{
$sql = "INSERT INTO ".TB_PREF."supp_invoice_items (supp_trans_type, supp_trans_no, stock_id, description, gl_code, unit_price, unit_tax, quantity,
grn_item_id, po_detail_item_id, memo_) ";
- $sql .= "VALUES ($supp_trans_type, $supp_trans_no, '$stock_id', '$description', '$gl_code', $unit_price, $unit_tax, $quantity,
- $grn_item_id, $po_detail_item_id, '$memo_')";
+ $sql .= "VALUES ($supp_trans_type, $supp_trans_no, ".db_escape($stock_id).
+ ", ".db_escape($description).", ".db_escape($gl_code).", $unit_price, $unit_tax, $quantity,
+ $grn_item_id, $po_detail_item_id, ".db_escape($memo_).")";
if ($err_msg == "")
$err_msg = "Cannot insert a supplier transaction detail record";
function get_supp_invoice_items($supp_trans_type, $supp_trans_no)
{
- $sql = "SELECT *,unit_price+unit_tax AS FullUnitPrice FROM ".TB_PREF."supp_invoice_items
+ $sql = "SELECT *, unit_price AS FullUnitPrice FROM ".TB_PREF."supp_invoice_items
WHERE supp_trans_type = $supp_trans_type
AND supp_trans_no = $supp_trans_no ORDER BY id";
return db_query($sql, "Cannot retreive supplier transaction detail records");