Improve database schema and install components
This commit is contained in:
+14
-9
@@ -783,7 +783,7 @@ function db_get_options($ddid, $orderby = '', $short = False, $default = NULL) {
|
||||
$sth = $pdo->prepare($sql);
|
||||
$sth->execute([$ddid]);
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
|
||||
$list[$rec[0]] = $rec[1];
|
||||
$list[$rec[0]] = h($rec[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -793,7 +793,7 @@ function db_get_opt_vessel() {
|
||||
$list = array();
|
||||
$sth = $pdo->query("SELECT vid, vesselname, model FROM vessel ORDER BY vid");
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
|
||||
$list[$rec[0]] = $rec[1];
|
||||
$list[$row[0]] = h($row[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -811,7 +811,7 @@ function db_get_opt_storage($vid) {
|
||||
$g_error->Add($e->getMessage());
|
||||
}
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
|
||||
$list[$rec[0]] = $rec[1];
|
||||
$list[$rec[0]] = h($rec[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -832,7 +832,7 @@ function db_get_opt_box($vid, $exclude=[]) {
|
||||
}
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
|
||||
if (! in_array($rec[0], $exclude)) {
|
||||
$list[$rec[0]] = $rec[1] . ($rec[2] ? ' - '. $rec[2] : '');
|
||||
$list[$rec[0]] = h($rec[1]) . ($rec[2] ? ' - '. h($rec[2]) : '');
|
||||
}
|
||||
}
|
||||
return $list;
|
||||
@@ -855,7 +855,7 @@ function db_get_opt_equip($vid, $default=NULL, $exclude=[]) {
|
||||
}
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
|
||||
if (! in_array($rec[0], $exclude)) {
|
||||
$list[$rec[0]] = $rec[1];
|
||||
$list[$rec[0]] = h($rec[1]);
|
||||
}
|
||||
}
|
||||
return $list;
|
||||
@@ -871,7 +871,7 @@ function db_get_opt_manuf($default=NULL) {
|
||||
$sql = "SELECT compid, compname FROM company WHERE comptype=2 ORDER BY compname";
|
||||
$sth = $pdo->query($sql);
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
|
||||
$list[$row[0]] = $row[1];
|
||||
$list[$row[0]] = h($row[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -886,7 +886,7 @@ function db_get_opt_supp($default=NULL) {
|
||||
$sql = "SELECT compid, compname FROM company WHERE comptype=1 ORDER BY compname";
|
||||
$sth = $pdo->query($sql);
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
|
||||
$list[$row[0]] = $row[1];
|
||||
$list[$row[0]] = h($row[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -901,7 +901,7 @@ function db_get_opt_user($userid, $default=NULL) {
|
||||
$sql = "SELECT userid, displayname FROM user WHERE userid>0 ORDER BY displayname";
|
||||
$sth = $pdo->query($sql);
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
|
||||
$list[$row[0]] = $row[1];
|
||||
$list[$row[0]] = h($row[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -931,7 +931,7 @@ function db_get_opt_proj($vid, $exclude=[], $default=NULL) {
|
||||
$g_error->Add($e->getMessage());
|
||||
}
|
||||
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
|
||||
$list[$rec[0]] = $rec[1];
|
||||
$list[$rec[0]] = h($rec[1]);
|
||||
}
|
||||
return $list;
|
||||
}
|
||||
@@ -1296,6 +1296,11 @@ function format_measurement($n, $unit, $v1, $v2, $v3) {
|
||||
|
||||
// ========== COMMON FUNCTIONS ================================================
|
||||
|
||||
function h($value) {
|
||||
// escape value coming from db for safe html output
|
||||
return htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
|
||||
}
|
||||
|
||||
function header_location($location, $message=NULL) {
|
||||
if (is_array($message)) {
|
||||
$valid_keys = array('succ', 'info', 'warn', 'err');
|
||||
|
||||
@@ -226,7 +226,7 @@ $opt_special = array(
|
||||
-2 => _('― all ―'),
|
||||
);
|
||||
foreach ($opt_special + $opt_invcond as $k => $v) {
|
||||
echo '<option value="', $k,'"';
|
||||
echo '<option value="', h($k), '"';
|
||||
if ($k == $flt->cond) {
|
||||
echo ' selected';
|
||||
}
|
||||
@@ -237,7 +237,7 @@ foreach ($opt_special + $opt_invcond as $k => $v) {
|
||||
</div>
|
||||
<div class="d-flex flex-nowrap gap-2">
|
||||
<label for="flt_txt">Text</label>
|
||||
<input type="text" class="form-control" name="flt_txt" size="15" maxlength="30" value="<?=$flt->txt ?>">
|
||||
<input type="text" class="form-control" name="flt_txt" size="15" maxlength="30" value="<?=h($flt->txt)?>">
|
||||
</div>
|
||||
</div>
|
||||
<div class="card-footer">
|
||||
|
||||
Reference in New Issue
Block a user