Security statements update against sql injection attacks.
[fa-stable.git] / purchasing / supplier_invoice.php
index 9f2f1cc167e4b22df8071f47a09afc64ae55aaa6..ab2409d981f7cafa7aa8786d86af896a66ffb953 100644 (file)
@@ -1,5 +1,14 @@
 <?php
-
+/**********************************************************************
+    Copyright (C) FrontAccounting, LLC.
+       Released under the terms of the GNU General Public License, GPL, 
+       as published by the Free Software Foundation, either version 3 
+       of the License, or (at your option) any later version.
+    This program is distributed in the hope that it will be useful,
+    but WITHOUT ANY WARRANTY; without even the implied warranty of
+    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
+    See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
+***********************************************************************/
 $page_security=5;
 $path_to_root="..";
 
@@ -49,8 +58,10 @@ if (isset($_GET['AddedID']))
 
        display_note(get_gl_view_str($trans_type, $invoice_no, _("View the GL Journal Entries for this Invoice")), 1);
 
-    hyperlink_params($_SERVER['PHP_SELF'], _("Enter Another Invoice"), "New=1");
+       hyperlink_params($_SERVER['PHP_SELF'], _("Enter Another Invoice"), "New=1");
 
+       hyperlink_params("$path_to_root/admin/attachments.php", _("Add an Attachment"), "filterType=$trans_type&trans_no=$invoice_no");
+       
        display_footer_exit();
 }
 
@@ -99,7 +110,7 @@ if (isset($_POST['AddGLCodeToTrans'])){
        $Ajax->activate('gl_items');
        $input_error = false;
 
-       $sql = "SELECT account_code, account_name FROM ".TB_PREF."chart_master WHERE account_code='" . $_POST['gl_code'] . "'";
+       $sql = "SELECT account_code, account_name FROM ".TB_PREF."chart_master WHERE account_code=".db_escape($_POST['gl_code']);
        $result = db_query($sql,"get account information");
        if (db_num_rows($result) == 0)
        {
@@ -119,6 +130,12 @@ if (isset($_POST['AddGLCodeToTrans'])){
                }
        }
 
+       if (!is_tax_gl_unique(get_post('gl_code'))) {
+               display_error(_("Cannot post to GL account used by more than one tax type."));
+               set_focus('gl_code');
+               $input_error = true;
+       }
+
        if ($input_error == false)
        {
                $_SESSION['supp_trans']->add_gl_codes_to_trans($_POST['gl_code'], $gl_act_name,
@@ -178,7 +195,11 @@ function check_data()
                return false;
        }
 
-       $sql = "SELECT Count(*) FROM ".TB_PREF."supp_trans WHERE supplier_id='" . $_SESSION['supp_trans']->supplier_id . "' AND supp_reference='" . $_POST['supp_reference'] . "'";
+       $sql = "SELECT Count(*) FROM ".TB_PREF."supp_trans WHERE supplier_id="
+               .db_escape($_SESSION['supp_trans']->supplier_id) . " AND supp_reference=" 
+               .db_escape( $_POST['supp_reference']) 
+               . " AND ov_amount!=0"; // ignore voided invoice references
+
        $result=db_query($sql,"The sql to check for the previous entry of the same invoice failed");
 
        $myrow = db_fetch_row($result);
@@ -306,68 +327,28 @@ if (isset($_POST['InvGRNAll']))
 }      
 
 //--------------------------------------------------------------------------------------------------
-$id = find_submit('Delete');
-if ($id != -1)
+$id3 = find_submit('Delete');
+if ($id3 != -1)
 {
-       $_SESSION['supp_trans']->remove_grn_from_trans($id);
+       $_SESSION['supp_trans']->remove_grn_from_trans($id3);
        $Ajax->activate('grn_items');
        $Ajax->activate('inv_tot');
 }
 
-$id = find_submit('Delete2');
-if ($id != -1)
+$id4 = find_submit('Delete2');
+if ($id4 != -1)
 {
-       $_SESSION['supp_trans']->remove_gl_codes_from_trans($id);
+       $_SESSION['supp_trans']->remove_gl_codes_from_trans($id4);
        clear_fields();
        $Ajax->activate('gl_items');
        $Ajax->activate('inv_tot');
 }
 
-start_form(false, true);
-
-start_table("$table_style2 width=98%", 8);
-echo "<tr><td valign=center>"; // outer table
-
-echo "<center>";
-
-invoice_header($_SESSION['supp_trans']);
-if ($_POST['supplier_id']=='') 
-       display_error('No supplier found for entered search text');
-else {
-       echo "</td></tr><tr><td valign=center>"; // outer table
-
-       echo "<center>";
-
-       display_grn_items($_SESSION['supp_trans'], 1);
-       //display_grn_items_for_selection();
-       display_gl_items($_SESSION['supp_trans'], 1);
-       //display_gl_controls();
-
-       //echo "</td></tr><tr><td align=center colspan=2>"; // outer table
-       echo "<br>";
-       div_start('inv_tot');
-       invoice_totals($_SESSION['supp_trans']);
-       div_end();
-}
-echo "</td></tr>";
-
-end_table(); // outer table
-
-//-----------------------------------------------------------------------------------------
-$id = find_submit('grn_item_id');
-$id2 = find_submit('void_item_id');
-if ($id != -1 || $id2 != -1)
-{
-       $Ajax->activate('grn_items');
-       $Ajax->activate('inv_tot');
-}
-
-if (get_post('AddGLCodeToTrans'))
-       $Ajax->activate('inv_tot');
-
+$id2 = -1;
 if ($_SESSION["wa_current_user"]->access == 2)
 {
-       if ($id2 != -1) // Added section 2008-10-18 Joe Hunt for voiding delivery lines
+       $id2 = find_submit('void_item_id');
+       if ($id2 != -1) 
        {
                begin_transaction();
                
@@ -390,12 +371,53 @@ if ($_SESSION["wa_current_user"]->access == 2)
                        -$myrow["QtyOstdg"], $myrow['std_cost_unit'], $grn["supplier_id"], 1, $myrow['unit_price']);
                        
                commit_transaction();
+               display_notification(sprintf(_('All yet non-invoiced items on delivery line # %d has been removed.'), $id2));
+
        }               
 }
 
-echo "<br>";
+if (isset($_POST['go']))
+{
+       $Ajax->activate('gl_items');
+       display_quick_entries($_SESSION['supp_trans'], $_POST['qid'], input_num('totamount'), QE_SUPPINV);
+       $_POST['totamount'] = price_format(0); $Ajax->activate('totamount');
+       $Ajax->activate('inv_tot');
+}
+
+start_form(false, true);
+
+invoice_header($_SESSION['supp_trans']);
+
+if ($_POST['supplier_id']=='') 
+       display_error('No supplier found for entered search text');
+else {
+       start_outer_table("$table_style2 width=98%", 5);
+
+       display_grn_items($_SESSION['supp_trans'], 1);
+
+       display_gl_items($_SESSION['supp_trans'], 1);
+
+       div_start('inv_tot');
+       invoice_totals($_SESSION['supp_trans']);
+       div_end();
+
+       end_outer_table(0, false);
+}
+
+//-----------------------------------------------------------------------------------------
+
+if ($id != -1 || $id2 != -1)
+{
+       $Ajax->activate('grn_items');
+       $Ajax->activate('inv_tot');
+}
+
+if (get_post('AddGLCodeToTrans'))
+       $Ajax->activate('inv_tot');
+
+br();
 submit_center('PostInvoice', _("Enter Invoice"), true, '', true);
-echo "<br>";
+br();
 
 end_form();