Security update merged from 2.1.
[fa-stable.git] / inventory / manage / items.php
index 967cb5e67ec56c400d1e09274d835818c7b05b9e..9356e0b11fcc729fb06bed9e1a864f58861b95f7 100644 (file)
@@ -1,10 +1,19 @@
 <?php
-
-$page_security = 11;
-$path_to_root="../..";
+/**********************************************************************
+    Copyright (C) FrontAccounting, LLC.
+       Released under the terms of the GNU General Public License, GPL, 
+       as published by the Free Software Foundation, either version 3 
+       of the License, or (at your option) any later version.
+    This program is distributed in the hope that it will be useful,
+    but WITHOUT ANY WARRANTY; without even the implied warranty of
+    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
+    See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
+***********************************************************************/
+$page_security = 'SA_ITEM';
+$path_to_root = "../..";
 include($path_to_root . "/includes/session.inc");
 
-page(_("Items"));
+page(_("Items"), @$_REQUEST['popup']);
 
 include_once($path_to_root . "/includes/date_functions.inc");
 include_once($path_to_root . "/includes/ui.inc");
@@ -13,30 +22,38 @@ include_once($path_to_root . "/includes/data_checks.inc");
 include_once($path_to_root . "/inventory/includes/inventory_db.inc");
 
 $user_comp = user_company();
+$new_item = get_post('stock_id')=='' || get_post('cancel') || get_post('clone'); 
 //------------------------------------------------------------------------------------
 
 if (isset($_GET['stock_id']))
 {
-       $stock_id = strtoupper($_GET['stock_id']);
+       $_POST['stock_id'] = $stock_id = $_GET['stock_id'];
 }
-else if (isset($_POST['stock_id']))
+elseif (isset($_POST['stock_id']))
 {
-       $stock_id = strtoupper($_POST['stock_id']);
+       $stock_id = $_POST['stock_id'];
+}
+if (list_updated('stock_id')) {
+       $_POST['NewStockID'] = get_post('stock_id');
+    clear_data();
+       $Ajax->activate('details');
+       $Ajax->activate('controls');
 }
 
-if (isset($_GET['New']) || !isset($_POST['NewStockID'])) 
-{
-       $_POST['New'] = "1";
+if (get_post('cancel')) {
+       $_POST['NewStockID'] = $_POST['stock_id'] = '';
+    clear_data();
+       set_focus('stock_id');
+       $Ajax->activate('_page_body');
 }
 
-if (isset($_POST['SelectStockItem'])) 
-{
-       $_POST['NewStockID'] = $_POST['stock_id'];
-       unset($_POST['New']);
+if (list_updated('category_id') || list_updated('mb_flag')) {
+       $Ajax->activate('details');
 }
 $upload_file = "";
 if (isset($_FILES['pic']) && $_FILES['pic']['name'] != '') 
 {
+       $stock_id = $_POST['NewStockID'];
        $result = $_FILES['pic']['error'];
        $upload_file = 'Yes'; //Assume all is well to start off with
        $filename = $comp_path . "/$user_comp/images";
@@ -44,27 +61,26 @@ if (isset($_FILES['pic']) && $_FILES['pic']['name'] != '')
        {
                mkdir($filename);
        }       
-       $filename .= "/$stock_id.jpg";
+       $filename .= "/".item_img_name($stock_id).".jpg";
        
         //But check for the worst 
        if (strtoupper(substr(trim($_FILES['pic']['name']), strlen($_FILES['pic']['name']) - 3)) != 'JPG')
        {
-               display_notification(_('Only jpg files are supported - a file extension of .jpg is expected'));
+               display_warning(_('Only jpg files are supported - a file extension of .jpg is expected'));
                $upload_file ='No';
        } 
        elseif ( $_FILES['pic']['size'] > ($max_image_size * 1024)) 
        { //File Size Check
-               display_notification(_('The file size is over the maximum allowed. The maximum size allowed in KB is') . ' ' . $max_image_size);
+               display_warning(_('The file size is over the maximum allowed. The maximum size allowed in KB is') . ' ' . $max_image_size);
                $upload_file ='No';
        } 
        elseif ( $_FILES['pic']['type'] == "text/plain" ) 
        {  //File type Check
-               display_notification( _('Only graphics files can be uploaded'));
+               display_warning( _('Only graphics files can be uploaded'));
                $upload_file ='No';
        } 
        elseif (file_exists($filename))
        {
-               display_notification(_('Attempting to overwrite an existing item image'));
                $result = unlink($filename);
                if (!$result) 
                {
@@ -76,12 +92,11 @@ if (isset($_FILES['pic']) && $_FILES['pic']['name'] != '')
        if ($upload_file == 'Yes')
        {
                $result  =  move_uploaded_file($_FILES['pic']['tmp_name'], $filename);
-               $message = ($result)?_('File url') ."<a href='$filename'>$filename</a>" : "Somthing is wrong with uploading a file.";
        }
+       $Ajax->activate('details');
  /* EOF Add Image upload for New Item  - by Ori */
 }
 
-
 check_db_has_stock_categories(_("There are no item categories defined in the system. At least one item category is required to add a item."));
 
 check_db_has_item_tax_types(_("There are no item tax types defined in the system. At least one item tax type is required to add a item."));
@@ -97,7 +112,7 @@ function clear_data()
        unset($_POST['NewStockID']);
        unset($_POST['dimension_id']);
        unset($_POST['dimension2_id']);
-       $_POST['New'] = "1";
+       unset($_POST['no_sale']);
 }
 
 //------------------------------------------------------------------------------------
@@ -129,19 +144,39 @@ if (isset($_POST['addupdate']))
                set_focus('NewStockID');
 
        }
-
+       elseif ($new_item && db_num_rows(get_item_kit($_POST['NewStockID'])))
+       {
+                       $input_error = 1;
+               display_error( _("This item code is already assigned to stock item or sale kit."));
+                       set_focus('NewStockID');
+       }
+       
        if ($input_error != 1)
        {
-
-               if (!isset($_POST['New'])) 
+               if (check_value('del_image'))
+               {
+                       $filename = $comp_path . "/$user_comp/images/".item_img_name($_POST['NewStockID']).".jpg";
+                       if (file_exists($filename))
+                               unlink($filename);
+               }
+               
+               if (!$new_item) 
                { /*so its an existing one */
-
                        update_item($_POST['NewStockID'], $_POST['description'],
-                               $_POST['long_description'], $_POST['category_id'], $_POST['tax_type_id'],
-                               $_POST['sales_account'], $_POST['inventory_account'], $_POST['cogs_account'],
+                               $_POST['long_description'], $_POST['category_id'], 
+                               $_POST['tax_type_id'], get_post('units'),
+                               get_post('mb_flag'), $_POST['sales_account'],
+                               $_POST['inventory_account'], $_POST['cogs_account'],
                                $_POST['adjustment_account'], $_POST['assembly_account'], 
-                               $_POST['dimension_id'], $_POST['dimension2_id']);
-
+                               $_POST['dimension_id'], $_POST['dimension2_id'],
+                               check_value('no_sale'));
+                       update_record_status($_POST['NewStockID'], $_POST['inactive'],
+                               'stock_master', 'stock_id');
+                       update_record_status($_POST['NewStockID'], $_POST['inactive'],
+                               'item_codes', 'item_code');
+                       set_focus('stock_id');
+                       $Ajax->activate('stock_id'); // in case of status change
+                       display_notification(_("Item has been updated."));
                } 
                else 
                { //it is a NEW part
@@ -151,52 +186,78 @@ if (isset($_POST['addupdate']))
                                $_POST['units'], $_POST['mb_flag'], $_POST['sales_account'],
                                $_POST['inventory_account'], $_POST['cogs_account'],
                                $_POST['adjustment_account'], $_POST['assembly_account'], 
-                               $_POST['dimension_id'], $_POST['dimension2_id']);
+                               $_POST['dimension_id'], $_POST['dimension2_id'],
+                               check_value('no_sale'));
+
+                       display_notification(_("A new item has been added."));
+                       $_POST['stock_id'] = $_POST['NewStockID'] = 
+                       $_POST['description'] = $_POST['long_description'] = '';
+                       $_POST['no_sale'] = 0;
+                       set_focus('NewStockID');
                }
-               meta_forward($_SERVER['PHP_SELF']);
+               $Ajax->activate('_page_body');
        }
 }
 
+if (get_post('clone')) {
+       unset($_POST['stock_id']);
+       unset($_POST['inactive']);
+       set_focus('NewStockID');
+       $Ajax->activate('_page_body');
+}
+
 //------------------------------------------------------------------------------------
 
-function can_delete($stock_id)
+function check_usage($stock_id, $dispmsg=true)
 {
-       $sql= "SELECT COUNT(*) FROM ".TB_PREF."stock_moves WHERE stock_id='$stock_id'";
-       $result = db_query($sql, "could not query stock moves");
-       $myrow = db_fetch_row($result);
-       if ($myrow[0] > 0) 
-       {
-               display_error(_('Cannot delete this item because there are stock movements that refer to this item.'));
-               return false;
+       $sqls=  array(
+       "SELECT COUNT(*) FROM "
+               .TB_PREF."stock_moves WHERE stock_id=".db_escape($stock_id) =>
+        _('Cannot delete this item because there are stock movements that refer to this item.'),
+       "SELECT COUNT(*) FROM "
+               .TB_PREF."bom WHERE component=".db_escape($stock_id)=>
+        _('Cannot delete this item record because there are bills of material that require this part as a component.'),
+       "SELECT COUNT(*) FROM "
+               .TB_PREF."sales_order_details WHERE stk_code=".db_escape($stock_id) =>
+        _('Cannot delete this item because there are existing purchase order items for it.'),
+       "SELECT COUNT(*) FROM "
+               .TB_PREF."purch_order_details WHERE item_code=".db_escape($stock_id)=>
+        _('Cannot delete this item because there are existing purchase order items for it.')
+       );
+
+       $msg = '';
+
+       foreach($sqls as $sql=>$err) {
+               $result = db_query($sql, "could not query stock usage");
+               $myrow = db_fetch_row($result);
+               if ($myrow[0] > 0) 
+               {
+                       $msg = $err; break;
+               }
        }
 
-       $sql= "SELECT COUNT(*) FROM ".TB_PREF."bom WHERE component='$stock_id'";
-       $result = db_query($sql, "could not query boms");
-       $myrow = db_fetch_row($result);
-       if ($myrow[0] > 0) 
-       {
-               display_error(_('Cannot delete this item record because there are bills of material that require this part as a component.'));
-               return false;
-       }
+       if ($msg == '') {       
 
-       $sql= "SELECT COUNT(*) FROM ".TB_PREF."sales_order_details WHERE stk_code='$stock_id'";
-       $result = db_query($sql, "could not query sales orders");
-       $myrow = db_fetch_row($result);
-       if ($myrow[0] > 0) 
-       {
-               display_error(_('Cannot delete this item record because there are existing sales orders for this part.'));
-               return false;
-       }
+               $kits = get_where_used($stock_id);
+               $num_kits = db_num_rows($kits);
+               if ($num_kits) {
+                       $msg = _("This item cannot be deleted because some code aliases 
+                               or foreign codes was entered for it, or there are kits defined 
+                               using this item as component")
+                               .':<br>';
 
-       $sql= "SELECT COUNT(*) FROM ".TB_PREF."purch_order_details WHERE item_code='$stock_id'";
-       $result = db_query($sql, "could not query purchase orders");
-       $myrow = db_fetch_row($result);
-       if ($myrow[0] > 0) 
-       {
-               display_error(_('Cannot delete this item because there are existing purchase order items for it.'));
+                       while($num_kits--) {
+                               $kit = db_fetch($kits);
+                               $msg .= "'".$kit[0]."'";
+                               if ($num_kits) $msg .= ',';
+                       }
+
+               }
+       }
+       if ($msg != '') {
+               if($dispmsg) display_error($msg);
                return false;
        }
-
        return true;
 }
 
@@ -205,18 +266,22 @@ function can_delete($stock_id)
 if (isset($_POST['delete']) && strlen($_POST['delete']) > 1) 
 {
 
-       if (can_delete($_POST['NewStockID'])) {
+       if (check_usage($_POST['NewStockID'])) {
 
                $stock_id = $_POST['NewStockID'];
                delete_item($stock_id);
-               $filename = $comp_path . "/$user_comp/images/$stock_id.jpg";
+               $filename = $comp_path . "/$user_comp/images/".item_img_name($stock_id).".jpg";
                if (file_exists($filename))
                        unlink($filename);
-               meta_forward($_SERVER['PHP_SELF']);
+               display_notification(_("Selected item has been deleted."));
+               $_POST['stock_id'] = '';
+               clear_data();
+               set_focus('stock_id');
+               $new_item = true;
+               $Ajax->activate('_page_body');
        }
 }
-
-//------------------------------------------------------------------------------------
+//-------------------------------------------------------------------------------------------- 
 
 start_form(true);
 
@@ -224,53 +289,37 @@ if (db_has_stock_items())
 {
        start_table("class='tablestyle_noborder'");
        start_row();
-    stock_items_list_cells(_("Select an item:"), 'stock_id', null);
-    submit_cells('SelectStockItem', _("Edit Item"));
+    stock_items_list_cells(_("Select an item:"), 'stock_id', null,
+         _('New item'), true, check_value('show_inactive'));
+       $new_item = get_post('stock_id')=='';
+       check_cells(_("Show inactive:"), 'show_inactive', null, true);
        end_row();
        end_table();
+
+       if (get_post('_show_inactive_update')) {
+               $Ajax->activate('stock_id');
+               set_focus('stock_id');
+       }
 }
 
-hyperlink_params($_SERVER['PHP_SELF'], _("Enter a new item"), "New=1");
-echo "<br>";
+div_start('details');
+start_outer_table($table_style2, 5);
 
-start_table("$table_style2 width=40%");
+table_section(1);
 
 table_section_title(_("Item"));
 
 //------------------------------------------------------------------------------------
-
-if (!isset($_POST['NewStockID']) || isset($_POST['New'])) 
+if ($new_item) 
 {
-
-/*If the page was called without $_POST['NewStockID'] passed to page then assume a new item is to be entered show a form with a part Code field other wise the form showing the fields with the existing entries against the part will show for editing with only a hidden stock_id field. New is set to flag that the page may have called itself and still be entering a new part, in which case the page needs to know not to go looking up details for an existing part*/
-
-       hidden('New', 'Yes');
-
        text_row(_("Item Code:"), 'NewStockID', null, 21, 20);
 
-       $company_record = get_company_prefs();
-
-    if (!isset($_POST['inventory_account']) || $_POST['inventory_account'] == "")
-       $_POST['inventory_account'] = $company_record["default_inventory_act"];
-
-    if (!isset($_POST['cogs_account']) || $_POST['cogs_account'] == "")
-       $_POST['cogs_account'] = $company_record["default_cogs_act"];
-
-       if (!isset($_POST['sales_account']) || $_POST['sales_account'] == "")
-               $_POST['sales_account'] = $company_record["default_inv_sales_act"];
-
-       if (!isset($_POST['adjustment_account']) || $_POST['adjustment_account'] == "")
-               $_POST['adjustment_account'] = $company_record["default_adj_act"];
-
-       if (!isset($_POST['assembly_account']) || $_POST['assembly_account'] == "")
-               $_POST['assembly_account'] = $company_record["default_assembly_act"];
-
+       $_POST['inactive'] = 0;
 } 
 else 
 { // Must be modifying an existing item
+               $_POST['NewStockID'] = $_POST['stock_id'];
 
-       if (!isset($_POST['New'])) 
-       {
                $myrow = get_item($_POST['NewStockID']);
 
                $_POST['long_description'] = $myrow["long_description"];
@@ -287,59 +336,74 @@ else
                $_POST['assembly_account']      = $myrow['assembly_account'];
                $_POST['dimension_id']  = $myrow['dimension_id'];
                $_POST['dimension2_id'] = $myrow['dimension2_id'];
-       
+               $_POST['no_sale']       = $myrow['no_sale'];
+               $_POST['del_image'] = 0;        
+               $_POST['inactive'] = $myrow["inactive"];
                label_row(_("Item Code:"),$_POST['NewStockID']);
                hidden('NewStockID', $_POST['NewStockID']);
-       }
+               set_focus('description');
 }
 
 text_row(_("Name:"), 'description', null, 52, 50);
 
-textarea_row(_('Description:'), 'long_description', null, 45, 3);
+textarea_row(_('Description:'), 'long_description', null, 42, 3);
 
-end_table();
-start_table("$table_style2 width=40%");
-// Add image upload for New Item  - by Joe
-start_row();
-label_cells(_("Image File (.jpg)") . ":", "<input type='file' id='pic' name='pic'>");
-// Add Image upload for New Item  - by Joe
-if (isset($_POST['NewStockID']) && file_exists("$comp_path/$user_comp/images/".$_POST['NewStockID'].".jpg")) 
-{
-       $stock_img_link = "<img src='$comp_path/$user_comp/images/".$_POST['NewStockID'].".jpg' width='$pic_width' height='$pic_height' border='0'>";
-} 
-else 
-{
-       $stock_img_link = "No Image";
-}
+stock_categories_list_row(_("Category:"), 'category_id', null, $new_item);
+
+if ($new_item && (list_updated('category_id') || !isset($_POST['units']))) {
 
-label_cell($stock_img_link, "valign=top align=center rowspan=5");
-end_row();
+       $category_record = get_item_category($_POST['category_id']);
 
-stock_categories_list_row(_("Category:"), 'category_id', null);
+       $_POST['tax_type_id'] = $category_record["dflt_tax_type"];
+       $_POST['units'] = $category_record["dflt_units"];
+       $_POST['mb_flag'] = $category_record["dflt_mb_flag"];
+       $_POST['inventory_account'] = $category_record["dflt_inventory_act"];
+       $_POST['cogs_account'] = $category_record["dflt_cogs_act"];
+       $_POST['sales_account'] = $category_record["dflt_sales_act"];
+       $_POST['adjustment_account'] = $category_record["dflt_adjustment_act"];
+       $_POST['assembly_account'] = $category_record["dflt_assembly_act"];
+       $_POST['dimension_id'] = $category_record["dflt_dim1"];
+       $_POST['dimension2_id'] = $category_record["dflt_dim2"];
+       $_POST['no_sale'] = $category_record["dflt_no_sale"];
+}
+$fresh_item = !isset($_POST['NewStockID']) || $new_item 
+       || check_usage($_POST['stock_id'],false);
 
 item_tax_types_list_row(_("Item Tax Type:"), 'tax_type_id', null);
 
-stock_item_types_list_row(_("Item Type:"), 'mb_flag', null,
-       (!isset($_POST['NewStockID']) || isset($_POST['New'])));
+stock_item_types_list_row(_("Item Type:"), 'mb_flag', null, $fresh_item);
+
+stock_units_list_row(_('Units of Measure:'), 'units', null, $fresh_item);
 
-stock_units_list_row(_('Units of Measure:'), 'units', null,
-       (!isset($_POST['NewStockID']) || isset($_POST['New'])));
-end_table();
-start_table("$table_style2 width=40%");
+$dim = get_company_pref('use_dimension');
+if ($dim >= 1)
+{
+       table_section_title(_("Dimensions"));
+
+       dimensions_list_row(_("Dimension")." 1", 'dimension_id', null, true, " ", false, 1);
+       if ($dim > 1)
+               dimensions_list_row(_("Dimension")." 2", 'dimension2_id', null, true, " ", false, 2);
+}
+if ($dim < 1)
+       hidden('dimension_id', 0);
+if ($dim < 2)
+       hidden('dimension2_id', 0);
+
+table_section(2);
 
 table_section_title(_("GL Accounts"));
 
 gl_all_accounts_list_row(_("Sales Account:"), 'sales_account', $_POST['sales_account']);
 
-gl_all_accounts_list_row(_("Inventory Account:"), 'inventory_account', $_POST['inventory_account']);
-
 if (!is_service($_POST['mb_flag'])) 
 {
+       gl_all_accounts_list_row(_("Inventory Account:"), 'inventory_account', $_POST['inventory_account']);
        gl_all_accounts_list_row(_("C.O.G.S. Account:"), 'cogs_account', $_POST['cogs_account']);
        gl_all_accounts_list_row(_("Inventory Adjustments Account:"), 'adjustment_account', $_POST['adjustment_account']);
 }
 else 
 {
+       gl_all_accounts_list_row(_("C.O.G.S. Account:"), 'inventory_account', $_POST['inventory_account']);
        hidden('cogs_account', $_POST['cogs_account']);
        hidden('adjustment_account', $_POST['adjustment_account']);
 }
@@ -349,35 +413,55 @@ if (is_manufactured($_POST['mb_flag']))
        gl_all_accounts_list_row(_("Item Assembly Costs Account:"), 'assembly_account', $_POST['assembly_account']);
 else
        hidden('assembly_account', $_POST['assembly_account']);
-$dim = get_company_pref('use_dimension');
-if ($dim >= 1)
-{
-       table_section_title(_("Dimensions"));
 
-       dimensions_list_row(_("Dimension")." 1", 'dimension_id', null, true, " ", false, 1);
-       if ($dim > 1)
-               dimensions_list_row(_("Dimension")." 2", 'dimension2_id', null, true, " ", false, 2);
+table_section_title(_("Other"));
+
+// Add image upload for New Item  - by Joe
+label_row(_("Image File (.jpg)") . ":", "<input type='file' id='pic' name='pic'>");
+// Add Image upload for New Item  - by Joe
+$stock_img_link = "";
+$check_remove_image = false;
+if (isset($_POST['NewStockID']) && file_exists("$comp_path/$user_comp/images/"
+       .item_img_name($_POST['NewStockID']).".jpg")) 
+{
+ // 31/08/08 - rand() call is necessary here to avoid caching problems. Thanks to Peter D.
+       $stock_img_link .= "<img id='item_img' alt = '[".$_POST['NewStockID'].".jpg".
+               "]' src='$comp_path/$user_comp/images/".item_img_name($_POST['NewStockID']).".jpg?nocache=".rand()."'".
+               " height='$pic_height' border='0'>";
+       $check_remove_image = true;     
+} 
+else 
+{
+       $stock_img_link .= _("No image");
 }
-if ($dim < 1)
-       hidden('dimension_id', 0);
-if ($dim < 2)
-       hidden('dimension2_id', 0);
 
-end_table(1);
+label_row("&nbsp;", $stock_img_link);
+if ($check_remove_image)
+       check_row(_("Delete Image:"), 'del_image');
+       
+check_row(_("Exclude from sales:"), 'no_sale');
 
-if (!isset($_POST['NewStockID']) || (isset($_POST['New']) && $_POST['New'] != "")) 
+record_status_list_row(_("Item status:"), 'inactive');
+end_outer_table(1);
+div_end();
+div_start('controls');
+if (!isset($_POST['NewStockID']) || $new_item) 
 {
-       submit_center('addupdate', _("Insert New Item"));
-
+       submit_center('addupdate', _("Insert New Item"), true, '', 'default');
 } 
 else 
 {
-       submit_center_first('addupdate', _("Update Item"));
-
-       submit_center_last('delete', _("Delete This Item"));
+       submit_center_first('addupdate', _("Update Item"), '', 
+               @$_REQUEST['popup'] ? true : 'default');
+       submit_return('select', get_post('stock_id'), 
+               _("Select this items and return to document entry."), 'default');
+       submit('clone', _("Clone This Item"), true, '', true);
+       submit('delete', _("Delete This Item"), true, '', true);
+       submit_center_last('cancel', _("Cancel"), _("Cancel Edition"), 'cancel');
 }
 
-
+div_end();
+hidden('popup', @$_REQUEST['popup']);
 end_form();
 
 //------------------------------------------------------------------------------------