X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;f=sales%2Fincludes%2Fdb%2Fsales_points_db.inc;h=b5abaef7f7f631bb1775bdaa5f9e42bf6b6b3679;hb=58ca6ac4ea7a903514388cf8c3f380f745d81551;hp=9feae5aa7846d2866fb6d85bce957b8a4bb1af9e;hpb=21290a4a16ca78fe736f62cf1cb039c06cb53fca;p=fa-stable.git diff --git a/sales/includes/db/sales_points_db.inc b/sales/includes/db/sales_points_db.inc index 9feae5aa..b5abaef7 100644 --- a/sales/includes/db/sales_points_db.inc +++ b/sales/includes/db/sales_points_db.inc @@ -25,17 +25,18 @@ function update_sales_point($id, $name, $location, $account, $cash, $credit) .",pos_account=".db_escape($account) .",cash_sale =$cash" .",credit_sale =$credit" - ." WHERE id = $id"; + ." WHERE id = ".db_escape($id); db_query($sql, "could not update sales type"); } -function get_all_sales_points() +function get_all_sales_points($all=false) { $sql = "SELECT pos.*, loc.location_name, acc.bank_account_name FROM " .TB_PREF."sales_pos as pos LEFT JOIN ".TB_PREF."locations as loc on pos.pos_location=loc.loc_code LEFT JOIN ".TB_PREF."bank_accounts as acc on pos.pos_account=acc.id"; + if (!$all) $sql .= " WHERE !pos.inactive"; return db_query($sql, "could not get all POS definitions"); } @@ -46,7 +47,7 @@ function get_sales_point($id) .TB_PREF."sales_pos as pos LEFT JOIN ".TB_PREF."locations as loc on pos.pos_location=loc.loc_code LEFT JOIN ".TB_PREF."bank_accounts as acc on pos.pos_account=acc.id - WHERE pos.id='$id'"; + WHERE pos.id=".db_escape($id); $result = db_query($sql, "could not get POS definition"); @@ -55,7 +56,7 @@ function get_sales_point($id) function get_sales_point_name($id) { - $sql = "SELECT pos_name FROM ".TB_PREF."sales_pos WHERE id=$id"; + $sql = "SELECT pos_name FROM ".TB_PREF."sales_pos WHERE id=".db_escape($id); $result = db_query($sql, "could not get POS name"); @@ -65,8 +66,7 @@ function get_sales_point_name($id) function delete_sales_point($id) { - $sql="DELETE FROM ".TB_PREF."sales_pos WHERE id=$id"; + $sql="DELETE FROM ".TB_PREF."sales_pos WHERE id=".db_escape($id); db_query($sql,"The point of sale record could not be deleted"); } -?> \ No newline at end of file