Improve database schema and install components

This commit is contained in:
2026-08-19 14:15:20 +02:00
parent 2476d1091a
commit ed2d1c1e84
6 changed files with 244 additions and 55 deletions
+14 -9
View File
@@ -783,7 +783,7 @@ function db_get_options($ddid, $orderby = '', $short = False, $default = NULL) {
$sth = $pdo->prepare($sql);
$sth->execute([$ddid]);
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
$list[$rec[0]] = $rec[1];
$list[$rec[0]] = h($rec[1]);
}
return $list;
}
@@ -793,7 +793,7 @@ function db_get_opt_vessel() {
$list = array();
$sth = $pdo->query("SELECT vid, vesselname, model FROM vessel ORDER BY vid");
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
$list[$rec[0]] = $rec[1];
$list[$row[0]] = h($row[1]);
}
return $list;
}
@@ -811,7 +811,7 @@ function db_get_opt_storage($vid) {
$g_error->Add($e->getMessage());
}
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
$list[$rec[0]] = $rec[1];
$list[$rec[0]] = h($rec[1]);
}
return $list;
}
@@ -832,7 +832,7 @@ function db_get_opt_box($vid, $exclude=[]) {
}
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
if (! in_array($rec[0], $exclude)) {
$list[$rec[0]] = $rec[1] . ($rec[2] ? ' - '. $rec[2] : '');
$list[$rec[0]] = h($rec[1]) . ($rec[2] ? ' - '. h($rec[2]) : '');
}
}
return $list;
@@ -855,7 +855,7 @@ function db_get_opt_equip($vid, $default=NULL, $exclude=[]) {
}
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
if (! in_array($rec[0], $exclude)) {
$list[$rec[0]] = $rec[1];
$list[$rec[0]] = h($rec[1]);
}
}
return $list;
@@ -871,7 +871,7 @@ function db_get_opt_manuf($default=NULL) {
$sql = "SELECT compid, compname FROM company WHERE comptype=2 ORDER BY compname";
$sth = $pdo->query($sql);
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
$list[$row[0]] = $row[1];
$list[$row[0]] = h($row[1]);
}
return $list;
}
@@ -886,7 +886,7 @@ function db_get_opt_supp($default=NULL) {
$sql = "SELECT compid, compname FROM company WHERE comptype=1 ORDER BY compname";
$sth = $pdo->query($sql);
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
$list[$row[0]] = $row[1];
$list[$row[0]] = h($row[1]);
}
return $list;
}
@@ -901,7 +901,7 @@ function db_get_opt_user($userid, $default=NULL) {
$sql = "SELECT userid, displayname FROM user WHERE userid>0 ORDER BY displayname";
$sth = $pdo->query($sql);
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $row) {
$list[$row[0]] = $row[1];
$list[$row[0]] = h($row[1]);
}
return $list;
}
@@ -931,7 +931,7 @@ function db_get_opt_proj($vid, $exclude=[], $default=NULL) {
$g_error->Add($e->getMessage());
}
foreach ($sth->fetchAll(PDO::FETCH_NUM) as $rec) {
$list[$rec[0]] = $rec[1];
$list[$rec[0]] = h($rec[1]);
}
return $list;
}
@@ -1296,6 +1296,11 @@ function format_measurement($n, $unit, $v1, $v2, $v3) {
// ========== COMMON FUNCTIONS ================================================
function h($value) {
// escape value coming from db for safe html output
return htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
}
function header_location($location, $message=NULL) {
if (is_array($message)) {
$valid_keys = array('succ', 'info', 'warn', 'err');
+2 -2
View File
@@ -226,7 +226,7 @@ $opt_special = array(
-2 => _('― all ―'),
);
foreach ($opt_special + $opt_invcond as $k => $v) {
echo '<option value="', $k,'"';
echo '<option value="', h($k), '"';
if ($k == $flt->cond) {
echo ' selected';
}
@@ -237,7 +237,7 @@ foreach ($opt_special + $opt_invcond as $k => $v) {
</div>
<div class="d-flex flex-nowrap gap-2">
<label for="flt_txt">Text</label>
<input type="text" class="form-control" name="flt_txt" size="15" maxlength="30" value="<?=$flt->txt ?>">
<input type="text" class="form-control" name="flt_txt" size="15" maxlength="30" value="<?=h($flt->txt)?>">
</div>
</div>
<div class="card-footer">