Single quotes encoded before database data insert.
[fa-stable.git] / purchasing / view / view_po.php
index fe1648222a364cecd5cb8fa08093dd76f30a199b..052103deeff636c073bf4161085a329996ee85aa 100644 (file)
@@ -1,15 +1,27 @@
 <?php
-
-
-$page_security = 2;
-$path_to_root="../..";
+/**********************************************************************
+    Copyright (C) FrontAccounting, LLC.
+       Released under the terms of the GNU General Public License, GPL, 
+       as published by the Free Software Foundation, either version 3 
+       of the License, or (at your option) any later version.
+    This program is distributed in the hope that it will be useful,
+    but WITHOUT ANY WARRANTY; without even the implied warranty of
+    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
+    See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
+***********************************************************************/
+$page_security = 'SA_SUPPTRANSVIEW';
+$path_to_root = "../..";
 include($path_to_root . "/purchasing/includes/po_class.inc");
 
 include($path_to_root . "/includes/session.inc");
-page(_("View Purchase Order"), true);
-
 include($path_to_root . "/purchasing/includes/purchasing_ui.inc");
 
+$js = "";
+if ($use_popup_windows)
+       $js .= get_js_open_window(900, 500);
+page(_("View Purchase Order"), true, false, "", $js);
+
+
 if (!isset($_GET['trans_no']))
 {
        die ("<br>" . _("This page must be called with a purchase order number to review."));
@@ -17,11 +29,6 @@ if (!isset($_GET['trans_no']))
 
 display_heading(_("Purchase Order") . " #" . $_GET['trans_no']);
 
-if (isset($_SESSION['Items']))
-{
-       unset ($_SESSION['Items']);
-}
-
 $purchase_order = new purch_order;
 
 read_po($_GET['trans_no'], $purchase_order);
@@ -63,7 +70,7 @@ foreach ($purchase_order->line_items as $stock_item)
        $dec = get_qty_dec($stock_item->stock_id);
        qty_cell($stock_item->quantity, false, $dec);
        label_cell($stock_item->units);
-       amount_cell($stock_item->price);
+       amount_decimal_cell($stock_item->price);
        amount_cell($line_total);
        label_cell($stock_item->req_del_date);
        qty_cell($stock_item->qty_received, false, $dec);
@@ -101,7 +108,7 @@ if (db_num_rows($grns_result) > 0)
     {
                alt_table_row_color($k);
 
-       label_cell(get_trans_view_str(25,$myrow["id"]));
+       label_cell(get_trans_view_str(ST_SUPPRECEIVE,$myrow["id"]));
        label_cell($myrow["reference"]);
        label_cell(sql2date($myrow["delivery_date"]));
        end_row();