Module gl sealed against XSS Attacks
[fa-stable.git] / sales / view / view_sales_order.php
index e717e4bed8033f551f636dc7c259850fab4bc8e2..13bebb09beec97d4fcb670a17d68c6bcfe8123c6 100644 (file)
@@ -16,17 +16,14 @@ if ($use_popup_windows)
 
 page(_("View Sales Order"), true, false, "", $js);
 
-display_heading(_("Sales Order") . " #" . $_GET['trans_no']);
+display_heading(sprintf(_("Sales Order #%d"),$_GET['trans_no']));
 
 if (isset($_SESSION['Items']))
 {
        unset ($_SESSION['Items']);
 }
 
-$_SESSION['Items'] = new cart;
-
-/*read in all the selected order into the Items cart  */
-read_sales_order($_GET['trans_no'], $_SESSION['Items']);
+$_SESSION['Items'] = new Cart(30, $_GET['trans_no'], true);
 
 start_table("$table_style2 width=95%", 5);
 echo "<tr valign=top><td>";
@@ -47,8 +44,8 @@ label_cells(_("Customer Order Ref."), $_SESSION['Items']->cust_ref, "class='tabl
 label_cells(_("Deliver To Branch"), $_SESSION['Items']->deliver_to, "class='tableheader2'");
 end_row();
 start_row();
-label_cells(_("Ordered On"), $_SESSION['Items']->orig_order_date, "class='tableheader2'");
-label_cells(_("Requested Delivery"), $_SESSION['Items']->delivery_date, "class='tableheader2'");
+label_cells(_("Ordered On"), $_SESSION['Items']->document_date, "class='tableheader2'");
+label_cells(_("Requested Delivery"), $_SESSION['Items']->due_date, "class='tableheader2'");
 end_row();
 start_row();
 label_cells(_("Order Currency"), $_SESSION['Items']->customer_currency, "class='tableheader2'");
@@ -82,7 +79,7 @@ while ($del_row = db_fetch($result))
 
        alt_table_row_color($k);
 
-       $this_total = $del_row["ov_freight"] + $del_row["ov_gst"] + $del_row["ov_amount"];
+       $this_total = $del_row["ov_freight"]+ $del_row["ov_amount"] + $del_row["ov_freight_tax"]  + $del_row["ov_gst"] ;
        $delivery_total += $this_total;
 
        label_cell(get_customer_trans_view_str($del_row["type"], $del_row["trans_no"]));
@@ -93,7 +90,7 @@ while ($del_row = db_fetch($result))
 
 }
 
-label_row(null, number_format2($delivery_total,user_price_dec()), "", "colspan=4 align=right");
+label_row(null, price_format($delivery_total), "", "colspan=4 align=right");
 
 end_table();
 echo "</td><td valign='top'>";
@@ -115,7 +112,7 @@ while ($inv_row = db_fetch($result))
 
        alt_table_row_color($k);
 
-       $this_total = $inv_row["ov_freight"] + $inv_row["ov_gst"] + $inv_row["ov_amount"];
+       $this_total = $inv_row["ov_freight"] + $inv_row["ov_freight_tax"]  + $inv_row["ov_gst"] + $inv_row["ov_amount"];
        $invoices_total += $this_total;
 
        label_cell(get_customer_trans_view_str($inv_row["type"], $inv_row["trans_no"]));
@@ -126,7 +123,7 @@ while ($inv_row = db_fetch($result))
 
 }
 
-label_row(null, number_format2($invoices_total,user_price_dec()), "", "colspan=4 align=right");
+label_row(null, price_format($invoices_total), "", "colspan=4 align=right");
 
 end_table();
 
@@ -147,7 +144,7 @@ while ($credits_row = db_fetch($result))
 
        alt_table_row_color($k);
 
-       $this_total = $credits_row["ov_freight"] + $credits_row["ov_gst"] + $credits_row["ov_amount"];
+       $this_total = $credits_row["ov_freight"] + $credits_row["ov_freight_tax"]  + $credits_row["ov_gst"] + $credits_row["ov_amount"];
        $credits_total += $this_total;
 
        label_cell(get_customer_trans_view_str($credits_row["type"], $credits_row["trans_no"]));
@@ -158,7 +155,7 @@ while ($credits_row = db_fetch($result))
 
 }
 
-label_row(null, "<font color=red>" . number_format2(-$credits_total,user_price_dec()) . "</font>",
+label_row(null, "<font color=red>" . price_format(-$credits_total) . "</font>",
        "", "colspan=4 align=right");
 
 
@@ -180,7 +177,8 @@ $k = 0;  //row colour counter
 
 foreach ($_SESSION['Items']->line_items as $stock_item) {
 
-       $line_total =   $stock_item->quantity * $stock_item->price * (1 - $stock_item->discount_percent);
+       $line_total = round($stock_item->quantity * $stock_item->price * (1 - $stock_item->discount_percent), 
+          user_price_dec());
 
        alt_table_row_color($k);
 
@@ -198,11 +196,11 @@ foreach ($_SESSION['Items']->line_items as $stock_item) {
 
 $items_total = $_SESSION['Items']->get_items_total();
 
-$display_total = number_format2($items_total + $_SESSION['Items']->freight_cost,user_price_dec());
+$display_total = price_format($items_total + $_SESSION['Items']->freight_cost);
 
-label_row(_("Shipping"), number_format2($_SESSION['Items']->freight_cost,user_price_dec()),
+label_row(_("Shipping"), price_format($_SESSION['Items']->freight_cost),
        "align=right colspan=6", "nowrap align=right");
-label_row(_("Total Excluding Tax"), $display_total, "align=right colspan=6",
+label_row(_("Total Order Value"), $display_total, "align=right colspan=6",
        "nowrap align=right");
 
 end_table(2);