if (check_valid_entries()==true)
{
$trans_ref = false;
- $sql = get_sql_for_view_transactions($_POST['filterType'], $_POST['FromTransNo'], $_POST['ToTransNo'], $trans_ref);
+ $sql = get_sql_for_view_transactions(get_post('filterType'), get_post('FromTransNo'), get_post('ToTransNo'), $trans_ref);
if ($sql == "")
return;
- $print_type = $_POST['filterType'];
+ $print_type = get_post('filterType');
$print_out = ($print_type == ST_SALESINVOICE || $print_type == ST_CUSTCREDIT || $print_type == ST_CUSTDELIVERY ||
$print_type == ST_PURCHORDER || $print_type == ST_SALESORDER || $print_type == ST_SALESQUOTE ||
$print_type == ST_CUSTPAYMENT || $print_type == ST_SUPPAYMENT || $print_type == ST_WORKORDER);
end_table(1);
$trans_ref = false;
- $sql = get_sql_for_view_transactions($_POST['filterType'], $_POST['FromTransNo'], $_POST['ToTransNo'], $trans_ref);
+ $sql = get_sql_for_view_transactions(get_post('filterType'), get_post('FromTransNo'), get_post('ToTransNo'), $trans_ref);
if ($sql == "")
return;
}
$sql = get_sql_for_search_dimensions($dim, $_POST['FromDate'], $_POST['ToDate'],
- $_POST['OrderNumber'], $_POST['type_'], $_POST['OpenOnly'], $_POST['OverdueOnly']);
+ $_POST['OrderNumber'], $_POST['type_'], check_value('OpenOnly'), check_value('OverdueOnly'));
$cols = array(
_("#") => array('fun'=>'view_link'),
if (!isset($_POST['bank_account']))
$_POST['bank_account'] = "";
-$sql = get_sql_for_bank_account_reconcile($_POST['bank_account'], get_post('reconcile_date'));
+$sql = get_sql_for_bank_account_reconcile(get_post('bank_account'), get_post('reconcile_date'));
$act = get_bank_account($_POST["bank_account"]);
display_heading($act['bank_account_name']." - ".$act['bank_curr_code']);
$selected_id = "";
}
-set_global_curr_code($_POST['curr_abrev']);
+set_global_curr_code(get_post('curr_abrev'));
-$sql = get_sql_for_exchange_rates($_POST['curr_abrev']);
+$sql = get_sql_for_exchange_rates(get_post('curr_abrev'));
$cols = array(
_("Date to Use From") => 'date',
);
$table =& new_db_pager('orders_tbl', $sql, $cols);
-if (is_company_currency($_POST['curr_abrev']))
+if (is_company_currency(get_post('curr_abrev')))
{
display_note(_("The selected currency is the company currency."), 2);
$sql .= " AND workorder.wo_ref LIKE ".db_escape('%'.$order.'%');
}
- if ($stock_id != '')
+ if ($stock_id != ALL_TEXT)
{
$sql .= " AND workorder.stock_id=".db_escape($stock_id);
}
"/manufacturing/manage/bom_edit.php?stock_id=" . $row["parent"]);
}
-$sql = get_sql_for_where_used($_POST['stock_id']);
+$sql = get_sql_for_where_used(get_post('stock_id'));
$cols = array(
_("Parent Item") => array('fun'=>'select_link'),
return number_format2($amount, $row['decimals']);
}
-$sql = get_sql_for_work_orders($outstanding_only, $_POST['SelectedStockItem'], $_POST['StockLocation'],
- $_POST['OrderNumber'], check_value('OverdueOnly'));
+$sql = get_sql_for_work_orders($outstanding_only, get_post('SelectedStockItem'), get_post('StockLocation'), get_post('OrderNumber'),
+ check_value('OverdueOnly'));
$cols = array(
_("#") => array('fun'=>'view_link', 'ord'=>''),
function get_sql_for_po_search_completed($from, $to, $supplier_id=ALL_TEXT, $location=ALL_TEXT,
$order_number = '', $stock_id = '')
{
-
$sql = "SELECT
porder.order_no,
porder.reference,
if ($supplier_id != ALL_TEXT)
$sql .= "AND supplier.supplier_id=".$supplier_id." ";
- if (isset($order_number) && $order_number != "")
+ if ($order_number != "")
{
$sql .= "AND porder.reference LIKE ".db_escape('%'. $order_number . '%');
}
{
$sql .= " AND porder.into_stock_location = ".db_escape($location);
}
- if (isset($selected_stock_item))
+ if ($stock_id !== '')
{
$sql .= " AND line.item_code=".db_escape($stock_id);
}
return $sql;
}
-function get_sql_for_po_search($from, $to, $supplier_id=ALL_TEXT, $location=ALL_TEXT)
+function get_sql_for_po_search($from, $to, $supplier_id=ALL_TEXT, $location=ALL_TEXT, $order_number='', $stock_id='')
{
- global $all_items, $order_number, $selected_stock_item;;
-
$sql = "SELECT
porder.order_no,
porder.reference,
AND location.loc_code = porder.into_stock_location
AND (line.quantity_ordered > line.quantity_received) ";
- if (isset($order_number) && $order_number != "")
+ if ($order_number != "")
{
$sql .= "AND porder.reference LIKE ".db_escape('%'. $order_number . '%');
}
$sql .= " AND porder.into_stock_location = ".db_escape($location);
}
- if (isset($selected_stock_item))
+ if ($stock_id != '')
{
- $sql .= " AND line.item_code=".db_escape($selected_stock_item);
+ $sql .= " AND line.item_code=".db_escape($stock_id);
}
if ($supplier_id != ALL_TEXT)
$sql .= " AND supplier.supplier_id=".db_escape($supplier_id);
}
//---------------------------------------------------------------------------------------------
-if (isset($_POST['order_number']) && ($_POST['order_number'] != ""))
-{
- $order_number = $_POST['order_number'];
-}
-
//figure out the sql required from the inputs available
-$sql = get_sql_for_po_search($_POST['OrdersAfterDate'], $_POST['OrdersToDate'], $_POST['supplier_id'],
- $_POST['StockLocation']);
+$sql = get_sql_for_po_search(get_post('OrdersAfterDate'), get_post('OrdersToDate'), get_post('supplier_id'), get_post('StockLocation'),
+ $_POST['order_number'], get_post('SelectStockFromList'));
//$result = db_query($sql,"No orders were returned");
if (isset($_GET['order_number']))
{
- $order_number = $_GET['order_number'];
+ $_POST['order_number'] = $_GET['order_number'];
}
//-----------------------------------------------------------------------------------
//---------------------------------------------------------------------------------------------
$sql = get_sql_for_po_search_completed(get_post('OrdersAfterDate'), get_post('OrdersToDate'),
- get_post('supplier_id') !== '' ? get_post('supplier_id') : ALL_TEXT,
- get_post('StockLocation'), get_post('order_number'), get_post('SelectStockFromList'));
+ get_post('supplier_id'), get_post('StockLocation'), get_post('order_number'), get_post('SelectStockFromList'));
$cols = array(
_("#") => array('fun'=>'trans_view', 'ord'=>''),
}
//------------------------------------------------------------------------------------------------
-$sql = get_sql_for_supplier_allocation_inquiry($_POST['TransAfterDate'],$_POST['TransToDate'],
- $_POST['filterType'], $_POST['supplier_id'], check_value('showSettled'));
+$sql = get_sql_for_supplier_allocation_inquiry(get_post('TransAfterDate'),get_post('TransToDate'),
+ get_post('filterType'), get_post('supplier_id'), check_value('showSettled'));
$cols = array(
_("Type") => array('fun'=>'systype_name'),
}
//------------------------------------------------------------------------------------------------
-$sql = get_sql_for_supplier_inquiry($_POST['filterType'], $_POST['TransAfterDate'], $_POST['TransToDate'], $_POST['supplier_id']);
+$sql = get_sql_for_supplier_inquiry(get_post('filterType'), get_post('TransAfterDate'), get_post('TransToDate'), get_post('supplier_id'));
$cols = array(
_("Type") => array('fun'=>'systype_name', 'ord'=>''),
//figure out the sql required from the inputs available
if ($delivery)
{
- $sql .= " AND trans.trans_no LIKE %".db_escape($delivery);
+ $sql .= " AND trans.trans_no LIKE ".db_escape('%' . $delivery . '%');
$sql .= " GROUP BY trans.trans_no";
}
else
$sql .= " AND trans.tran_date >= '".date2sql($from)."'";
$sql .= " AND trans.tran_date <= '".date2sql($to)."'";
- if ($stock_item)
+ if ($stock_item != ALL_TEXT)
$sql .= " AND line.stock_id=".db_escape($stock_item)." ";
if ($location != ALL_TEXT)
PrepaidOrders
*/
function get_sql_for_sales_orders_view($trans_type, $trans_no, $filter,
- $stock_item=null, $from='', $to='', $ref='', $location='', $customer_id=ALL_TEXT)
+ $stock_item='', $from='', $to='', $ref='', $location=ALL_TEXT, $customer_id=ALL_TEXT)
{
$sql = "SELECT
elseif ($ref != "")
{
// search orders with reference like
- $number_like = "%".$ref."%";
- $sql .= " AND sorder.reference LIKE ".db_escape($number_like);
+ $sql .= " AND sorder.reference LIKE ".db_escape('%' . $ref . '%');
// ." GROUP BY sorder.order_no";
}
else // ... or select inquiry constraints
//if ($selected_customer != -1)
// $sql .= " AND sorder.debtor_no=".db_escape($selected_customer);
- if (isset($stock_item))
+ if ($stock_item != ALL_TEXT)
$sql .= " AND line.stk_code=".db_escape($stock_item);
- if ($location)
+ if ($location != ALL_TEXT)
$sql .= " AND sorder.from_stk_loc = ".db_escape($location);
if ($filter=='OutstandingOnly')
$row["Outstanding"]!=0;
}
//------------------------------------------------------------------------------------------------
-$sql = get_sql_for_sales_deliveries_view(get_post('DeliveryAfterDate'), get_post('DeliveryToDate'), get_post('customer_id'),
+$sql = get_sql_for_sales_deliveries_view(get_post('DeliveryAfterDate'), get_post('DeliveryToDate'), get_post('customer_id'),
get_post('SelectStockFromList'), get_post('StockLocation'), get_post('DeliveryNumber'), get_post('OutstandingOnly'));
$cols = array(
if (user_use_date_picker())
$js .= get_js_date_picker();
page($_SESSION['page_title'], false, false, "", $js);
-/*
-if (isset($_GET['selected_customer']))
-{
- $selected_customer = $_GET['selected_customer'];
-}
-elseif (isset($_POST['selected_customer']))
-{
- $selected_customer = $_POST['selected_customer'];
-}
-else
- $selected_customer = -1;
-*/
-//---------------------------------------------------------------------------------------------
-
-if (isset($_POST['SelectStockFromList']) && ($_POST['SelectStockFromList'] != "") &&
- ($_POST['SelectStockFromList'] != ALL_TEXT))
-{
- $selected_stock_item = $_POST['SelectStockFromList'];
-}
-else
-{
- unset($selected_stock_item);
-}
//---------------------------------------------------------------------------------------------
// Query format functions
//
//---------------------------------------------------------------------------------------------
// Orders inquiry table
//
-$sql = get_sql_for_sales_orders_view($trans_type, $_POST['OrderNumber'], $_POST['order_view_mode'],
- @$selected_stock_item, @$_POST['OrdersAfterDate'], @$_POST['OrdersToDate'], @$_POST['OrderReference'], $_POST['StockLocation'],
- get_post('customer_id') !== '' ? get_post('customer_id') : ALL_TEXT);
+$sql = get_sql_for_sales_orders_view($trans_type, get_post('OrderNumber'), get_post('order_view_mode'),
+ get_post('SelectStockFromList'), get_post('OrdersAfterDate'), get_post('OrdersToDate'), get_post('OrderReference'), get_post('StockLocation'),
+ get_post('customer_id'));
if ($trans_type == ST_SALESORDER)
$cols = array(