Sealing against XSS atacks: purchasing,sales,install,admin,taxes
[fa-stable.git] / sales / manage / sales_areas.php
1 <?php
2
3
4 $page_security = 3;
5 $path_to_root="../..";
6 include($path_to_root . "/includes/session.inc");
7
8 page(_("Sales Areas"));
9
10 include($path_to_root . "/includes/ui.inc");
11
12 if (isset($_GET['selected_id']))
13 {
14         $selected_id = strtoupper($_GET['selected_id']);
15
16 elseif (isset($_POST['selected_id']))
17 {
18         $selected_id = strtoupper($_POST['selected_id']);
19 }
20
21 if (isset($_POST['ADD_ITEM']) || isset($_POST['UPDATE_ITEM'])) 
22 {
23
24         $input_error = 0;
25
26         if (strlen($_POST['description']) == 0) 
27         {
28                 $input_error = 1;
29                 display_error(_("The area description cannot be empty."));
30         }
31
32         if ($input_error != 1)
33         {
34         if (isset($selected_id)) 
35         {
36                 $sql = "UPDATE ".TB_PREF."areas SET description=".db_escape($_POST['description'])." WHERE area_code = '$selected_id'";
37         } 
38         else 
39         {
40     
41                 $sql = "INSERT INTO ".TB_PREF."areas (description) VALUES (".db_escape($_POST['description']) . ")";
42         }
43     
44         db_query($sql,"The sales area could not be updated or added");
45         
46                 meta_forward($_SERVER['PHP_SELF']);                     
47         }
48
49
50 if (isset($_GET['delete'])) 
51 {
52
53         $cancel_delete = 0;
54
55         // PREVENT DELETES IF DEPENDENT RECORDS IN 'debtors_master'
56
57         $sql= "SELECT COUNT(*) FROM ".TB_PREF."cust_branch WHERE area='$selected_id'";
58         $result = db_query($sql,"check failed");
59         $myrow = db_fetch_row($result);
60         if ($myrow[0] > 0) 
61         {
62                 $cancel_delete = 1;
63                 display_error(_("Cannot delete this area because customer branches have been created using this area."));
64         } 
65         if ($cancel_delete == 0) 
66         {
67                 $sql="DELETE FROM ".TB_PREF."areas WHERE area_code='" . $selected_id . "'";
68                 db_query($sql,"could not delete sales area");
69
70                 meta_forward($_SERVER['PHP_SELF']);                     
71         } //end if Delete area
72
73
74 //-------------------------------------------------------------------------------------------------
75
76 $sql = "SELECT * FROM ".TB_PREF."areas";
77 $result = db_query($sql,"could not get areas");
78
79 start_table("$table_style width=40%");
80 $th = array(_("Area Name"), "", "");
81 table_header($th);
82 $k = 0; 
83
84 while ($myrow = db_fetch($result)) 
85 {
86         
87         alt_table_row_color($k);
88                 
89         label_cell($myrow["description"]);
90         edit_link_cell("selected_id=" . $myrow["area_code"]);
91         delete_link_cell("selected_id=" . $myrow["area_code"]. "&delete=1");
92         end_row();
93 }
94
95
96 end_table();
97 hyperlink_no_params($_SERVER['PHP_SELF'], _("New Sales Area"));
98
99 //-------------------------------------------------------------------------------------------------
100
101 start_form();
102
103 start_table("$table_style2 width=40%");
104
105 if (isset($selected_id)) 
106 {
107         //editing an existing area
108         $sql = "SELECT * FROM ".TB_PREF."areas WHERE area_code='$selected_id'";
109
110         $result = db_query($sql,"could not get area");
111         $myrow = db_fetch($result);
112
113         $_POST['description']  = $myrow["description"];
114         hidden("selected_id", $selected_id);
115
116
117 text_row_ex(_("Area Name:"), 'description', 30); 
118
119 end_table(1);
120
121 submit_add_or_update_center(!isset($selected_id));
122
123 end_form();
124
125 end_page();
126 ?>