}
return $ret;
} else
- return is_float($dflt) ? input_num($name, $dflt) :
- ((!isset($_POST[$name]) || $_POST[$name] === '') ? $dflt : $_POST[$name]);
+ return is_float($dflt) ? input_num($name, $dflt) :
+ ((!isset($_POST[$name]) /*|| $_POST[$name] === ''*/) ? $dflt : $_POST[$name]);
}
//---------------------------------------------------------------------------------
+$form_nested = -1;
function start_form($multi=false, $dummy=false, $action="", $name="")
{
// $dummy - leaved for compatibility with 2.0 API
+ global $form_nested;
+
+ if (++$form_nested) return;
if ($name != "")
$name = "name='$name'";
}
+/*
+ Flush hidden fields buffer.
+*/
+function output_hidden()
+{
+ global $hidden_fields;
+
+ if (is_array($hidden_fields))
+ echo implode('', $hidden_fields);
+ $hidden_fields = array();
+}
//---------------------------------------------------------------------------------
function end_form($breaks=0)
{
+ global $Ajax, $form_nested, $hidden_fields;
+
+ if ($form_nested-- > 0) return;
+
+ $_SESSION['csrf_token'] = random_id();
if ($breaks)
br($breaks);
- echo "<input type=\"hidden\" name=\"_focus\" value=\"".get_post('_focus')."\">\n";
+ hidden('_focus');
+ hidden('_modified', get_post('_modified', 0));
+ hidden('_confirmed'); // helper for final form confirmation
+ hidden('_token', $_SESSION['csrf_token']);
+
+ output_hidden();
echo "</form>\n";
+ $Ajax->activate('_token');
+ $Ajax->activate('_confirmed');
+}
+
+function check_csrf_token()
+{
+ if ($_SESSION['csrf_token'] != @$_POST['_token'])
+ {
+ display_error(_("Request from outside of this page is forbidden."));
+ error_log(_("CSRF attack detected from: ").@$_SERVER['HTTP_HOST'].' ('.@$_SERVER['HTTP_REFERER'].')');
+ return false;
+ }
+ return true;
}
function start_table($class=false, $extra="", $padding='2', $spacing='0')
echo " class='tablestyle'";
if ($extra != "")
echo " $extra";
- echo " cellpadding=$padding cellspacing=$spacing>\n";
+ echo " cellpadding='$padding' cellspacing='$spacing'>\n";
}
function end_table($breaks=0)
{
echo "</table></center>\n";
+ output_hidden();
if ($breaks)
br($breaks);
}
if ($number > 1)
{
echo "</table>\n";
- $width = ($width ? "width=$width" : "");
- //echo "</td><td class='tableseparator' $width>\n"; // outer table
+ output_hidden();
+ $width = ($width ? "width='$width'" : "");
echo "</td><td style='border-left:1px solid #cccccc;' $width>\n"; // outer table
}
echo "<table class='tablestyle_inner'>\n";
function end_outer_table($breaks=0, $close_table=true)
{
if ($close_table)
+ {
echo "</table>\n";
+ output_hidden();
+ }
echo "</td></tr>\n";
end_table($breaks);
}
echo "</td></tr><tr><td valign=center $params>";
}
-function meta_forward($forward_to, $params="")
+function meta_forward($forward_to, $params="", $timeout=0, $return=false)
{
global $Ajax;
- echo "<meta http-equiv='Refresh' content='0; url=$forward_to?$params'>\n";
+ echo "<meta http-equiv='Refresh' content='".$timeout."; url=$forward_to?$params'>\n";
echo "<center><br>" . _("You should automatically be forwarded.");
echo " " . _("If this does not happen") . " " . "<a href='$forward_to?$params'>" . _("click here") . "</a> " . _("to continue") . ".<br><br></center>\n";
if ($params !='') $params = '?'.$params;
$Ajax->redirect($forward_to.$params);
- exit;
+ if (!$return) exit;
}
//-----------------------------------------------------------------------------------
return $clean ? $label : array($label, $access);
}
-function hyperlink_back($center=true, $no_menu=true, $type_no=0, $trans_no=0)
+function hyperlink_back($center=true, $no_menu=true, $type_no=0, $trans_no=0, $final=false)
{
+ global $path_to_root;
+
if ($center)
echo "<center>";
- start_table(false, "width=30%");
+ $id = 0;
+ if ($no_menu && $trans_no != 0)
+ {
+ include_once($path_to_root."/admin/db/attachments_db.inc");
+ $id = has_attachment($type_no, $trans_no);
+ $attach = get_attachment_string($type_no, $trans_no);
+ echo $attach;
+ }
+ $width = ($id != 0 ? "30%" : "20%");
+ start_table(false, "width='$width'");
start_row();
if ($no_menu)
{
- if ($type_no != 0 && $trans_no != 0)
- {
- global $path_to_root;
- include_once($path_to_root."/admin/db/attachments_db.inc");
- $id = has_attachment($type_no, $trans_no);
- if ($id != 0)
- echo "<td align=center><a href='$path_to_root/admin/attachments.php?vw=$id' target='blanc_'>"._("View Attachment")."</a></td>\n";
- }
echo "<td align=center><a href='javascript:window.print();'>"._("Print")."</a></td>\n";
}
- echo "<td align=center><a href='javascript:goBack();'>".($no_menu ? _("Close") : _("Back"))."</a></td>\n";
+ echo "<td align=center><a href='javascript:goBack(".($final ? '-2' : '').");'>".($no_menu ? _("Close") : _("Back"))."</a></td>\n";
end_row();
end_table();
if ($center)
}
else
$preview_str = $label;
-
return $preview_str;
}
function menu_link($url, $label, $id=null)
{
+ global $path_to_root;
$id = default_focus($id);
$pars = access_string($label);
+
+ if ($url[0] != '/')
+ $url = '/'.$url;
+ $url = $path_to_root.$url;
+
return "<a href='$url' class='menu_option' id='$id' $pars[1]>$pars[0]</a>";
}
function submenu_option($title, $url, $id=null)
{
- global $path_to_root;
- display_note(menu_link($path_to_root . $url, $title, $id), 0, 1);
+ display_note( menu_link($url, $title, $id), 0, 1);
}
function submenu_view($title, $type, $number, $id=null)
{
- display_note(get_trans_view_str($type, $number, $title, false, 'menu_option', $id), 0, 1);
+ display_note(get_trans_view_str($type, $number, $title, false, 'viewlink', $id), 0, 1);
}
function submenu_print($title, $type, $number, $id=null, $email=0, $extra=0)
{
- display_note(print_document_link($number, $title, true, $type, false, 'menu_option', $id, $email, $extra), 0, 1);
+ display_note(print_document_link($number, $title, true, $type, false, 'printlink', $id, $email, $extra), 0, 1);
}
//-----------------------------------------------------------------------------------
//--------------------------------------------------------------------------------------------------
-function alt_table_row_color(&$k)
+function alt_table_row_color(&$k, $extra_class=null)
{
+ $classes = $extra_class ? array($extra_class) : array();
if ($k == 1)
{
- echo "<tr class='oddrow'>\n";
+ array_push($classes, 'oddrow');
$k = 0;
}
else
{
- echo "<tr class='evenrow'>\n";
+ array_push($classes, 'evenrow');
$k++;
}
+ echo "<tr class='".implode(' ', $classes)."'>\n";
}
function table_section_title($msg, $colspan=2)
{
global $ajax_divs, $Ajax;
+ output_hidden();
if (count($ajax_divs))
{
$div = array_pop($ajax_divs);
if ($div[1] !== null)
$Ajax->addUpdate($div[1], $div[0], ob_get_flush());
- echo "</div>";
}
+ echo "</div>";
+}
+
+//-----------------------------------------------------------------------------
+// Tabbed area:
+// $name - prefix for widget internal elements:
+// Nth tab submit name: {$name}_N
+// div id: _{$name}_div
+// sel (hidden) name: _{$name}_sel
+// $tabs - array of tabs; string: tab title or array(tab_title, enabled_status)
+
+function tabbed_content_start($name, $tabs, $dft='') {
+ global $Ajax;
+
+ $selname = '_'.$name.'_sel';
+ $div = '_'.$name.'_div';
+
+ $sel = find_submit($name.'_', false);
+ if($sel==null)
+ $sel = get_post($selname, (string)($dft==='' ? key($tabs) : $dft));
+
+ if ($sel!==@$_POST[$selname])
+ $Ajax->activate($name);
+
+ $_POST[$selname] = $sel;
+
+ div_start($name);
+ $str = "<ul class='ajaxtabs' rel='$div'>\n";
+ foreach($tabs as $tab_no => $tab) {
+
+ $acc = access_string(is_array($tab) ? $tab[0] : $tab);
+ $disabled = (is_array($tab) && !$tab[1]) ? 'disabled ' : '';
+ $str .= ( "<li>"
+ ."<button type='submit' name='{$name}_".$tab_no
+ ."' class='".((string)$tab_no===$sel ? 'current':'ajaxbutton')."' $acc[1] $disabled>"
+ ."<span>$acc[0]</span>"
+ ."</button>\n"
+ ."</li>\n" );
+ }
+
+ $str .= "</ul>\n";
+ $str .= "<div class='spaceBox'></div>\n";
+ $str .= "<input type='hidden' name='$selname' value='$sel'>\n";
+ $str .= "<div class='contentBox' id='$div'>\n";
+ echo $str;
+}
+
+function tabbed_content_end() {
+ output_hidden();
+ echo "</div>"; // content box (don't change to div_end() unless div_start() is used above)
+ div_end(); // tabs widget
+}
+
+function tab_changed($name)
+{
+ $to = find_submit("{$name}_", false);
+ if (!$to) return null;
+
+ return array('from' => $from = get_post("_{$name}_sel"),
+ 'to' => $to);
+}
+/*
+ Check whether tab has been just switched on
+*/
+function tab_opened($name, $tab)
+{
+ return (get_post('_'.$name.'_sel') != $tab) && (find_submit($name.'_', false) == $tab);
+}
+/*
+ Check whether tab has been just switched off
+*/
+function tab_closed($name, $tab)
+{
+ return (get_post('_'.$name.'_sel') == $tab) && (find_submit($name.'_', false) != $tab);
+}
+/*
+ Check whether tab is visible on current page
+*/
+function tab_visible($name, $tab)
+{
+ $new = find_submit($name.'_', false);
+ return (get_post('_'.$name.'_sel') == $tab && !$new) || $new==$tab;
}
/* Table editor interfaces. Key is editor type
*/
$popup_editors = array(
'customer' => array('/sales/manage/customers.php?debtor_no=',
- 113, _("Customers")),
+ 113, _("Customers"), 900, 600),
'branch' => array('/sales/manage/customer_branches.php?SelectedBranch=',
- 114, _("Branches")),
+ 114, _("Branches"), 900, 700),
'supplier' => array('/purchasing/manage/suppliers.php?supplier_id=',
- 113, _("Suppliers")),
+ 113, _("Suppliers"), 900, 700),
'item' => array('/inventory/manage/items.php?stock_id=',
- 115, _("Items"))
+ 115, _("Items"), 800, 600),
+ 'fa_item' => array('/inventory/manage/items.php?FixedAsset=1&stock_id=',
+ 115, _("Items"), 800, 600)
);
/*
Bind editors for various selectors.
$key = $caller===true ? $popup_editors[$type][1] : $caller;
- $Editors[$key] = array( $path_to_root . $popup_editors[$type][0], $input);
+ $Editors[$key] = array( $path_to_root . $popup_editors[$type][0], $input,
+ $popup_editors[$type][3], $popup_editors[$type][4]);
$help = 'F' . ($key - 111) . ' - ';
$help .= $popup_editors[$type][2];
return 0;
} else
return get_post('DialogConfirm', 0);
-}
+}
+/*
+ Confirm dialog to be used optionally in final form checking routine.
+ Displays warning conditionally unless it was displayed
+*/
+function display_confirmation($msg)
+{
+ global $Ajax;
+
+ if (!get_post('_confirmed'))
+ {
+ $_POST['_confirmed'] = 1;
+ display_warning($msg);
+ return false;
+ } else
+ return true;
+}
+/*
+ Block menu/shortcut links during transaction procesing.
+*/
+function page_processing($msg = false)
+{
+ global $Ajax;
+
+ if ($msg === true)
+ $msg = _("Entered data has not been saved yet.\nDo you want to abandon changes?");
+
+ $js = "_validate._processing=" . (
+ $msg ? '\''.strtr($msg, array("\n"=>'\\n')) . '\';' : 'null;');
+ if (in_ajax()) {
+ $Ajax->addScript(true, $js);
+ } else
+ add_js_source($js);
+}
-?>
\ No newline at end of file
+function page_modified($status = true)
+{
+ global $Ajax;
+
+ $js = "_validate._modified=" . ($status ? 1:0).';';
+ if (in_ajax()) {
+ $Ajax->addScript(true, $js);
+ } else
+ add_js_source($js);
+}