X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;f=sales%2Fincludes%2Fdb%2Fsales_points_db.inc;h=c7ff404b9eb832b48b6d7b0a443c1dd0f8b6e71d;hb=7010ff2972dfbc8be4e577bdeac6b8da7278b691;hp=9feae5aa7846d2866fb6d85bce957b8a4bb1af9e;hpb=86af6b95195f569b21ec74c752bc6907907c7316;p=fa-stable.git diff --git a/sales/includes/db/sales_points_db.inc b/sales/includes/db/sales_points_db.inc index 9feae5aa..c7ff404b 100644 --- a/sales/includes/db/sales_points_db.inc +++ b/sales/includes/db/sales_points_db.inc @@ -25,17 +25,18 @@ function update_sales_point($id, $name, $location, $account, $cash, $credit) .",pos_account=".db_escape($account) .",cash_sale =$cash" .",credit_sale =$credit" - ." WHERE id = $id"; + ." WHERE id = ".db_escape($id); db_query($sql, "could not update sales type"); } -function get_all_sales_points() +function get_all_sales_points($all=false) { $sql = "SELECT pos.*, loc.location_name, acc.bank_account_name FROM " .TB_PREF."sales_pos as pos LEFT JOIN ".TB_PREF."locations as loc on pos.pos_location=loc.loc_code LEFT JOIN ".TB_PREF."bank_accounts as acc on pos.pos_account=acc.id"; + if (!$all) $sql .= " WHERE !pos.inactive"; return db_query($sql, "could not get all POS definitions"); } @@ -46,7 +47,7 @@ function get_sales_point($id) .TB_PREF."sales_pos as pos LEFT JOIN ".TB_PREF."locations as loc on pos.pos_location=loc.loc_code LEFT JOIN ".TB_PREF."bank_accounts as acc on pos.pos_account=acc.id - WHERE pos.id='$id'"; + WHERE pos.id=".db_escape($id); $result = db_query($sql, "could not get POS definition"); @@ -55,7 +56,7 @@ function get_sales_point($id) function get_sales_point_name($id) { - $sql = "SELECT pos_name FROM ".TB_PREF."sales_pos WHERE id=$id"; + $sql = "SELECT pos_name FROM ".TB_PREF."sales_pos WHERE id=".db_escape($id); $result = db_query($sql, "could not get POS name"); @@ -65,7 +66,7 @@ function get_sales_point_name($id) function delete_sales_point($id) { - $sql="DELETE FROM ".TB_PREF."sales_pos WHERE id=$id"; + $sql="DELETE FROM ".TB_PREF."sales_pos WHERE id=".db_escape($id); db_query($sql,"The point of sale record could not be deleted"); }