Security update merged from 2.1.
[fa-stable.git] / manufacturing / includes / db / work_order_issues_db.inc
index 9474da08ed4ebf55fb2e38e177cd5cfcd4b236ae..2bdffa266b61306c8d0afd7e614ad71a65c0bd1e 100644 (file)
@@ -1,10 +1,21 @@
 <?php
-
+/**********************************************************************
+    Copyright (C) FrontAccounting, LLC.
+       Released under the terms of the GNU General Public License, GPL, 
+       as published by the Free Software Foundation, either version 3 
+       of the License, or (at your option) any later version.
+    This program is distributed in the hope that it will be useful,
+    but WITHOUT ANY WARRANTY; without even the implied warranty of
+    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
+    See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
+***********************************************************************/
 //--------------------------------------------------------------------------------------
 
 function add_work_order_issue($woid, $ref, $to_work_order, $items, $location, $workcentre,
        $date_, $memo_)
 {
+       global $Refs;
+
        begin_transaction();
 
        $details = get_work_order($woid);
@@ -25,8 +36,8 @@ function add_work_order_issue($woid, $ref, $to_work_order, $items, $location, $w
 
        // insert the actual issue
        $sql = "INSERT INTO ".TB_PREF."wo_issues (workorder_id, reference, issue_date, loc_code, workcentre_id)
-               VALUES ($woid, ".db_escape($ref).", '" .
-               date2sql($date_) . "', ".db_escape($location).", $workcentre)";
+               VALUES (".db_escape($woid).", ".db_escape($ref).", '" .
+               date2sql($date_) . "', ".db_escape($location).", ".db_escape($workcentre).")";
        db_query($sql,"The work order issue could not be added");
 
        $number = db_insert_id();
@@ -38,18 +49,20 @@ function add_work_order_issue($woid, $ref, $to_work_order, $items, $location, $w
                        $item->quantity = -$item->quantity;
 
                // insert a -ve stock move for each item
-               add_stock_move(28, $item->stock_id, $number,
+               add_stock_move(ST_MANUISSUE, $item->stock_id, $number,
                        $location, $date_, $memo_, -$item->quantity, 0);
 
                $sql = "INSERT INTO ".TB_PREF."wo_issue_items (issue_id, stock_id, qty_issued)
-                       VALUES ('$number', '$item->stock_id', $item->quantity)";
+                       VALUES (".db_escape($number).", ".db_escape($item->stock_id).", "
+                       .db_escape($item->quantity).")";
                db_query($sql,"A work order issue item could not be added");
        }
 
        if ($memo_)
-               add_comments(28, $number, $date_, $memo_);
+               add_comments(ST_MANUISSUE, $number, $date_, $memo_);
 
-       references::save_last($ref, 28);
+       $Refs->save(ST_MANUISSUE, $number, $ref);
+       add_audit_trail(ST_MANUISSUE, $number, $date_);
 
        commit_transaction();
 }
@@ -58,18 +71,30 @@ function add_work_order_issue($woid, $ref, $to_work_order, $items, $location, $w
 
 function get_work_order_issues($woid)
 {
-       $sql = "SELECT * FROM ".TB_PREF."wo_issues WHERE workorder_id=$woid ORDER BY issue_no";
+       $sql = "SELECT * FROM ".TB_PREF."wo_issues WHERE workorder_id=".db_escape($woid)
+       ." ORDER BY issue_no";
     return db_query($sql, "The work order issues could not be retrieved");
 }
 
+function get_additional_issues($woid)
+{
+       $sql = "SELECT ".TB_PREF."wo_issues.*, ".TB_PREF."wo_issue_items.*
+               FROM ".TB_PREF."wo_issues, ".TB_PREF."wo_issue_items
+               WHERE ".TB_PREF."wo_issues.issue_no=".TB_PREF."wo_issue_items.issue_id
+               AND ".TB_PREF."wo_issues.workorder_id=".db_escape($woid)
+               ." ORDER BY ".TB_PREF."wo_issue_items.id";
+    return db_query($sql, "The work order issues could not be retrieved");
+}
 //--------------------------------------------------------------------------------------
 
 function get_work_order_issue($issue_no)
 {
        $sql = "SELECT DISTINCT ".TB_PREF."wo_issues.*, ".TB_PREF."workorders.stock_id,
-               ".TB_PREF."stock_master.description, ".TB_PREF."locations.location_name, ".TB_PREF."workcentres.name AS WorkCentreName
-               FROM ".TB_PREF."wo_issues, ".TB_PREF."workorders, ".TB_PREF."stock_master, ".TB_PREF."locations, ".TB_PREF."workcentres
-               WHERE issue_no='$issue_no'
+               ".TB_PREF."stock_master.description, ".TB_PREF."locations.location_name, "
+               .TB_PREF."workcentres.name AS WorkCentreName
+               FROM ".TB_PREF."wo_issues, ".TB_PREF."workorders, ".TB_PREF."stock_master, "
+               .TB_PREF."locations, ".TB_PREF."workcentres
+               WHERE issue_no=".db_escape($issue_no)."
                AND ".TB_PREF."workorders.id = ".TB_PREF."wo_issues.workorder_id
                AND ".TB_PREF."locations.loc_code = ".TB_PREF."wo_issues.loc_code
                AND ".TB_PREF."workcentres.id = ".TB_PREF."wo_issues.workcentre_id
@@ -83,9 +108,10 @@ function get_work_order_issue($issue_no)
 
 function get_work_order_issue_details($issue_no)
 {
-       $sql = "SELECT ".TB_PREF."wo_issue_items.*,".TB_PREF."stock_master.description, ".TB_PREF."stock_master.units
+       $sql = "SELECT ".TB_PREF."wo_issue_items.*,"
+       .TB_PREF."stock_master.description, ".TB_PREF."stock_master.units
                FROM ".TB_PREF."wo_issue_items, ".TB_PREF."stock_master
-               WHERE issue_id=$issue_no
+               WHERE issue_id=".db_escape($issue_no)."
                AND ".TB_PREF."stock_master.stock_id=".TB_PREF."wo_issue_items.stock_id
                ORDER BY ".TB_PREF."wo_issue_items.id";
     return db_query($sql, "The work order issue items could not be retrieved");
@@ -95,7 +121,7 @@ function get_work_order_issue_details($issue_no)
 
 function exists_work_order_issue($issue_no)
 {
-       $sql = "SELECT issue_no FROM ".TB_PREF."wo_issues WHERE issue_no=$issue_no";
+       $sql = "SELECT issue_no FROM ".TB_PREF."wo_issues WHERE issue_no=".db_escape($issue_no);
        $result = db_query($sql, "Cannot retreive a wo issue");
 
     return (db_num_rows($result) > 0);
@@ -108,14 +134,15 @@ function void_work_order_issue($type_no)
        begin_transaction();
 
        // void the actual issue items and their quantities
-       $sql = "UPDATE ".TB_PREF."wo_issue_items Set qty_issued = 0 WHERE issue_id=$type_no";
+       $sql = "UPDATE ".TB_PREF."wo_issue_items Set qty_issued = 0 WHERE issue_id="
+               .db_escape($type_no);
        db_query($sql,"A work order issue item could not be voided");
 
        // void all related stock moves
-       void_stock_move(28, $type_no);
+       void_stock_move(ST_MANUISSUE, $type_no);
 
        // void any related gl trans
-       void_gl_trans(28, $type_no, true);
+       void_gl_trans(ST_MANUISSUE, $type_no, true);
 
        commit_transaction();
 }