] : 'n/a', "</td></tr>\n"; echo '<tr><th>', _('Supplier'),"</th><td>", $equipment->supplier ? $opt_supplier[$equipment->supplier] : 'n/a', "</td></tr>\n";
echo '<tr><th>', _('Category'),"</th><td>", $opt_ecat[$equipment->ecat], "</td></tr>\n"; echo '<tr><th>', _('Category'),"</th><td>", $opt_ecat[$equipment->ecat], "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", nl2br($equipment->remarks), "</td></tr>\n"; echo '<tr><th>', _('Remarks'),"</th><td>", h($equipment->remarks, br:true), "</td></tr>\n";
echo '<tr><th>', _('Flags'),"</th><td>", $equipment->flags, "</td></tr>\n"; echo '<tr><th>', _('Flags'),"</th><td>", $equipment->flags, "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
@@ -545,6 +545,30 @@ echo '</div>'; // container
// Buttons at bottom of data area // Buttons at bottom of data area
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
// Annotations
echo '<h3>', _('Annotations'), "</h3>\n";
$sql = "SELECT noteid, annotation "
. "FROM note "
. "WHERE notetype='equip' AND refid=?";
$sth = $pdo->prepare($sql);
$sth->execute([$id]);
if ($sth->rowCount() > 0) {
$n = 0;
foreach ($sth->fetchAll() as $row) {
$n += 1;
echo "<p>($n) {$row['annotation']}";
echo ' <a title="', _('Edit'), '" href="note.php?f=edit&id=', $row['noteid'], '"><i class="bi-pencil"></i></a>';
echo "</p>\n";
}
} else {
echo '<p>', _('No annotations for this equipment'), "</p>\n";
}
echo '<div class="container-fluid px-0 my-3">', "\n";
echo '<a href="note.php?f=add&t=equip&id=', $id, '" class="btn btn-primary" role="button">';
echo _('Add note'), "</a>\n";
echo "</div>\n";
// Maintenance records // Maintenance records
echo '<h3>', _('Maintenances'), "</h3>"; echo '<h3>', _('Maintenances'), "</h3>";
@@ -649,20 +673,20 @@ $equipment = $sth->fetch(PDO::FETCH_OBJ);
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="ename" class="form-label"><?=_('Name')?></label> <label for="ename" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="ename" name="ename" value="<?=$equipment->ename ?>"> <input type="text" class="form-control" id="ename" name="ename" value="<?=h($equipment->ename)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="shortname" class="form-label"><?=_('Short name')?></label> <label for="shortname" class="form-label"><?=_('Short name')?></label>
<input type="text" class="form-control" id="shortname" name="shortname" value="<?=$equipment->shortname ?>"> <input type="text" class="form-control" id="shortname" name="shortname" value="<?=h($equipment->shortname)?>">
</div> </div>
<?php form_create_select('manufacturer', _('Manufacturer'), $opt_manufacturer, $equipment->manufacturer); ?> <?php form_create_select('manufacturer', _('Manufacturer'), $opt_manufacturer, $equipment->manufacturer); ?>
<div class="mb-3"> <div class="mb-3">
<label for="model" class="form-label"><?=_('Model')?></label> <label for="model" class="form-label"><?=_('Model')?></label>
<input type="text" class="form-control" id="model" name="model" value="<?=$equipment->model ?>"> <input type="text" class="form-control" id="model" name="model" value="<?=h($equipment->model)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="serial" class="form-label"><?=_('Serial')?></label> <label for="serial" class="form-label"><?=_('Serial')?></label>
<input type="text" class="form-control" id="serial" name="serial" value="<?=$equipment->serial ?>"> <input type="text" class="form-control" id="serial" name="serial" value="<?=h($equipment->serial)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="weight" class="form-label"><?=_('Weight, kg')?></label> <label for="weight" class="form-label"><?=_('Weight, kg')?></label>
@@ -682,7 +706,7 @@ form_create_select('category', _('Category'), $g_opt_unknown + $opt_ecat, $equip
?> ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$equipment->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($equipment->remarks, br:true)?></textarea>
</div> </div>
<?php <?php
$opt_flags = db_load_enum('equipment', 'flags', true, true, false); $opt_flags = db_load_enum('equipment', 'flags', true, true, false);
@@ -705,8 +729,8 @@ $equipment = $sth->fetch(PDO::FETCH_OBJ);
echo '<h2>', _('Delete equipment'),"</h2>\n"; echo '<h2>', _('Delete equipment'),"</h2>\n";
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n"; echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
echo '<p>Name: ', $equipment->ename, "</p>"; echo '<p>Name: ', h($equipment->ename), "</p>";
echo '<p>Remarks: ', $equipment->remarks, "</p>"; echo '<p>Remarks: ', h($equipment->remarks, br:true), "</p>";
echo '<p>', _('Deleting an equipment item is final. There is no way back. Only delete if you are absolute sure.'), "</p>\n"; echo '<p>', _('Deleting an equipment item is final. There is no way back. Only delete if you are absolute sure.'), "</p>\n";
+3 -3
View File
@@ -173,7 +173,7 @@ foreach ($res as $row) {
echo "<td>", $row['description'], "</td>\n"; echo "<td>", $row['description'], "</td>\n";
// Edit current record button // Edit current record button
echo "<td>"; echo "<td>";
echo '<a title="', _('Edit'), '" href="', $g_scriptname, '?f=edit&id=', $row['fusevid'], '"><i class="bi bi-pencil"></i></a>', "\n"; echo '<a title="', _('Edit'), '" href="', $g_scriptname, '?f=edit&id=', $row['fuseid'], '"><i class="bi bi-pencil"></i></a>', "\n";
echo "</td>\n"; echo "</td>\n";
echo "</tr>\n"; echo "</tr>\n";
} }
@@ -234,7 +234,7 @@ echo '<tr><th>', _('Current'),"</th><td>", $fuse->current, "A</td></tr>\n";
echo '<tr><th>', _('Location'),"</th><td>", $opt_location[$fuse->location], "</td></tr>\n"; echo '<tr><th>', _('Location'),"</th><td>", $opt_location[$fuse->location], "</td></tr>\n";
echo '<tr><th>', _('Cable'),"</th><td>", $fuse->cableid, "</td></tr>\n"; echo '<tr><th>', _('Cable'),"</th><td>", $fuse->cableid, "</td></tr>\n";
echo '<tr><th>', _('Equipment'),"</th><td>", $fuse->eid, "</td></tr>\n"; echo '<tr><th>', _('Equipment'),"</th><td>", $fuse->eid, "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", nl2br($fuse->remarks), "</td></tr>\n"; echo '<tr><th>', _('Remarks'),"</th><td>", h($fuse->remarks, br:true), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
@@ -259,7 +259,7 @@ echo '<h2>', _('Edit fuse'), "</h2>\n";
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="note" class="form-label"><?=_('Description')?></label> <label for="note" class="form-label"><?=_('Description')?></label>
<input type="text" class="form-control" id="description" name="description" value="<?=$fuse->description ?>"> <input type="text" class="form-control" id="description" name="description" value="<?=h($fuse->description)?>">
</div> </div>
<?php <?php
+34 -4
View File
@@ -12,7 +12,8 @@
* # Date Changes by * # Date Changes by
* ------ ------------ ---------------------------------------------- ----- * ------ ------------ ---------------------------------------------- -----
* 0.1.0 2024-03-12 Started development tho * 0.1.0 2024-03-12 Started development tho
' 0.2.0 2026-08-18 First public release tho * 0.2.0 2026-08-18 First public release tho
* 0.2.1 2026-08-28 Foreign keys, bugfixes and output sanitation tho
* *
*/ */
@@ -48,7 +49,7 @@ define('ROLE_SAILOR', 'sailor');
// ========== PAGE START CODE ================================================= // ========== PAGE START CODE =================================================
// global version string // global version string
$g_version = 'v0.2.0'; $g_version = 'v0.2.1';
$g_scriptname = basename($_SERVER['SCRIPT_NAME']); $g_scriptname = basename($_SERVER['SCRIPT_NAME']);
@@ -936,6 +937,21 @@ function db_get_opt_proj($vid, $exclude=[], $default=NULL) {
return $list; return $list;
} }
function db_get_opt_cable($vid, $default=NULL) {
global $pdo;
if (isset($default)) {
$list = $default;
} else {
$list = array();
}
$sql = "SELECT cableid, cablename FROM cable WHERE vid=? ORDER BY cablename";
$sth = $pdo->query($sql);
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
$list[$row[0]] = h($row[1]);
}
return $list;
}
function db_get_filter($user, $sno, $fields = []) { function db_get_filter($user, $sno, $fields = []) {
// if fields supplied empting missing field are created // if fields supplied empting missing field are created
global $pdo; global $pdo;
@@ -1233,6 +1249,18 @@ function format_currency($val) {
} }
} }
function format_date($date) {
global $user;
// $user->datefmt;
/*'Y-m-d' => _('YYYY-MM-DD'). $curdate->format(' - Y-m-d'),
'Y/m/d' => _('YYYY/MM/DD'). $curdate->format(' - Y/m/d'),
'd.m.Y' => _('DD.MM.YYYY'). $curdate->format(' - d.m.Y'),
'd/m/Y' => _('DD/MM/YYYY'). $curdate->format(' - d/m/Y'),
'm-d-Y' => _('MM/DD/YYYY'). $curdate->format(' - m-d-Y') */
return '';
}
function format_color($color) { function format_color($color) {
$colstr = '<span style="'; $colstr = '<span style="';
$style = "padding:2px 4px;border-radius:4px;background-color:#".$color; $style = "padding:2px 4px;border-radius:4px;background-color:#".$color;
@@ -1296,9 +1324,11 @@ function format_measurement($n, $unit, $v1, $v2, $v3) {
// ========== COMMON FUNCTIONS ================================================ // ========== COMMON FUNCTIONS ================================================
function h($value) { function h($value, $br=false) {
// escape value coming from db for safe html output // escape value coming from db for safe html output
return htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8'); // optional convert line breaks to <br> tags
$value = htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
return $br ? nl2br($value) : $value;
} }
function header_location($location, $message=NULL) { function header_location($location, $message=NULL) {
+1 -1
View File
@@ -171,7 +171,7 @@ if ($vessel->shipyard && $vessel->shipyard > 0) {
} }
} }
if (strlen($vessel->remarks) > 0) { if (strlen($vessel->remarks) > 0) {
echo nl2br($vessel->remarks); echo h($vessel->remarks, br:true);
} }
echo "</div>\n"; echo "</div>\n";
echo "</div>\n"; // row 2 echo "</div>\n"; // row 2
+3 -3
View File
@@ -396,7 +396,7 @@ echo "<tr><th>", _('Weight'), "</th><td>", format_float($inventory->weight, 2, '
echo "<tr><th>", _('Price'), "</th><td>", format_currency($inventory->price), "</td></tr>\n"; echo "<tr><th>", _('Price'), "</th><td>", format_currency($inventory->price), "</td></tr>\n";
echo "<tr><th>", _('Purchase date'), "</th><td>", $inventory->purchdate, "</td></tr>\n"; echo "<tr><th>", _('Purchase date'), "</th><td>", $inventory->purchdate, "</td></tr>\n";
echo "<tr><th>", _('Condition'), "</th><td>", $opt_invcond[$inventory->invcond], "</td></tr>\n"; echo "<tr><th>", _('Condition'), "</th><td>", $opt_invcond[$inventory->invcond], "</td></tr>\n";
echo "<tr><th>", _('Remarks'), "</th><td>", nl2br($inventory->remarks), "</td></tr>\n"; echo "<tr><th>", _('Remarks'), "</th><td>", h($inventory->remarks, br:true), "</td></tr>\n";
$tags = db_load_taglist('inv', $id); $tags = db_load_taglist('inv', $id);
form_tag_assignment($g_scriptname, $id, $tags); form_tag_assignment($g_scriptname, $id, $tags);
@@ -422,7 +422,7 @@ $inventory = $sth->fetch(PDO::FETCH_OBJ);
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="invname" class="form-label"><?=_('Name')?></label> <label for="invname" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="invname" name="invname" value="<?=$inventory->invname ?>"> <input type="text" class="form-control" id="invname" name="invname" value="<?=h($inventory->invname)?>">
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="number" class="form-label"><?=_('Number')?></label> <label for="number" class="form-label"><?=_('Number')?></label>
@@ -464,7 +464,7 @@ foreach ($cond as $k => $v) {
<?php form_create_select('eid', _('Equipment'), $opt_equipment, $inventory->eid); ?> <?php form_create_select('eid', _('Equipment'), $opt_equipment, $inventory->eid); ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$inventory->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($inventory->remarks, br:true)?></textarea>
</div> </div>
<?php <?php
+338 -313
View File
File diff suppressed because it is too large Load Diff
Binary file not shown.
Binary file not shown.
+8 -6
View File
@@ -245,14 +245,15 @@ elseif ($action == ACT_VIEW):
echo '<h2>', _('View Maintenance'), "</h2>\n"; echo '<h2>', _('View Maintenance'), "</h2>\n";
// load maintenance record
$sql = "SELECT m.activities, m.eid, m.remarks, m.series, m.maintstate, e.ename " $sql = "SELECT m.activities, m.eid, m.remarks, m.series, m.maintstate, e.ename "
. "FROM maintenance AS m LEFT OUTER JOIN equipment AS e USING (eid) " . "FROM maintenance AS m LEFT OUTER JOIN equipment AS e USING (eid) "
. "WHERE m.maintid=?"; . "WHERE m.maintid=?";
$sth = $pdo->prepare($sql); $sth = $pdo->prepare($sql);
$sth->execute([$id]); $sth->execute([$id]);
$maint = $sth->fetch(PDO::FETCH_OBJ); $maint = $sth->fetch(PDO::FETCH_OBJ);
if ($maint !== false && isset($maint->eid)) {
if (isset($maint->eid)) { // if available load document references
$sql = "SELECT r.docid, d.filename, d.title, d.hash, d.extension " $sql = "SELECT r.docid, d.filename, d.title, d.hash, d.extension "
. "FROM docref AS r INNER JOIN document AS d USING (docid) " . "FROM docref AS r INNER JOIN document AS d USING (docid) "
. "WHERE r.reftype='equipment' AND r.refid=?"; . "WHERE r.reftype='equipment' AND r.refid=?";
@@ -260,6 +261,7 @@ if (isset($maint->eid)) {
$sth->execute([$maint->eid]); $sth->execute([$maint->eid]);
$docs = $sth->fetchAll(); $docs = $sth->fetchAll();
} else { } else {
$maint = new stdClass();
$maint->ename = _('n/a'); $maint->ename = _('n/a');
unset($docs); unset($docs);
} }
@@ -271,13 +273,13 @@ echo '<div class="col">';
echo '<table class="table">', "\n"; echo '<table class="table">', "\n";
echo '<tr><th>', _('Activities'),"</th><td>", $maint->activities, "</td></tr>\n"; echo '<tr><th>', _('Activities'),"</th><td>", $maint->activities, "</td></tr>\n";
echo '<tr><th>', _('Equipment'),"</th><td>", $maint->ename; echo '<tr><th>', _('Equipment'),"</th><td>", h($maint->ename);
if (isset($maint->eid) and $maint->eid>0) { if (isset($maint->eid) and $maint->eid>0) {
// Link to equipment // Link to equipment
echo ' <a href="equipment.php?f=view&id=', $maint->eid, '"><i class="bi-eye"></i></a>'; echo ' <a href="equipment.php?f=view&id=', $maint->eid, '"><i class="bi-eye"></i></a>';
} }
echo "</td></tr>\n"; echo "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", $maint->remarks, "</td></tr>\n"; echo '<tr><th>', _('Remarks'),"</th><td>", h($maint->remarks), "</td></tr>\n";
echo '<tr><th>', _('Series'),"</th><td>", $maint->series, "</td></tr>\n"; echo '<tr><th>', _('Series'),"</th><td>", $maint->series, "</td></tr>\n";
echo '<tr><th scope="row">', _('State'),"</th><td>", get_enum($maint->maintstate), "</td></tr>\n"; echo '<tr><th scope="row">', _('State'),"</th><td>", get_enum($maint->maintstate), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
@@ -343,12 +345,12 @@ echo '<h2>', _('Edit Maintenance'), "</h2>\n";
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="activities" class="form-label"><?=_('Activities')?></label> <label for="activities" class="form-label"><?=_('Activities')?></label>
<input type="text" class="form-control" id="activities" name="activities" value="<?=$maint->activities ?>"> <input type="text" class="form-control" id="activities" name="activities" value="<?=h($maint->activities)?>">
</div> </div>
<?php form_create_select('eid', _('Equipment'), $opt_equipment, $maint->eid); ?> <?php form_create_select('eid', _('Equipment'), $opt_equipment, $maint->eid); ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$maint->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($maint->remarks, br:true)?></textarea>
</div> </div>
<div class="mb-3"> <div class="mb-3">
<label for="series" class="form-label"><?=_('Series')?></label> <label for="series" class="form-label"><?=_('Series')?></label>
+9 -9
View File
@@ -300,15 +300,15 @@ $measurement = $sth->fetch(PDO::FETCH_OBJ);
echo '<h2>', _('Measurement'), "</h2>\n"; echo '<h2>', _('Measurement'), "</h2>\n";
echo '<table class="table">', "\n"; echo '<table class="table">', "\n";
echo '<tr><th style="width:20%">', _('Name'),"</th><td>", $measurement->mname, "</td></tr>\n"; echo '<tr><th style="width:20%">', _('Name'),"</th><td>", h($measurement->mname), "</td></tr>\n";
echo '<tr><th>', _('Unit'),"</th><td>", $opt_unit[$measurement->unit], "</td></tr>\n"; echo '<tr><th>', _('Unit'), '</th><td>', $opt_unit[$measurement->unit], "</td></tr>\n";
echo '<tr><th>', _('Values'),"</th><td>$measurement->nval</td></tr>\n"; echo '<tr><th>', _('Values'), '</th><td>', $measurement->nval, "</td></tr>\n";
echo '<tr><th>', _('Value 1'),"</th><td>$measurement->val1</td></tr>\n"; echo '<tr><th>', _('Value 1'), '</th><td>', $measurement->val1, "</td></tr>\n";
echo '<tr><th>', _('Value 2'),"</th><td>$measurement->val2</td></tr>\n"; echo '<tr><th>', _('Value 2'), '</th><td>', $measurement->val2, "</td></tr>\n";
echo '<tr><th>', _('Value 3'),"</th><td>$measurement->val3</td></tr>\n"; echo '<tr><th>', _('Value 3'), '</th><td>', $measurement->val3, "</td></tr>\n";
echo '<tr><th>', _('Accuracy'),"</th><td>$measurement->accuracy</td></tr>\n"; echo '<tr><th>', _('Accuracy'), '</th><td>', get_enum($measurement->accuracy), "</td></tr>\n";
echo '<tr><th>', _('Date'),"</th><td>$measurement->mdate</td></tr>\n"; echo '<tr><th>', _('Date'), '</th><td>', $measurement->mdate, "</td></tr>\n";
echo '<tr><th>', _('Note'),"</th><td>$measurement->note</td></tr>\n"; echo '<tr><th>', _('Note'), '</th><td>', h($measurement->note), "</td></tr>\n";
echo '<tr><th>', _('Equipment'), '</th><td>', $opt_equipment[$measurement->eid], "</td></tr>\n"; echo '<tr><th>', _('Equipment'), '</th><td>', $opt_equipment[$measurement->eid], "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
+7 -1
View File
@@ -130,7 +130,7 @@ echo '<h2>', _('Add Note'), "</h2>\n";
$notetype = gpc_get_enum($_REQUEST, 't', $opt_notetype); $notetype = gpc_get_enum($_REQUEST, 't', $opt_notetype);
// get task info for reference // get object info for reference
if ($notetype == 'task') { if ($notetype == 'task') {
$sql = "SELECT taskname FROM task WHERE taskid=?"; $sql = "SELECT taskname FROM task WHERE taskid=?";
$sth = $pdo->prepare($sql); $sth = $pdo->prepare($sql);
@@ -143,6 +143,12 @@ if ($notetype == 'task') {
$sth->execute([$id]); $sth->execute([$id]);
$activities = $sth->fetchColumn(); $activities = $sth->fetchColumn();
echo '<h3>', sprintf(_('Maintenance: %s'), $activities), "</h3>\n"; echo '<h3>', sprintf(_('Maintenance: %s'), $activities), "</h3>\n";
} elseif ($notetype == 'equip') {
$sql = "SELECT ename FROM equipment WHERE eid=?";
$sth = $pdo->prepare($sql);
$sth->execute([$id]);
$ename = $sth->fetchColumn();
echo '<h3>', sprintf(_('Equipment: %s'), $ename), "</h3>\n";
} }
?> ?>
+3 -3
View File
@@ -307,14 +307,14 @@ $sth->execute([$id]);
$project = $sth->fetch(PDO::FETCH_OBJ); $project = $sth->fetch(PDO::FETCH_OBJ);
echo "<h2>", $project->projname, "</h2>\n"; echo "<h2>", $project->projname, "</h2>\n";
echo '<table class="table">', "\n"; echo '<table class="table">', "\n";
echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", $project->projname, "</td></tr>\n"; echo '<tr><th scope="row" style="width:20%">', _('Name'),"</th><td>", h($project->projname), "</td></tr>\n";
echo '<tr><th scope="row">', _('Responsible'),"</th><td>", $opt_user[$project->responsible], "</td></tr>\n"; echo '<tr><th scope="row">', _('Responsible'),"</th><td>", $opt_user[$project->responsible], "</td></tr>\n";
echo '<tr><th scope="row">', _('Start date'),"</th><td>", $project->startdate, "</td></tr>\n"; echo '<tr><th scope="row">', _('Start date'),"</th><td>", $project->startdate, "</td></tr>\n";
echo '<tr><th scope="row">', _('Duration'),"</th><td>", $project->duration, "</td></tr>\n"; echo '<tr><th scope="row">', _('Duration'),"</th><td>", $project->duration, "</td></tr>\n";
echo '<tr><th scope="row">', _('Costs plan'),"</th><td>", format_currency($project->costs_plan), "</td></tr>\n"; echo '<tr><th scope="row">', _('Costs plan'),"</th><td>", format_currency($project->costs_plan), "</td></tr>\n";
echo '<tr><th scope="row">', _('Costs final'),"</th><td>", format_currency($project->costs_final), "</td></tr>\n"; echo '<tr><th scope="row">', _('Costs final'),"</th><td>", format_currency($project->costs_final), "</td></tr>\n";
echo '<tr><th scope="row">', _('State'),"</th><td>", get_enum($project->projstate), "</td></tr>\n"; echo '<tr><th scope="row">', _('State'),"</th><td>", get_enum($project->projstate), "</td></tr>\n";
echo '<tr><th scope="row">', _('Remarks'),"</th><td>", nl2br($project->remarks), "</td></tr>\n"; echo '<tr><th scope="row">', _('Remarks'),"</th><td>", h($project->remarks, br:true), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
@@ -401,7 +401,7 @@ form_create_select('projstate', _('Status'), $opt_state, $project->projstate);
?> ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$project->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($project->remarks, br:true)?></textarea>
</div> </div>
<button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button> <button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button>
<a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a> <a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a>
+2 -2
View File
@@ -292,7 +292,7 @@ echo '<tr><th>', _('Storedate'),"</th><td>", $prov->storedate, "</td></tr>\n";
echo '<tr><th>', _('Shelflife'),"</th><td>", $prov->shelflife, "</td></tr>\n"; echo '<tr><th>', _('Shelflife'),"</th><td>", $prov->shelflife, "</td></tr>\n";
echo '<tr><th>', _('Price'), "</th><td>", format_currency($prov->price), "</td></tr>\n"; echo '<tr><th>', _('Price'), "</th><td>", format_currency($prov->price), "</td></tr>\n";
echo '<tr><th>', _('Storage'),"</th><td>", ($opt_storage[$prov->sid] ?? ''), "</td></tr>\n"; echo '<tr><th>', _('Storage'),"</th><td>", ($opt_storage[$prov->sid] ?? ''), "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", nl2br($prov->remarks), "</td></tr>\n"; echo '<tr><th>', _('Remarks'),"</th><td>", h($prov->remarks, br:true), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
@@ -359,7 +359,7 @@ form_create_select('sid', _('Storage'), $g_opt_none + $opt_storage, $prov->sid);
?> ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3" maxlength="150"><?=$prov->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3" maxlength="150"><?=h($prov->remarks, br:true)?></textarea>
</div> </div>
<?php <?php
form_edit_buttons($g_scriptname, $id); form_edit_buttons($g_scriptname, $id);
+5 -5
View File
@@ -231,7 +231,7 @@ echo '<tr><th>', _('Location (x, y, z)'),"</th><td>(", $storage->x, ', ', $stora
echo '<tr><th>', _('Width (wx, wy, wz)'),"</th><td>(", $storage->wx, ', ', $storage->wy, ', ', $storage->wz, ")</td></tr>\n"; echo '<tr><th>', _('Width (wx, wy, wz)'),"</th><td>(", $storage->wx, ', ', $storage->wy, ', ', $storage->wz, ")</td></tr>\n";
echo '<tr><th>', _('Angle'),"</th><td>", $storage->angle, "°</td></tr>\n"; echo '<tr><th>', _('Angle'),"</th><td>", $storage->angle, "°</td></tr>\n";
echo '<tr><th>', _('Color'),"</th><td>", $storage->color, "</td></tr>\n"; echo '<tr><th>', _('Color'),"</th><td>", $storage->color, "</td></tr>\n";
echo '<tr><th>', _('Remarks'),"</th><td>", $storage->remarks, "</td></tr>\n"; echo '<tr><th>', _('Remarks'),"</th><td>", h($storage->remarks), "</td></tr>\n";
echo "</table>\n"; echo "</table>\n";
form_view_buttons($g_scriptname, $id); form_view_buttons($g_scriptname, $id);
@@ -314,7 +314,7 @@ $storage = $sth->fetch(PDO::FETCH_OBJ);
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="sname" class="form-label"><?=_('Name')?></label> <label for="sname" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="sname" name="sname" value="<?=$storage->sname ?>"> <input type="text" class="form-control" id="sname" name="sname" value="<?=h($storage->sname)?>">
</div> </div>
<?php <?php
form_create_select('stype', _('Type'), $opt_stype, $storage->stype); form_create_select('stype', _('Type'), $opt_stype, $storage->stype);
@@ -358,7 +358,7 @@ form_create_select('stype', _('Type'), $opt_stype, $storage->stype);
<?php form_create_select('capaunit', _('Capacity Unit'), $opt_capaunit, $storage->capaunit); ?> <?php form_create_select('capaunit', _('Capacity Unit'), $opt_capaunit, $storage->capaunit); ?>
<div class="mb-3"> <div class="mb-3">
<label for="remarks" class="form-label"><?=_('Remarks')?></label> <label for="remarks" class="form-label"><?=_('Remarks')?></label>
<textarea class="form-control" id="remarks" name="remarks" rows="3"><?=$storage->remarks ?></textarea> <textarea class="form-control" id="remarks" name="remarks" rows="3"><?=h($storage->remarks, br:true)?></textarea>
</div> </div>
<button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button> <button type="submit" name="submit[update]" class="btn btn-primary"><?=_('Save')?></button>
<a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a> <a href="<?=$g_scriptname?>?f=view&id=<?=$id?>" class="btn btn-secondary"><?=_('Back')?></a>
@@ -377,8 +377,8 @@ $storage = $sth->fetch(PDO::FETCH_OBJ);
echo '<h2>', _('Delete Storage'), "</h2>\n"; echo '<h2>', _('Delete Storage'), "</h2>\n";
echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n"; echo '<p>', sprintf(_('Record no. %d'), $id), "</p>\n";
echo '<p>Name: ', $storage->sname, "</p>"; echo '<p>Name: ', h($storage->sname), "</p>";
echo '<p>Remarks: ', $storage->remarks, "</p>"; echo '<p>Remarks: ', h($storage->remarks, br:true), "</p>";
echo '<p>', _('Deleting a storage is final. There is no way back. Only delete if you are absolute sure.'), "</p>\n"; echo '<p>', _('Deleting a storage is final. There is no way back. Only delete if you are absolute sure.'), "</p>\n";
+2 -3
View File
@@ -127,7 +127,6 @@ page_caption_search($pagetitle);
// load filter from db // load filter from db
$flt = db_get_filter($user->id, 206, ['txt', 'prio', 'stat', 'proj']); $flt = db_get_filter($user->id, 206, ['txt', 'prio', 'stat', 'proj']);
$w = array('(t.vid=:vid OR t.vid IS NULL)'); $w = array('(t.vid=:vid OR t.vid IS NULL)');
$p = array(':vid' => $user->vid); $p = array(':vid' => $user->vid);
if (strlen($flt->txt) > 1) { if (strlen($flt->txt) > 1) {
@@ -215,7 +214,7 @@ filter_create_select('flt_prio', _('Priority'), $g_opt_all + $g_opt_none + $opt_
</div> </div>
<?php <?php
$opt_status = db_load_enum('task', 'taskstate', true, true, false); $opt_status = db_load_enum('task', 'taskstate', true, true, false);
filter_create_checks('flt_stat', _('Status'), $opt_status, $flt->stat); filter_create_checks('flt_stat', _('Status'), $opt_status, $flt->stat ?? []);
?> ?>
</div> </div>
<div class="card-footer"> <div class="card-footer">
@@ -367,7 +366,7 @@ echo '<h2>', _('Edit Task'), "</h2>\n";
<input type="hidden" name="id" value="<?=$id?>"> <input type="hidden" name="id" value="<?=$id?>">
<div class="mb-3"> <div class="mb-3">
<label for="taskname" class="form-label"><?=_('Name')?></label> <label for="taskname" class="form-label"><?=_('Name')?></label>
<input type="text" class="form-control" id="taskname" name="taskname" value="<?=$task->taskname ?>"> <input type="text" class="form-control" id="taskname" name="taskname" value="<?=h($task->taskname)?>">
</div> </div>
<?php <?php
$opt_none = [-1 => '&horbar; none &horbar;']; $opt_none = [-1 => '&horbar; none &horbar;'];
+1 -1
View File
@@ -2644,7 +2644,7 @@ thread in "Segeln Forum"
<object class="GtkLabel"> <object class="GtkLabel">
<property name="visible">True</property> <property name="visible">True</property>
<property name="can-focus">False</property> <property name="can-focus">False</property>
<property name="label" translatable="yes">YMS-GUI version 0.2.0</property> <property name="label" translatable="yes">YMS-GUI version 0.2.1</property>
</object> </object>
<packing> <packing>
<property name="expand">False</property> <property name="expand">False</property>
+4 -3
View File
@@ -273,9 +273,10 @@ if __name__ == "__main__":
db.disconnect() db.disconnect()
else: else:
errno, errtxt = db.last_error() errno, errtxt = db.last_error()
messagebox(_("Database connection cannot be established.\n\n" gtkutils.messagebox(
_("Database connection cannot be established.\n\n"
"Server: %s\nDatabase: %s\n" "Server: %s\nDatabase: %s\n"
"Error: %s (%d)" "Error: %s (%d)") % (cfg['host'], cfg['db'], errtxt, errno),
) % (cfg['host'], cfg['db'], errtxt, errno), title="YMS") title="YMS")
# Another fine product of the sirius cybernetics corporation # Another fine product of the sirius cybernetics corporation