Additional security fixes in sql statements.
[fa-stable.git] / gl / manage / gl_accounts.php
1 <?php
2 /**********************************************************************
3     Copyright (C) FrontAccounting, LLC.
4         Released under the terms of the GNU General Public License, GPL, 
5         as published by the Free Software Foundation, either version 3 
6         of the License, or (at your option) any later version.
7     This program is distributed in the hope that it will be useful,
8     but WITHOUT ANY WARRANTY; without even the implied warranty of
9     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
10     See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
11 ***********************************************************************/
12 $page_security = 'SA_GLACCOUNT';
13 $path_to_root = "../..";
14 include($path_to_root . "/includes/session.inc");
15
16 page(_("Chart of Accounts"));
17
18 include($path_to_root . "/includes/ui.inc");
19 include($path_to_root . "/gl/includes/gl_db.inc");
20 include($path_to_root . "/admin/db/tags_db.inc");
21 include_once($path_to_root . "/includes/data_checks.inc");
22
23 check_db_has_gl_account_groups(_("There are no account groups defined. Please define at least one account group before entering accounts."));
24
25 //-------------------------------------------------------------------------------------
26
27 if (isset($_POST['_AccountList_update'])) 
28 {
29         $_POST['selected_account'] = $_POST['AccountList'];
30         unset($_POST['account_code']);
31 }
32
33 if (isset($_POST['selected_account']))
34 {
35         $selected_account = $_POST['selected_account'];
36
37 elseif (isset($_GET['selected_account']))
38 {
39         $selected_account = $_GET['selected_account'];
40 }
41 else
42         $selected_account = "";
43 //-------------------------------------------------------------------------------------
44
45 if (isset($_POST['add']) || isset($_POST['update'])) 
46 {
47
48         $input_error = 0;
49
50         if (strlen($_POST['account_code']) == 0) 
51         {
52                 $input_error = 1;
53                 display_error( _("The account code must be entered."));
54                 set_focus('account_code');
55         } 
56         elseif (strlen($_POST['account_name']) == 0) 
57         {
58                 $input_error = 1;
59                 display_error( _("The account name cannot be empty."));
60                 set_focus('account_name');
61         } 
62         elseif (!$accounts_alpha && !is_numeric($_POST['account_code'])) 
63         {
64             $input_error = 1;
65             display_error( _("The account code must be numeric."));
66                 set_focus('account_code');
67         }
68
69         if ($input_error != 1)
70         {
71                 if ($accounts_alpha == 2)
72                         $_POST['account_code'] = strtoupper($_POST['account_code']);
73
74                 if (!isset($_POST['account_tags']))
75                         $_POST['account_tags'] = array();
76
77         if ($selected_account) 
78                 {
79                 if (update_gl_account($_POST['account_code'], $_POST['account_name'], 
80                                 $_POST['account_type'], $_POST['account_code2'])) {
81                                 update_record_status($_POST['account_code'], $_POST['inactive'],
82                                         'chart_master', 'account_code');
83                                 update_tag_associations(TAG_ACCOUNT, $_POST['account_code'], 
84                                         $_POST['account_tags']);
85                                 $Ajax->activate('account_code'); // in case of status change
86                                 display_notification(_("Account data has been updated."));
87                         }
88                 }
89         else 
90                 {
91                 if (add_gl_account($_POST['account_code'], $_POST['account_name'], 
92                                 $_POST['account_type'], $_POST['account_code2']))
93                                 {
94                                         add_tag_associations($_POST['account_code'], $_POST['account_tags']);
95                                         display_notification(_("New account has been added."));
96                                         $selected_account = $_POST['AccountList'] = $_POST['account_code'];
97                                 }
98                 }
99                 $Ajax->activate('_page_body');
100         }
101
102
103 //-------------------------------------------------------------------------------------
104
105 function can_delete($selected_account)
106 {
107         if ($selected_account == "")
108                 return false;
109         $acc = db_escape($selected_account);
110
111         $sql= "SELECT COUNT(*) FROM ".TB_PREF."gl_trans WHERE account=$acc";
112         $result = db_query($sql,"Couldn't test for existing transactions");
113
114         $myrow = db_fetch_row($result);
115         if ($myrow[0] > 0) 
116         {
117                 display_error(_("Cannot delete this account because transactions have been created using this account."));
118                 return false;
119         }
120
121         $sql= "SELECT COUNT(*) FROM ".TB_PREF."company WHERE debtors_act=$acc 
122                 OR pyt_discount_act=$acc
123                 OR creditors_act=$acc 
124                 OR freight_act=$acc
125                 OR default_sales_act=$acc 
126                 OR default_sales_discount_act=$acc
127                 OR default_prompt_payment_act=$acc
128                 OR default_inventory_act=$acc
129                 OR default_cogs_act=$acc
130                 OR default_adj_act=$acc
131                 OR default_inv_sales_act=$acc
132                 OR default_assembly_act=$acc";
133         $result = db_query($sql,"Couldn't test for default company GL codes");
134
135         $myrow = db_fetch_row($result);
136         if ($myrow[0] > 0) 
137         {
138                 display_error(_("Cannot delete this account because it is used as one of the company default GL accounts."));
139                 return false;
140         }
141         
142         $sql= "SELECT COUNT(*) FROM ".TB_PREF."bank_accounts WHERE account_code=$acc";
143         $result = db_query($sql,"Couldn't test for bank accounts");
144
145         $myrow = db_fetch_row($result);
146         if ($myrow[0] > 0) 
147         {
148                 display_error(_("Cannot delete this account because it is used by a bank account."));
149                 return false;
150         }       
151
152         $sql= "SELECT COUNT(*) FROM ".TB_PREF."stock_master WHERE 
153                 inventory_account=$acc 
154                 OR cogs_account=$acc
155                 OR adjustment_account=$acc 
156                 OR sales_account=$acc";
157         $result = db_query($sql,"Couldn't test for existing stock GL codes");
158
159         $myrow = db_fetch_row($result);
160         if ($myrow[0] > 0) 
161         {
162                 display_error(_("Cannot delete this account because it is used by one or more Items."));
163                 return false;
164         }       
165         
166         $sql= "SELECT COUNT(*) FROM ".TB_PREF."tax_types WHERE sales_gl_code=$acc OR purchasing_gl_code=$acc";
167         $result = db_query($sql,"Couldn't test for existing tax GL codes");
168
169         $myrow = db_fetch_row($result);
170         if ($myrow[0] > 0) 
171         {
172                 display_error(_("Cannot delete this account because it is used by one or more Taxes."));
173                 return false;
174         }       
175         
176         $sql= "SELECT COUNT(*) FROM ".TB_PREF."cust_branch WHERE 
177                 sales_account=$acc 
178                 OR sales_discount_account=$acc
179                 OR receivables_account=$acc
180                 OR payment_discount_account=$acc";
181         $result = db_query($sql,"Couldn't test for existing cust branch GL codes");
182
183         $myrow = db_fetch_row($result);
184         if ($myrow[0] > 0) 
185         {
186                 display_error(_("Cannot delete this account because it is used by one or more Customer Branches."));
187                 return false;
188         }               
189         
190         $sql= "SELECT COUNT(*) FROM ".TB_PREF."suppliers WHERE 
191                 purchase_account=$acc
192                 OR payment_discount_account=$acc
193                 OR payable_account=$acc";
194         $result = db_query($sql,"Couldn't test for existing suppliers GL codes");
195
196         $myrow = db_fetch_row($result);
197         if ($myrow[0] > 0) 
198         {
199                 display_error(_("Cannot delete this account because it is used by one or more suppliers."));
200                 return false;
201         }                                                                       
202         
203         $sql= "SELECT COUNT(*) FROM ".TB_PREF."quick_entry_lines WHERE 
204                 dest_id=$acc AND UPPER(LEFT(action, 1)) <> 'T'";
205         $result = db_query($sql,"Couldn't test for existing suppliers GL codes");
206
207         $myrow = db_fetch_row($result);
208         if ($myrow[0] > 0) 
209         {
210                 display_error(_("Cannot delete this account because it is used by one or more Quick Entry Lines."));
211                 return false;
212         }                                                                       
213
214         return true;
215 }
216
217 //--------------------------------------------------------------------------------------
218
219 if (isset($_POST['delete'])) 
220 {
221
222         if (can_delete($selected_account))
223         {
224                 delete_gl_account($selected_account);
225                 $selected_account = $_POST['AccountList'] = '';
226                 delete_tag_associations(TAG_ACCOUNT,$selected_account, true);
227                 $selected_account = $_POST['AccountList'] = '';
228                 display_notification(_("Selected account has been deleted"));
229                 unset($_POST['account_code']);
230                 $Ajax->activate('_page_body');
231         }
232
233
234 //-------------------------------------------------------------------------------------
235
236 start_form();
237
238 if (db_has_gl_accounts()) 
239 {
240         start_table("class = 'tablestyle_noborder'");
241         start_row();
242     gl_all_accounts_list_cells(null, 'AccountList', null, false, false,
243                 _('New account'), true, check_value('show_inactive'));
244         check_cells(_("Show inactive:"), 'show_inactive', null, true);
245         end_row();
246         end_table();
247         if (get_post('_show_inactive_update')) {
248                 $Ajax->activate('AccountList');
249                 set_focus('AccountList');
250         }
251 }
252         
253 br(1);
254 start_table($table_style2);
255
256 if ($selected_account != "") 
257 {
258         //editing an existing account
259         $myrow = get_gl_account($selected_account);
260
261         $_POST['account_code'] = $myrow["account_code"];
262         $_POST['account_code2'] = $myrow["account_code2"];
263         $_POST['account_name']  = $myrow["account_name"];
264         $_POST['account_type'] = $myrow["account_type"];
265         $_POST['inactive'] = $myrow["inactive"];
266         
267         $tags_result = get_tags_associated_with_record(TAG_ACCOUNT, $selected_account);
268         $tagids = array();
269         while ($tag = db_fetch($tags_result)) 
270                 $tagids[] = $tag['id'];
271         $_POST['account_tags'] = $tagids;
272
273         hidden('account_code', $_POST['account_code']);
274         hidden('selected_account', $selected_account);
275                 
276         label_row(_("Account Code:"), $_POST['account_code']);
277
278 else
279 {
280         if (!isset($_POST['account_code'])) {
281                 $_POST['account_tags'] = array();
282                 $_POST['account_code'] = $_POST['account_code2'] = '';
283                 $_POST['account_name']  = $_POST['account_type'] = '';
284                 $_POST['inactive'] = 0;
285         }
286         text_row_ex(_("Account Code:"), 'account_code', 11);
287 }
288
289 text_row_ex(_("Account Code 2:"), 'account_code2', 11);
290
291 text_row_ex(_("Account Name:"), 'account_name', 60);
292
293 gl_account_types_list_row(_("Account Group:"), 'account_type', null);
294
295 tag_list_row(_("Account Tags:"), 'account_tags', 5, TAG_ACCOUNT, true);
296
297 record_status_list_row(_("Account status:"), 'inactive');
298 end_table(1);
299
300 if ($selected_account == "") 
301 {
302         submit_center('add', _("Add Account"), true, '', false);
303
304 else 
305 {
306     submit_center_first('update', _("Update Account"), '', false);
307     submit_center_last('delete', _("Delete account"), '',true);
308 }
309 end_form();
310
311 end_page();
312
313 ?>