Security sql statements update against sql injection attacks.
[fa-stable.git] / sales / inquiry / sales_orders_view.php
1 <?php
2 /**********************************************************************
3     Copyright (C) FrontAccounting, LLC.
4         Released under the terms of the GNU General Public License, GPL, 
5         as published by the Free Software Foundation, either version 3 
6         of the License, or (at your option) any later version.
7     This program is distributed in the hope that it will be useful,
8     but WITHOUT ANY WARRANTY; without even the implied warranty of
9     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
10     See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
11 ***********************************************************************/
12 $page_security = 2;
13 $path_to_root="../..";
14
15 include($path_to_root . "/includes/db_pager.inc");
16 include($path_to_root . "/includes/session.inc");
17 include($path_to_root . "/sales/includes/sales_ui.inc");
18 include_once($path_to_root . "/reporting/includes/reporting.inc");
19
20 $js = "";
21 if ($use_popup_windows)
22         $js .= get_js_open_window(900, 600);
23 if ($use_date_picker)
24         $js .= get_js_date_picker();
25
26 if (isset($_GET['OutstandingOnly']) && ($_GET['OutstandingOnly'] == true))
27 {
28         $_POST['order_view_mode'] = 'OutstandingOnly';
29         $_SESSION['page_title'] = _("Search Outstanding Sales Orders");
30 }
31 elseif (isset($_GET['InvoiceTemplates']) && ($_GET['InvoiceTemplates'] == true))
32 {
33         $_POST['order_view_mode'] = 'InvoiceTemplates';
34         $_SESSION['page_title'] = _("Search Template for Invoicing");
35 }
36 elseif (isset($_GET['DeliveryTemplates']) && ($_GET['DeliveryTemplates'] == true))
37 {
38         $_POST['order_view_mode'] = 'DeliveryTemplates';
39         $_SESSION['page_title'] = _("Select Template for Delivery");
40 }
41 elseif (!isset($_POST['order_view_mode']))
42 {
43         $_POST['order_view_mode'] = false;
44         $_SESSION['page_title'] = _("Search All Sales Orders");
45 }
46
47 page($_SESSION['page_title'], false, false, "", $js);
48
49 if (isset($_GET['selected_customer']))
50 {
51         $selected_customer = $_GET['selected_customer'];
52 }
53 elseif (isset($_POST['selected_customer']))
54 {
55         $selected_customer = $_POST['selected_customer'];
56 }
57 else
58         $selected_customer = -1;
59
60 //---------------------------------------------------------------------------------------------
61
62 if (isset($_POST['SelectStockFromList']) && ($_POST['SelectStockFromList'] != "") &&
63         ($_POST['SelectStockFromList'] != reserved_words::get_all()))
64 {
65         $selected_stock_item = $_POST['SelectStockFromList'];
66 }
67 else
68 {
69         unset($selected_stock_item);
70 }
71 //---------------------------------------------------------------------------------------------
72 //      Query format functions
73 //
74 function check_overdue($row)
75 {
76         return ($row['type'] == 0
77                 && date1_greater_date2(Today(), sql2date($row['ord_date']))
78                 && ($row['TotDelivered'] < $row['TotQuantity']));
79 }
80
81 function view_link($dummy, $order_no)
82 {
83         return  get_customer_trans_view_str(systypes::sales_order(), $order_no);
84 }
85
86 function prt_link($row)
87 {
88         return print_document_link($row['order_no'], _("Print"), true, 30, ICON_PRINT);
89 }
90
91 function edit_link($row) 
92 {
93   return pager_link( _("Edit"),
94     "/sales/sales_order_entry.php?" . SID . "ModifyOrderNumber=" . $row['order_no'], ICON_EDIT);
95 }
96
97 function dispatch_link($row)
98 {
99   return pager_link( _("Dispatch"),
100         "/sales/customer_delivery.php?" . SID . "OrderNumber=" .$row['order_no'], ICON_DOC);
101 }
102
103 function invoice_link($row)
104 {
105   return pager_link( _("Invoice"),
106         "/sales/sales_order_entry.php?" . SID . "NewInvoice=" .$row["order_no"], ICON_DOC);
107 }
108
109 function delivery_link($row)
110 {
111   return pager_link( _("Delivery"),
112         "/sales/sales_order_entry.php?" . SID . "NewDelivery=" .$row['order_no'], ICON_DOC);
113 }
114
115 function tmpl_checkbox($row)
116 {
117         $name = "chgtpl" .$row['order_no'];
118         $value = $row['type'] ? 1:0;
119
120 // save also in hidden field for testing during 'Update'
121
122  return checkbox(null, $name, $value, true,
123         _('Set this order as a template for direct deliveries/invoices'))
124         . hidden('last['.$row['order_no'].']', $value, false);
125 }
126 //---------------------------------------------------------------------------------------------
127 // Update db record if respective checkbox value has changed.
128 //
129 function change_tpl_flag($id)
130 {
131         global  $Ajax;
132         
133         $sql = "UPDATE ".TB_PREF."sales_orders SET type = !type WHERE order_no=$id";
134
135         db_query($sql, "Can't change sales order type");
136         $Ajax->activate('orders_tbl');
137 }
138
139 $id = find_submit('_chgtpl');
140 if ($id != -1)
141         change_tpl_flag($id);
142
143 if (isset($_POST['Update']) && isset($_POST['last'])) {
144         foreach($_POST['last'] as $id => $value)
145                 if ($value != check_value('chgtpl'.$id))
146                         change_tpl_flag($id);
147 }
148
149 //---------------------------------------------------------------------------------------------
150 //      Order range form
151 //
152 if (get_post('_OrderNumber_changed')) // enable/disable selection controls
153 {
154         $disable = get_post('OrderNumber') !== '';
155
156         if ($_POST['order_view_mode']!='DeliveryTemplates' 
157                 && $_POST['order_view_mode']!='InvoiceTemplates') {
158                         $Ajax->addDisable(true, 'OrdersAfterDate', $disable);
159                         $Ajax->addDisable(true, 'OrdersToDate', $disable);
160         }
161         $Ajax->addDisable(true, 'StockLocation', $disable);
162         $Ajax->addDisable(true, '_SelectStockFromList_edit', $disable);
163         $Ajax->addDisable(true, 'SelectStockFromList', $disable);
164
165         if ($disable) {
166                 $Ajax->addFocus(true, 'OrderNumber');
167         } else
168                 $Ajax->addFocus(true, 'OrdersAfterDate');
169
170         $Ajax->activate('orders_tbl');
171 }
172
173 start_form(false, false, $_SERVER['PHP_SELF'] .SID);
174
175 start_table("class='tablestyle_noborder'");
176 start_row();
177 ref_cells(_("#:"), 'OrderNumber', '',null, '', true);
178 if ($_POST['order_view_mode'] != 'DeliveryTemplates' && $_POST['order_view_mode'] != 'InvoiceTemplates')
179 {
180         date_cells(_("from:"), 'OrdersAfterDate', '', null, -30);
181         date_cells(_("to:"), 'OrdersToDate', '', null, 1);
182 }
183 locations_list_cells(_("Location:"), 'StockLocation', null, true);
184
185 stock_items_list_cells(_("Item:"), 'SelectStockFromList', null, true);
186
187 submit_cells('SearchOrders', _("Search"),'',_('Select documents'), true);
188
189 hidden('order_view_mode', $_POST['order_view_mode']);
190
191 end_row();
192
193 end_table(1);
194 end_form();
195 //---------------------------------------------------------------------------------------------
196 //      Orders inquiry table
197 //
198 $sql = "SELECT 
199                 sorder.order_no,
200                 debtor.name,
201                 branch.br_name,"
202                 .($_POST['order_view_mode']=='InvoiceTemplates' 
203                         || $_POST['order_view_mode']=='DeliveryTemplates' ?
204                  "sorder.comments, " : "sorder.customer_ref, ")
205                 ."sorder.ord_date,
206                 sorder.delivery_date,
207                 sorder.deliver_to,
208                 Sum(line.unit_price*line.quantity*(1-line.discount_percent)) AS OrderValue,
209                 sorder.type,
210                 debtor.curr_code,
211                 Sum(line.qty_sent) AS TotDelivered,
212                 Sum(line.quantity) AS TotQuantity
213         FROM ".TB_PREF."sales_orders as sorder, "
214                 .TB_PREF."sales_order_details as line, "
215                 .TB_PREF."debtors_master as debtor, "
216                 .TB_PREF."cust_branch as branch
217                 WHERE sorder.order_no = line.order_no
218                 AND sorder.debtor_no = debtor.debtor_no
219                 AND sorder.branch_code = branch.branch_code
220                 AND debtor.debtor_no = branch.debtor_no";
221
222 if (isset($_POST['OrderNumber']) && $_POST['OrderNumber'] != "")
223 {
224         // search orders with number like 
225         $number_like = "%".$_POST['OrderNumber'];
226         $sql .= " AND sorder.order_no LIKE ".db_escape($number_like)
227                         ." GROUP BY sorder.order_no";
228 }
229 else    // ... or select inquiry constraints
230 {
231         if ($_POST['order_view_mode']!='DeliveryTemplates' && $_POST['order_view_mode']!='InvoiceTemplates')
232         {
233                 $date_after = date2sql($_POST['OrdersAfterDate']);
234                 $date_before = date2sql($_POST['OrdersToDate']);
235
236                 $sql .=  " AND sorder.ord_date >= '$date_after'"
237                                 ." AND sorder.ord_date <= '$date_before'";
238         }
239         if ($selected_customer != -1)
240                 $sql .= " AND sorder.debtor_no=".db_escape($selected_customer);
241
242         if (isset($selected_stock_item))
243                 $sql .= " AND line.stk_code=".db_escape($selected_stock_item);
244
245         if (isset($_POST['StockLocation']) && $_POST['StockLocation'] != reserved_words::get_all())
246                 $sql .= " AND sorder.from_stk_loc = ".db_escape($_POST['StockLocation'])." ";
247
248         if ($_POST['order_view_mode']=='OutstandingOnly')
249                 $sql .= " AND line.qty_sent < line.quantity";
250         elseif ($_POST['order_view_mode']=='InvoiceTemplates' || $_POST['order_view_mode']=='DeliveryTemplates')
251                 $sql .= " AND sorder.type=1";
252
253         $sql .= " GROUP BY sorder.order_no,
254                                 sorder.debtor_no,
255                                 sorder.branch_code,
256                                 sorder.customer_ref,
257                                 sorder.ord_date,
258                                 sorder.deliver_to";
259 }
260
261 $cols = array(
262         _("Order #") => array('fun'=>'view_link'),
263         _("Customer"),
264         _("Branch"), 
265         _("Cust Order Ref"),
266         _("Order Date") => 'date',
267         _("Required By") =>array('type'=>'date', 'ord'=>''),
268         _("Delivery To"), 
269         _("Order Total") => array('type'=>'amount', 'ord'=>''),
270         'Type' => 'skip',
271         _("Currency") => array('align'=>'center')
272 );
273
274 if ($_POST['order_view_mode'] == 'OutstandingOnly') {
275         //array_replace($cols, 3, 1, _("Cust Order Ref"));
276         array_append($cols, array(array('insert'=>true, 'fun'=>'dispatch_link')));
277
278 } elseif ($_POST['order_view_mode'] == 'InvoiceTemplates') {
279         array_replace($cols, 3, 1, _("Description"));
280         array_append($cols, array( array('insert'=>true, 'fun'=>'invoice_link')));
281
282 } else if ($_POST['order_view_mode'] == 'DeliveryTemplates') {
283         array_replace($cols, 3, 1, _("Description"));
284         array_append($cols, array(
285                         array('insert'=>true, 'fun'=>'delivery_link'))
286         );
287
288 } else {
289          array_append($cols,array(
290                         _("Tmpl") => array('insert'=>true, 'fun'=>'tmpl_checkbox'),
291                                         array('insert'=>true, 'fun'=>'edit_link'),
292                                         array('insert'=>true, 'fun'=>'prt_link')));
293 };
294
295
296 $table =& new_db_pager('orders_tbl', $sql, $cols);
297 $table->set_marker('check_overdue', _("Marked items are overdue."));
298
299 if (get_post('SearchOrders')) {
300         $table->set_sql($sql);
301         $table->set_columns($cols);
302 }
303 $table->width = "80%";
304 start_form();
305
306 display_db_pager($table);
307 submit_center('Update', _("Update"), true, '', null);
308
309 end_form();
310 end_page();
311 ?>