function costs_link($row)
{
+/*
return $row["closed"] || !$row["released"] ? '' :
pager_link(_('Costs'),
"/gl/gl_bank.php?NewPayment=1&PayType="
.payment_person_types::WorkOrder(). "&PayPerson=" .$row["id"]);
+*/
+ return $row["closed"] || !$row["released"] ? '' :
+ pager_link(_('Costs'),
+ "/manufacturing/work_order_costs.php?trans_no=" .$row["id"]);
}
function view_gl_link($row)
if (isset($_POST['StockLocation']) && $_POST['StockLocation'] != $all_items)
{
- $sql .= " AND workorder.loc_code='" . $_POST['StockLocation'] . "' ";
+ $sql .= " AND workorder.loc_code=".db_escape($_POST['StockLocation']);
}
if (isset($_POST['OrderNumber']) && $_POST['OrderNumber'] != "")
{
- $sql .= " AND workorder.wo_ref LIKE '%". $_POST['OrderNumber'] . "%'";
+ $sql .= " AND workorder.wo_ref LIKE ".db_escape('%'.$_POST['OrderNumber'].'%');
}
if (isset($_POST['SelectedStockItem']) && $_POST['SelectedStockItem'] != $all_items)
{
- $sql .= " AND workorder.stock_id='". $_POST['SelectedStockItem'] . "'";
+ $sql .= " AND workorder.stock_id=".db_escape($_POST['SelectedStockItem']);
}
if (check_value('OverdueOnly'))