X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;ds=sidebyside;f=dimensions%2Finquiry%2Fsearch_dimensions.php;h=1c63c2fc89171f7019a3accdedcf2db29378ec06;hb=9437de4193bde74b4a77e6ddcafede09b500c241;hp=8006a1c4f6265517bb4ce0e2bfc5566d1d57d4d5;hpb=c1ab12ce9d688466f26ac4ca3b0e11ddc0c4b8e2;p=fa-stable.git diff --git a/dimensions/inquiry/search_dimensions.php b/dimensions/inquiry/search_dimensions.php index 8006a1c4..1c63c2fc 100644 --- a/dimensions/inquiry/search_dimensions.php +++ b/dimensions/inquiry/search_dimensions.php @@ -90,13 +90,11 @@ submit_cells('SearchOrders', _("Search"), '', '', 'default'); end_row(); end_table(); -end_form(); - $dim = get_company_pref('use_dimension'); function view_link($row) { - return get_dimensions_trans_view_str(systypes::dimension(), $row["id"]); + return get_dimensions_trans_view_str(ST_DIMENSION, $row["id"]); } function is_closed($row) @@ -118,7 +116,7 @@ function sum_dimension($row) function is_overdue($row) { - return date_diff(Today(), sql2date($row["due_date"]), "d") > 0; + return date_diff2(Today(), sql2date($row["due_date"]), "d") > 0; } function edit_link($row) @@ -141,7 +139,7 @@ $sql = "SELECT dim.id, if (isset($_POST['OrderNumber']) && $_POST['OrderNumber'] != "") { - $sql .= " AND reference LIKE '%". $_POST['OrderNumber'] . "%'"; + $sql .= " AND reference LIKE ".db_escape("%". $_POST['OrderNumber'] . "%"); } else { if ($dim == 1) @@ -154,14 +152,14 @@ if (isset($_POST['OrderNumber']) && $_POST['OrderNumber'] != "") if (isset($_POST['type_']) && ($_POST['type_'] > 0)) { - $sql .= " AND type_=" . $_POST['type_']; + $sql .= " AND type_=".db_escape($_POST['type_']); } if (isset($_POST['OverdueOnly'])) { $today = date2sql(Today()); - $sql .= " AND due_date < '$today' "; + $sql .= " AND due_date < '$today'"; } $sql .= " AND date_ >= '" . date2sql($_POST['FromDate']) . "' @@ -187,12 +185,7 @@ if ($outstanding_only) { $table =& new_db_pager('dim_tbl', $sql, $cols); $table->set_marker('is_overdue', _("Marked dimensions are overdue.")); -if (get_post('SearchOrders')) { - $table->set_sql($sql); - $table->set_columns($cols); -} $table->width = "80%"; -start_form(); display_db_pager($table);