Security sql statements update against sql injection attacks.
[fa-stable.git] / reporting / rep108.php
1 <?php
2 /**********************************************************************
3     Copyright (C) FrontAccounting, LLC.
4         Released under the terms of the GNU General Public License, GPL, 
5         as published by the Free Software Foundation, either version 3 
6         of the License, or (at your option) any later version.
7     This program is distributed in the hope that it will be useful,
8     but WITHOUT ANY WARRANTY; without even the implied warranty of
9     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
10     See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
11 ***********************************************************************/
12 $page_security = 2;
13 // ----------------------------------------------------------------
14 // $ Revision:  2.0 $
15 // Creator:     Joe Hunt
16 // date_:       2005-05-19
17 // Title:       Print Statements
18 // ----------------------------------------------------------------
19 $path_to_root="..";
20
21 include_once($path_to_root . "/includes/session.inc");
22 include_once($path_to_root . "/includes/date_functions.inc");
23 include_once($path_to_root . "/includes/data_checks.inc");
24 include_once($path_to_root . "/sales/includes/sales_db.inc");
25
26 //----------------------------------------------------------------------------------------------------
27
28 print_statements();
29
30 //----------------------------------------------------------------------------------------------------
31
32 function getTransactions($debtorno, $date)
33 {
34     $sql = "SELECT ".TB_PREF."debtor_trans.*, ".TB_PREF."sys_types.type_name,
35                                 (".TB_PREF."debtor_trans.ov_amount + ".TB_PREF."debtor_trans.ov_gst + ".TB_PREF."debtor_trans.ov_freight + ".TB_PREF."debtor_trans.ov_discount)
36                                 AS TotalAmount, ".TB_PREF."debtor_trans.alloc AS Allocated,
37                                 ((".TB_PREF."debtor_trans.type = 10)
38                                         AND ".TB_PREF."debtor_trans.due_date < '$date') AS OverDue
39                         FROM ".TB_PREF."debtor_trans, ".TB_PREF."sys_types
40                         WHERE ".TB_PREF."debtor_trans.tran_date <= '$date' AND ".TB_PREF."debtor_trans.debtor_no = $debtorno
41                                 AND ".TB_PREF."debtor_trans.type = ".TB_PREF."sys_types.type_id
42                                 AND ".TB_PREF."debtor_trans.type <> 13
43                                 ORDER BY ".TB_PREF."debtor_trans.tran_date";
44
45     return db_query($sql,"No transactions were returned");
46 }
47
48 //----------------------------------------------------------------------------------------------------
49
50 function print_statements()
51 {
52         global $path_to_root;
53
54         include_once($path_to_root . "/reporting/includes/pdf_report.inc");
55
56         $customer = $_POST['PARAM_0'];
57         $currency = $_POST['PARAM_1'];
58         $bankaccount = $_POST['PARAM_2'];
59         $email = $_POST['PARAM_3'];
60         $comments = $_POST['PARAM_4'];
61
62         $dec = user_price_dec();
63
64         $cols = array(4, 100, 130, 190, 250, 320, 385, 450, 515);
65
66         //$headers in doctext.inc
67
68         $aligns = array('left', 'left', 'left', 'left', 'right', 'right', 'right', 'right');
69
70         $params = array('comments' => $comments,
71                                         'bankaccount' => $bankaccount);
72
73         $baccount = get_bank_account($params['bankaccount']);
74
75         $cur = get_company_pref('curr_default');
76         $PastDueDays1 = get_company_pref('past_due_days');
77         $PastDueDays2 = 2 * $PastDueDays1;
78
79         if ($email == 0)
80         {
81                 $rep = new FrontReport(_('STATEMENT'), "StatementBulk", user_pagesize());
82                 $rep->currency = $cur;
83                 $rep->Font();
84                 $rep->Info($params, $cols, null, $aligns);
85         }
86
87         $sql = "SELECT debtor_no, name AS DebtorName, address, tax_id, email, curr_code, curdate() AS tran_date, payment_terms FROM ".TB_PREF."debtors_master";
88         if ($customer != reserved_words::get_all_numeric())
89                 $sql .= " WHERE debtor_no = ".db_escape($customer);
90         else
91                 $sql .= " ORDER by name";
92         $result = db_query($sql, "The customers could not be retrieved");
93
94         while ($myrow=db_fetch($result))
95         {
96                 $date = date('Y-m-d');
97
98                 $myrow['order_'] = "";
99
100                 $TransResult = getTransactions($myrow['debtor_no'], $date);
101                 if (db_num_rows($TransResult) == 0)
102                         continue;
103                 if ($email == 1)
104                 {
105                         $rep = new FrontReport("", "", user_pagesize());
106                         $rep->currency = $cur;
107                         $rep->Font();
108                         $rep->title = _('STATEMENT');
109                         $rep->filename = "Statement" . $myrow['debtor_no'] . ".pdf";
110                         $rep->Info($params, $cols, null, $aligns);
111                 }
112                 $rep->Header2($myrow, null, null, $baccount, 12);
113                 $rep->NewLine();
114                 $linetype = true;
115                 $doctype = 12;
116                 if ($rep->currency != $myrow['curr_code'])
117                 {
118                         include($path_to_root . "/reporting/includes/doctext2.inc");
119                 }
120                 else
121                 {
122                         include($path_to_root . "/reporting/includes/doctext.inc");
123                 }
124                 $rep->fontSize += 2;
125                 $rep->TextCol(0, 8, $doc_Outstanding);
126                 $rep->fontSize -= 2;
127                 $rep->NewLine(2);
128                 while ($myrow2=db_fetch($TransResult))
129                 {
130                         $DisplayTotal = number_format2(Abs($myrow2["TotalAmount"]),$dec);
131                         $DisplayAlloc = number_format2($myrow2["Allocated"],$dec);
132                         $DisplayNet = number_format2($myrow2["TotalAmount"] - $myrow2["Allocated"],$dec);
133
134                         $rep->TextCol(0, 1,     $myrow2['type_name'], -2);
135                         $rep->TextCol(1, 2,     $myrow2['reference'], -2);
136                         $rep->TextCol(2, 3,     sql2date($myrow2['tran_date']), -2);
137                         if ($myrow2['type'] == 10)
138                                 $rep->TextCol(3, 4,     sql2date($myrow2['due_date']), -2);
139                         if ($myrow2['type'] == 10)
140                                 $rep->TextCol(4, 5,     $DisplayTotal, -2);
141                         else
142                                 $rep->TextCol(5, 6,     $DisplayTotal, -2);
143                         $rep->TextCol(6, 7,     $DisplayAlloc, -2);
144                         $rep->TextCol(7, 8,     $DisplayNet, -2);
145                         $rep->NewLine();
146                         if ($rep->row < $rep->bottomMargin + (10 * $rep->lineHeight))
147                                 $rep->Header2($myrow, null, null, $baccount, 12);
148                 }
149                 $nowdue = "1-" . $PastDueDays1 . " " . $doc_Days;
150                 $pastdue1 = $PastDueDays1 + 1 . "-" . $PastDueDays2 . " " . $doc_Days;
151                 $pastdue2 = $doc_Over . " " . $PastDueDays2 . " " . $doc_Days;
152                 $CustomerRecord = get_customer_details($myrow['debtor_no']);
153                 $str = array($doc_Current, $nowdue, $pastdue1, $pastdue2, $doc_Total_Balance);
154                 $str2 = array(number_format2(($CustomerRecord["Balance"] - $CustomerRecord["Due"]),$dec),
155                         number_format2(($CustomerRecord["Due"]-$CustomerRecord["Overdue1"]),$dec),
156                         number_format2(($CustomerRecord["Overdue1"]-$CustomerRecord["Overdue2"]) ,$dec),
157                         number_format2($CustomerRecord["Overdue2"],$dec),
158                         number_format2($CustomerRecord["Balance"],$dec));
159                 $col = array($rep->cols[0], $rep->cols[0] + 110, $rep->cols[0] + 210, $rep->cols[0] + 310,
160                         $rep->cols[0] + 410, $rep->cols[0] + 510);
161                 $rep->row = $rep->bottomMargin + (8 * $rep->lineHeight - 6);
162                 for ($i = 0; $i < 5; $i++)
163                         $rep->TextWrap($col[$i], $rep->row, $col[$i + 1] - $col[$i], $str[$i], 'right');
164                 $rep->NewLine();
165                 for ($i = 0; $i < 5; $i++)
166                         $rep->TextWrap($col[$i], $rep->row, $col[$i + 1] - $col[$i], $str2[$i], 'right');
167                 if ($email == 1)
168                         $rep->End($email, $doc_Statement . " " . $doc_as_of . " " . sql2date($date), $myrow, 12);
169
170         }
171         if ($email == 0)
172                 $rep->End();
173 }
174
175 ?>