Sealing against XSS atacks: purchasing,sales,install,admin,taxes
[fa-stable.git] / sales / manage / customer_branches.php
1 <?php
2
3 $page_security = 3;
4 $path_to_root="../..";
5 include($path_to_root . "/includes/session.inc");
6
7 page(_("Customer Branches"));
8
9 include($path_to_root . "/includes/ui.inc");
10
11 //-----------------------------------------------------------------------------------------------
12
13 check_db_has_customers(_("There are no customers defined in the system. Please define a customer to add customer branches."));
14
15 check_db_has_sales_people(_("There are no sales people defined in the system. At least one sales person is required before proceeding."));
16
17 check_db_has_sales_areas(_("There are no sales areas defined in the system. At least one sales area is required before proceeding."));
18
19 check_db_has_shippers(_("There are no shipping companies defined in the system. At least one shipping company is required before proceeding."));
20
21 check_db_has_tax_groups(_("There are no tax groups defined in the system. At least one tax group is required before proceeding."));
22
23 //-----------------------------------------------------------------------------------------------
24
25 if (isset($_GET['debtor_no'])) 
26 {
27         $_POST['customer_id'] = strtoupper($_GET['debtor_no']);
28         $_POST['New'] = "1";
29 }
30
31 if (isset($_GET['SelectedBranch']))
32 {
33         $_POST['branch_code'] = strtoupper($_GET['SelectedBranch']);
34         unset($_POST['New']);
35 }
36
37 if (!isset($_GET['SelectedBranch']) && !isset($_POST['AddUpdate'])) 
38 {
39         $_POST['New'] = "1";
40 }
41
42 //-----------------------------------------------------------------------------------------------
43
44 if (isset($_POST['ADD_ITEM']) || isset($_POST['UPDATE_ITEM'])) 
45 {
46
47         //initialise no input errors assumed initially before we test
48         $input_error = 0;
49
50         //first off validate inputs sensible
51
52         if (strlen($_POST['br_name']) == 0) 
53         {
54                 $input_error = 1;
55                 display_error(_("The Branch name cannot be empty."));
56         }
57
58         if ($input_error != 1) 
59         {
60
61                 //if (!isset($_POST['New']))
62                 if (isset($_POST['UPDATE_ITEM']))
63                 {
64                         /*SelectedBranch could also exist if submit had not been clicked this code would not run in this case cos submit is false of course see the     delete code below*/
65
66                         $sql = "UPDATE ".TB_PREF."cust_branch SET br_name = " . db_escape($_POST['br_name']) . ",
67                                 br_address = ".db_escape($_POST['br_address']). ",
68                 phone=".db_escape($_POST['phone']). ",
69                 fax=".db_escape($_POST['fax']).",
70                 contact_name=".db_escape($_POST['contact_name']) . ",
71                 salesman= ".db_escape($_POST['salesman']) . ",
72                 area=".db_escape($_POST['area']) . ",
73                 email=".db_escape($_POST['email']) . ",
74                 tax_group_id=".db_escape($_POST['tax_group_id']). ",
75                                 sales_account=".db_escape($_POST['sales_account']) . ",
76                                 sales_discount_account=".db_escape($_POST['sales_discount_account']) . ",
77                                 receivables_account=".db_escape($_POST['receivables_account']) . ",
78                                 payment_discount_account=".db_escape($_POST['payment_discount_account']) . ",
79                 default_location=".db_escape($_POST['default_location']) . ",
80                 br_post_address =".db_escape($_POST['br_post_address']) . ",
81                 disable_trans=".db_escape($_POST['disable_trans']) . ",
82                 default_ship_via=".db_escape($_POST['default_ship_via']) . "
83                 WHERE branch_code =".db_escape($_POST['branch_code']) . "
84                 AND debtor_no=".db_escape($_POST['customer_id']);
85
86                 } 
87                 else
88                 {
89                         /*Selected branch is null cos no item selected on first time round so must be adding a  record must be submitting new entries in the new Customer Branches form */
90                         $sql = "INSERT INTO ".TB_PREF."cust_branch (debtor_no, br_name, br_address,
91                                 salesman, phone, fax,
92                                 contact_name, area, email, tax_group_id, sales_account, receivables_account, payment_discount_account, sales_discount_account, default_location,
93                                 br_post_address, disable_trans, default_ship_via)
94                                 VALUES (".db_escape($_POST['customer_id']). ",".db_escape($_POST['br_name']) . ", " 
95                                         .db_escape($_POST['br_address']) . ", ".db_escape($_POST['salesman']) . ", " 
96                                         .db_escape($_POST['phone']) . ", ".db_escape($_POST['fax']) . ","
97                                         .db_escape($_POST['contact_name']) . ", ".db_escape($_POST['area']) . "," 
98                                         .db_escape($_POST['email']) . ", ".db_escape($_POST['tax_group_id']) . ", " 
99                                         .db_escape($_POST['sales_account']) . ", " 
100                                         .db_escape($_POST['receivables_account']) . ", " 
101                                         .db_escape($_POST['payment_discount_account']) . ", " 
102                                         .db_escape($_POST['sales_discount_account']) . ", " 
103                                         .db_escape($_POST['default_location']) . ", " 
104                                         .db_escape($_POST['br_post_address']) . "," 
105                                         .db_escape($_POST['disable_trans']) . ", " 
106                                         .db_escape($_POST['default_ship_via']) . ")";
107                 }
108
109                 //run the sql from either of the above possibilites
110                 db_query($sql,"The branch record could not be inserted or updated");
111
112                 meta_forward($_SERVER['PHP_SELF'], "debtor_no=" . $_POST['customer_id']);
113         }
114
115
116 elseif (isset($_GET['delete'])) 
117 {
118         //the link to delete a selected record was clicked instead of the submit button
119
120         // PREVENT DELETES IF DEPENDENT RECORDS IN 'debtor_trans'
121
122         $sql= "SELECT COUNT(*) FROM ".TB_PREF."debtor_trans WHERE branch_code='" . $_POST['branch_code']. "' AND debtor_no = '" . $_POST['customer_id']. "'";
123         $result = db_query($sql,"could not query debtortrans");
124         $myrow = db_fetch_row($result);
125         if ($myrow[0] > 0) 
126         {
127                 display_error(_("Cannot delete this branch because customer transactions have been created to this branch."));
128
129         } 
130         else 
131         {
132                 $sql= "SELECT COUNT(*) FROM ".TB_PREF."sales_orders WHERE branch_code='" . $_POST['branch_code']. "' AND debtor_no = '" . $_POST['customer_id']. "'";
133                 $result = db_query($sql,"could not query sales orders");
134
135                 $myrow = db_fetch_row($result);
136                 if ($myrow[0] > 0) 
137                 {
138                         display_error(_("Cannot delete this branch because sales orders exist for it. Purge old sales orders first."));
139                 } 
140                 else 
141                 {
142                         $sql="DELETE FROM ".TB_PREF."cust_branch WHERE branch_code='" . $_POST['branch_code']. "' AND debtor_no='" . $_POST['customer_id']. "'";
143                         db_query($sql,"could not delete branch");
144                         meta_forward($_SERVER['PHP_SELF'], "debtor_no=" . $_POST['customer_id']);
145                 }
146         } //end ifs to test if the branch can be deleted
147 }
148
149 start_form();
150
151 echo "<center>" . _("Select a customer: ") . "&nbsp;&nbsp;";
152 customer_list('customer_id', null, false, true);
153 echo "</center><br><br>";
154
155 $num_branches = db_customer_has_branches($_POST['customer_id']);
156 if ($num_branches)
157 {
158         $sql = "SELECT ".TB_PREF."debtors_master.name, ".TB_PREF."cust_branch.*, ".TB_PREF."salesman.salesman_name,
159                 ".TB_PREF."areas.description, ".TB_PREF."tax_groups.name AS tax_group_name
160                 FROM ".TB_PREF."cust_branch, ".TB_PREF."debtors_master, ".TB_PREF."areas, ".TB_PREF."salesman, ".TB_PREF."tax_groups
161                 WHERE ".TB_PREF."cust_branch.debtor_no=".TB_PREF."debtors_master.debtor_no
162                 AND ".TB_PREF."cust_branch.tax_group_id=".TB_PREF."tax_groups.id
163                 AND ".TB_PREF."cust_branch.area=".TB_PREF."areas.area_code
164                 AND ".TB_PREF."cust_branch.salesman=".TB_PREF."salesman.salesman_code
165                 AND ".TB_PREF."cust_branch.debtor_no = '" . $_POST['customer_id']. "'";
166
167         $result = db_query($sql,"could not get customer branches");
168
169         start_table("$table_style width=60%");
170
171         $th = array(_("Name"), _("Contact"), _("Sales Person"), _("Area"),
172                 _("Phone No"), _("Fax No"), _("E-mail"), _("Tax Group"), "", "");
173         table_header($th);      
174
175         while ($myrow = db_fetch($result))
176         {
177                 start_row();
178                 label_cell($myrow["br_name"]);
179                 label_cell($myrow["contact_name"]);
180                 label_cell($myrow["salesman_name"]);
181                 label_cell($myrow["description"]);
182                 label_cell($myrow["phone"]);
183                 label_cell($myrow["fax"]);
184                 label_cell("<a href=mailto:" . $myrow["email"]. ">" . $myrow["email"]. "</a>");
185                 label_cell($myrow["tax_group_name"]);
186                 edit_link_cell("debtor_no=" . $_POST['customer_id']. "&SelectedBranch=" . $myrow["branch_code"]);
187                 delete_link_cell("debtor_no=" . $_POST['customer_id']. "&SelectedBranch=" . $myrow["branch_code"]. "&delete=yes");
188                 end_row();
189         } 
190         end_table();
191         //END WHILE LIST LOOP
192 }
193 else
194         display_note(_("The selected customer does not have any branches. Please create at least one branch."));
195 //else
196 //{
197 //}     
198
199
200 if (!isset($_POST['New'])) 
201 {
202         hyperlink_params($_SERVER['PHP_SELF'], _("New Customer Branch"), "debtor_no=" . $_POST['customer_id']);
203 }
204 echo "<br>";
205 start_table("$table_style2 width=60%", 5);
206 echo "<tr valign=top><td>"; // outer table
207
208 echo "<table>";
209
210
211 if (!isset($_POST['New']) && $num_branches) 
212 {
213
214         //editing an existing branch
215     $sql = "SELECT * FROM ".TB_PREF."cust_branch
216                 WHERE branch_code='" . $_POST['branch_code'] . "'
217                 AND debtor_no='" . $_POST['customer_id'] . "'";
218
219         $result = db_query($sql,"check failed");
220     $myrow = db_fetch($result);
221
222     $_POST['branch_code'] = $myrow["branch_code"];
223     $_POST['br_name']  = $myrow["br_name"];
224     $_POST['br_address']  = $myrow["br_address"];
225     $_POST['br_post_address']  = $myrow["br_post_address"];
226     $_POST['contact_name'] = $myrow["contact_name"];
227     $_POST['salesman'] =$myrow["salesman"];
228     $_POST['area'] =$myrow["area"];
229     $_POST['phone'] =$myrow["phone"];
230     $_POST['fax'] =$myrow["fax"];
231     $_POST['email'] =$myrow["email"];
232     $_POST['tax_group_id'] = $myrow["tax_group_id"];
233     $_POST['disable_trans'] = $myrow['disable_trans'];
234     $_POST['default_location'] = $myrow["default_location"];
235     $_POST['default_ship_via'] = $myrow['default_ship_via'];
236     $_POST['sales_account'] = $myrow["sales_account"];
237     $_POST['sales_discount_account'] = $myrow['sales_discount_account'];
238     $_POST['receivables_account'] = $myrow['receivables_account'];
239     $_POST['payment_discount_account'] = $myrow['payment_discount_account'];
240
241
242 else 
243 { //end of if $SelectedBranch only do the else when a new record is being entered
244
245         $sql = "SELECT name, address, email
246                 FROM ".TB_PREF."debtors_master WHERE debtor_no = '" . $_POST['customer_id']. "'";
247         $result = db_query($sql,"check failed");
248         $myrow = db_fetch($result);
249         $_POST['br_name'] = $myrow["name"];
250         $_POST['contact_name'] = _("Main Branch");
251         $_POST['br_address'] = $_POST['br_post_address'] = $myrow["address"];
252         $_POST['branch_code'] = "";
253         $_POST['email'] = $myrow['email'];
254         if (!isset($_POST['sales_account']) || !isset($_POST['sales_discount_account'])) 
255         {
256                 $company_record = get_company_prefs();
257
258             $_POST['sales_account'] = $company_record["default_sales_act"];
259             $_POST['sales_discount_account'] = $company_record['default_sales_discount_act'];
260             $_POST['receivables_account'] = $company_record['debtors_act'];
261             $_POST['payment_discount_account'] = $company_record['default_prompt_payment_act'];
262
263         }
264
265         hidden('New', 'Yes');
266 }
267 hidden('branch_code', $_POST['branch_code']);
268
269 table_section_title(_("Name and Contact"));
270
271 text_row(_("Branch Name:"), 'br_name', $_POST['br_name'], 35, 40);
272 text_row(_("Contact Person:"), 'contact_name', $_POST['contact_name'], 35, 40);
273
274 text_row(_("Phone Number:"), 'phone', null, 20, 20);
275 text_row(_("Fax Number:"), 'fax', null, 20, 20);
276
277 text_row("<a href='Mailto:'>" . _("E-mail:") . "</a>", 'email', $_POST['email'], 35, 55);
278
279 table_section_title(_("Sales"));
280
281 sales_persons_list_row( _("Sales Person:"), 'salesman', null);
282
283 sales_areas_list_row( _("Sales Area:"), 'area', null);
284
285 locations_list_row(_("Default Inventory Location:"), 'default_location', null);
286
287 shippers_list_row(_("Default Shipping Company:"), 'default_ship_via', null);
288
289 tax_groups_list_row(_("Tax Group:"), 'tax_group_id', null, 31, 30);
290
291 yesno_list_row(_("Disable this Branch:"), 'disable_trans', null);
292
293 echo "</table>";
294
295 echo "</td><td  class='tableseparator'>"; // outer table
296
297 echo"<table>";
298
299 table_section_title(_("GL Accounts"));
300
301 gl_all_accounts_list_row(_("Sales Account:"), 'sales_account', $_POST['sales_account']);
302
303 gl_all_accounts_list_row(_("Sales Discount Account:"), 'sales_discount_account', $_POST['sales_discount_account']);
304
305 gl_all_accounts_list_row(_("Accounts Receivable Account:"), 'receivables_account', $_POST['receivables_account']);
306
307 gl_all_accounts_list_row(_("Prompt Payment Discount Account:"), 'payment_discount_account', $_POST['payment_discount_account']);
308
309 table_section_title(_("Addresses"));
310
311 textarea_row(_("Mailing Address:"), 'br_post_address',$_POST['br_post_address'], 35, 5);
312
313 textarea_row(_("Billing Address:"), 'br_address', $_POST['br_address'], 35, 5);
314
315 end_table();
316
317 end_table(1); // outer table
318
319 submit_add_or_update_center(isset($_POST['New']));
320
321 end_form();
322
323 end_page();
324
325 ?>