Sealing against XSS atacks: purchasing,sales,install,admin,taxes
[fa-stable.git] / sales / includes / db / cust_trans_details_db.inc
index b0f7a90a399704552fc2172fa7062b01a5e83c24..b44c1d5f12e41d4922e8a5c8cfa03c7efacf3a17 100644 (file)
@@ -2,28 +2,28 @@
 
 //----------------------------------------------------------------------------------------
 
-function add_customer_trans_detail_item_base($debtor_trans_type, $debtor_trans_no, $stock_id, $description, $quantity,
-       $unit_price, $unit_tax, $discount_percent, $standard_cost)
-{
-       $sql = "INSERT INTO ".TB_PREF."debtor_trans_details (debtor_trans_no, debtor_trans_type, stock_id, description, quantity, unit_price, unit_tax, discount_percent, standard_cost)
-               VALUES ($debtor_trans_no, $debtor_trans_type, '$stock_id', '$description', $quantity, $unit_price, $unit_tax, $discount_percent, $standard_cost)";
-
-       db_query($sql, "The debtor transaction detail could not be added");
-}
-
-//----------------------------------------------------------------------------------------
-
 function get_customer_trans_details($debtor_trans_type, $debtor_trans_no)
 {
-       $sql = "SELECT ".TB_PREF."debtor_trans_details.*, ".TB_PREF."debtor_trans_details.unit_price+".TB_PREF."debtor_trans_details.unit_tax AS FullUnitPrice,
+if (!is_array($debtor_trans_no))
+       $debtor_trans_no = array( 0=>$debtor_trans_no );
+
+       $sql = "SELECT ".TB_PREF."debtor_trans_details.*,
+               ".TB_PREF."debtor_trans_details.unit_price+".TB_PREF."debtor_trans_details.unit_tax AS FullUnitPrice,
                ".TB_PREF."debtor_trans_details.description As StockDescription,
                ".TB_PREF."stock_master.units
                FROM ".TB_PREF."debtor_trans_details,".TB_PREF."stock_master
-               WHERE debtor_trans_no=$debtor_trans_no
-               AND debtor_trans_type=$debtor_trans_type
+               WHERE (";
+
+       $tr=array();
+       foreach ($debtor_trans_no as $trans_no)
+               $tr[] = 'debtor_trans_no='.$trans_no;
+
+       $sql .= implode(' OR ', $tr);
+
+
+       $sql.=  ") AND debtor_trans_type=$debtor_trans_type
                AND ".TB_PREF."stock_master.stock_id=".TB_PREF."debtor_trans_details.stock_id
                ORDER BY id";
-
        return db_query($sql, "The debtor transaction detail could not be queried");
 }
 
@@ -41,40 +41,6 @@ function void_customer_trans_details($type, $type_no)
        // clear the stock move items
        void_stock_move($type, $type_no);
 }
-
-//----------------------------------------------------------------------------------------
-
-function add_customer_trans_detail_item($debtor_trans_type, $debtor_trans_no, $stock_id, $description,
-       $Location, $date_, $quantity, $unit_price, $unit_tax, $discount_percent,
-       $reference,     $std_cost)
-{
-       add_customer_trans_detail_item_base($debtor_trans_type, $debtor_trans_no, $stock_id, $description,
-               $quantity, $unit_price, $unit_tax, $discount_percent, $std_cost);
-
-       add_stock_move_customer($debtor_trans_type, $stock_id, $debtor_trans_no, $Location,
-               $date_, $reference, $quantity, $std_cost, 1, $unit_price+$unit_tax, $discount_percent);
-
-       return $std_cost;
-}
-
-//----------------------------------------------------------------------------------------
-
-function add_customer_trans_detail_item_writeoff($debtor_trans_type, $debtor_trans_no, $stock_id, $description,
-       $Location, $date_, $quantity, $unit_price, $unit_tax, $discount_percent,
-       $reference, $std_cost)
-{
-       $retCost = add_customer_trans_detail_item($debtor_trans_type, $debtor_trans_no, $stock_id, $description,
-               $Location, $date_, $quantity, $unit_price, $unit_tax, $discount_percent,
-               $reference,     $std_cost);
-
-       $reference = _("Write off") . " " . $reference;
-
-       add_stock_move_customer($debtor_trans_type, $stock_id, $debtor_trans_no, $Location,
-               $date_, $reference, -$quantity, $std_cost, 0, $unit_price+$unit_tax, $discount_percent);
-
-       return $retCost;
-}
-
 //----------------------------------------------------------------------------------------
 
 function add_customer_trans_tax_detail_item($debtor_trans_type, $debtor_trans_no,
@@ -94,6 +60,7 @@ function get_customer_trans_tax_details($debtor_trans_type, $debtor_trans_no)
                FROM ".TB_PREF."debtor_trans_tax_details,".TB_PREF."tax_types
                WHERE debtor_trans_no=$debtor_trans_no
                AND debtor_trans_type=$debtor_trans_type
+               AND amount != 0
                AND ".TB_PREF."tax_types.id = ".TB_PREF."debtor_trans_tax_details.tax_type_id";
 
        return db_query($sql, "The debtor transaction tax details could not be queried");
@@ -112,4 +79,28 @@ function void_customer_trans_tax_details($type, $type_no)
 
 //----------------------------------------------------------------------------------------
 
+function write_customer_trans_detail_item($debtor_trans_type, $debtor_trans_no, $stock_id, $description,
+       $quantity, $unit_price, $unit_tax, $discount_percent, $std_cost, $line_id=0)
+{
+       if ($line_id!=0)
+               $sql = "UPDATE ".TB_PREF."debtor_trans_details SET
+                       stock_id=".db_escape($stock_id).",
+                       description=".db_escape($description).",
+                       quantity=$quantity,
+                       unit_price=$unit_price,
+                       unit_tax=$unit_tax,
+                       discount_percent=$discount_percent,
+                       standard_cost=$std_cost WHERE
+                       id=$line_id";
+       else
+                       $sql = "INSERT INTO ".TB_PREF."debtor_trans_details (debtor_trans_no,
+                               debtor_trans_type, stock_id, description, quantity, unit_price,
+                               unit_tax, discount_percent, standard_cost)
+                       VALUES ($debtor_trans_no, $debtor_trans_type, ".db_escape($stock_id).
+                       ", ".db_escape($description).",
+                               $quantity, $unit_price, $unit_tax, $discount_percent, $std_cost)";
+
+       db_query($sql, "The debtor transaction detail could not be written");
+}
+
 ?>
\ No newline at end of file