From 72d4bc7d84822e975db2b2316ca0e83d1a2d0c52 Mon Sep 17 00:00:00 2001 From: Dany De Bontridder Date: Wed, 31 Dec 2008 15:19:46 +0000 Subject: [PATCH] Bug : fiche.inc.php protect against CS Bug : add the synchro of attributes Bug : fix order problem of the attribute Cosmetic : move the columns saldo of the card to the end of the table Improve : create_doc doesn't create the doc for postgresql --- doc/developper/create_doc.sh | 3 +- html/admin/sql/patch/upgrade54.sql | 52 ++++++++++++++++++++++++++++++ include/class_fiche_def.php | 13 ++++++-- include/constant.php | 2 +- include/fiche.inc.php | 2 +- include/impress_fiche.inc.php | 14 ++++---- 6 files changed, 75 insertions(+), 11 deletions(-) create mode 100644 html/admin/sql/patch/upgrade54.sql diff --git a/doc/developper/create_doc.sh b/doc/developper/create_doc.sh index 708d1eeed..3f4601e47 100755 --- a/doc/developper/create_doc.sh +++ b/doc/developper/create_doc.sh @@ -1,7 +1,8 @@ doxygen cd html; sed -i "s/utf-8/utf-8/g" * +cd .. if [ ! -z "$PGUSER" ] ; then postgresql_autodoc -u $PGUSER --password $PGPASSWORD -h localhost -d mod1 postgresql_autodoc -u $PGUSER --password $PGPASSWORD -h localhost -d account_repository fi -cd ../../../ && dev/compose_list.sh +cd ../../ && dev/compose_list.sh diff --git a/html/admin/sql/patch/upgrade54.sql b/html/admin/sql/patch/upgrade54.sql new file mode 100644 index 000000000..ece0035e2 --- /dev/null +++ b/html/admin/sql/patch/upgrade54.sql @@ -0,0 +1,52 @@ +begin; +create or replace function fiche_attribut_synchro (p_fd_id fiche_def.fd_id%TYPE) returns void as +$BODY$ +declare + -- this sql gives the f_id and the missing attribute (ad_id) + list_missing cursor for select f_id,fd_id,ad_id,jnt_order from jnt_fic_attr join fiche as A using (fd_id) where fd_id=p_fd_id and ad_id not in (select ad_id from fiche join jnt_fic_att_value using (f_id) where fd_id=jnt_fic_attr.fd_id and A.f_id=f_id); + rec record; + -- value of the last insert + jnt jnt_fic_att_value%ROWTYPE; +begin + open list_missing; + loop + + fetch list_missing into rec; + IF NOT FOUND then + exit; + end if; + -- insert a value into jnt_fic_att_value + insert into jnt_fic_att_value (f_id,ad_id) values (rec.f_id,rec.ad_id) returning * into jnt; + + -- now we insert into attr_value + insert into attr_value values (jnt.jft_id,''); + end loop; + close list_missing; +end; +$BODY$ language plpgsql; + +create or replace function attribute_correct_order () returns void as +$BODY$ +declare + crs_correct cursor for select A.jnt_id,A.jnt_order from jnt_fic_attr as A join jnt_fic_attr as B using (fd_id) where A.jnt_order=B.jnt_order and A.jnt_id > B.jnt_id; + rec record; +begin + open crs_correct; + loop + fetch crs_correct into rec; + if NOT FOUND then + close crs_correct; + return; + end if; + update jnt_fic_attr set jnt_order=jnt_order + 1 where jnt_id = rec.jnt_id; + end loop; + close crs_correct; + perform attribute_correct_order (); +end; +$BODY$ language plpgsql; + +select fiche_attribut_synchro(fd_id) from fiche_def; +select attribute_correct_order(); +update version set val=55; + +commit; \ No newline at end of file diff --git a/include/class_fiche_def.php b/include/class_fiche_def.php index bedbfad04..ff39a8649 100644 --- a/include/class_fiche_def.php +++ b/include/class_fiche_def.php @@ -79,6 +79,9 @@ class fiche_def { function Get() { if ( $this->id == 0 ) return 0; + ExecSqlParam($this->cn,'select fiche_attribut_synchro($1)', + array($this->id)); + $sql="select * from fiche_def ". " where fd_id=".$this->id; $Ret=ExecSql($this->cn,$sql); @@ -350,8 +353,8 @@ class fiche_def { $span_mod=''.$l_line['quick_code'].''; - echo $span_mod.''.$l_line['vw_name'].""; - echo ''; + echo $span_mod.''.h($l_line['vw_name']).""; + echo ''; } echo ''; echo '
'; @@ -370,6 +373,9 @@ class fiche_def { echo_debug("class_fiche_def",__LINE__,"DisplayAttribut"); if ( $this->id == 0 ) return ; + ExecSqlParam($this->cn,'select fiche_attribut_synchro($1)', + array($this->id)); + $MaxLine=sizeof($this->attribut); echo_debug("class_fiche_def",__LINE__,"MaxLine = ".$MaxLine); $r=""; @@ -517,7 +523,10 @@ class fiche_def { ExecSqlParam($this->cn,$sql,array(${'jnt_order'.$row->ad_id}, $this->id, $row->ad_id)); + } + /* correct the order */ + ExecSql($this->cn,'select attribute_correct_order()'); } diff --git a/include/constant.php b/include/constant.php index 2b5d9901c..a4d26e9f8 100644 --- a/include/constant.php +++ b/include/constant.php @@ -25,7 +25,7 @@ */ require_once ('config.inc.php'); -define ("DBVERSION",54); +define ("DBVERSION",55); define ("MAX_COMPTE",4); define ('MAX_BUD_DETAIL',20); diff --git a/include/fiche.inc.php b/include/fiche.inc.php index 106a47d98..5663e8bb5 100644 --- a/include/fiche.inc.php +++ b/include/fiche.inc.php @@ -74,7 +74,7 @@ function ShowFicheDefInput($p_fiche_def) $p_fiche_def->GetAttribut(); if (isset ($_REQUEST['label']) ) $p_fiche_def->SaveLabel($_REQUEST['label']); - $r.= '

'.$p_fiche_def->label.'

'; + $r.= '

'.h($p_fiche_def->label).'

'; $r.= ''; $r.=dossier::hidden(); diff --git a/include/impress_fiche.inc.php b/include/impress_fiche.inc.php index 752012944..696bf256a 100644 --- a/include/impress_fiche.inc.php +++ b/include/impress_fiche.inc.php @@ -89,17 +89,18 @@ if ( isset ($_REQUEST['fd_id'])) { echo "
"; echo ""; $fiche_def->GetAttribut(); + $r=''; foreach ($fiche_def->attribut as $attribut) { echo ""; // si solde demandé affiche la col //-- if ($attribut->ad_id==ATTR_DEF_ACCOUNT && $with_amount==true) { - echo ""; - echo ""; - echo ""; + $r=''; } } + echo $r; + echo ""; $e=$fiche_def->GetByType($fiche_def->id); @@ -120,12 +121,13 @@ if ( isset ($_REQUEST['fd_id'])) { $sql_periode=sql_filter_per($cn,$_REQUEST['from_periode'],$_REQUEST['to_periode'],'p_id','j_tech_per'); $solde= $detail->get_solde_detail($sql_periode); - printf ("",$solde['debit']); - printf ("",$solde['credit']); - printf ("",$solde['solde']); } } + printf ("",$solde['debit']); + printf ("",$solde['credit']); + printf ("",$solde['solde']); + } echo ""; }
".$attribut->ad_text."DébitCréditSoldeDébitCréditSolde
% 10.2f% 10.2f% 10.2f% 10.2f% 10.2f% 10.2f