Merged revisions 2258,2260-2262,2264-2268,2270-2283,2285-2297,2299-2322,2324-2340 via svnmerge from

svn+ssh://danydb@svn/svn/phpcompta/branches/rel430

........
  r2258 | danydb | 2008-12-18 23:21:00 +0100 (Thu, 18 Dec 2008) | 1 line
  
  Add debug
........
  r2262 | danydb | 2008-12-19 22:38:25 +0100 (Fri, 19 Dec 2008) | 1 line
  
  Add a local admin 
........
  r2270 | danydb | 2008-12-21 20:11:26 +0100 (Sun, 21 Dec 2008) | 1 line
  
  Doc. remove the useless todo list
........
  r2271 | danydb | 2008-12-22 21:18:46 +0100 (Mon, 22 Dec 2008) | 3 lines
  
  Remove obsolete functions insertRapt, deleteRapt and getconcerned
  Remove obsolete file user_update
........
  r2272 | danydb | 2008-12-22 21:21:46 +0100 (Mon, 22 Dec 2008) | 2 lines
  
  Remove obsolete function isFicheOfJrn
........
  r2273 | danydb | 2008-12-22 21:44:28 +0100 (Mon, 22 Dec 2008) | 1 line
  
  Improve Invoice : add the username 
........
  r2287 | danydb | 2009-01-13 21:37:07 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning replace GetConcerned by Acc_Reconciliation
........
  r2288 | danydb | 2009-01-13 21:38:40 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Add a comment on jrn operation
........
  r2289 | danydb | 2009-01-13 21:40:13 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning : add comments to the code
........
  r2290 | danydb | 2009-01-13 21:40:46 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning replace GetConcerned by Acc_Reconciliation
........
  r2291 | danydb | 2009-01-13 21:41:35 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning replace GetConcerned by Acc_Reconciliation
........
  r2292 | danydb | 2009-01-13 21:42:15 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Add documentation about new tags
........
  r2293 | danydb | 2009-01-13 21:43:22 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning start rewriting of the security part 
........
  r2294 | danydb | 2009-01-14 20:09:18 +0100 (Wed, 14 Jan 2009) | 1 line
  
  Improve : template of security + security code
........
  r2295 | danydb | 2009-01-14 20:21:51 +0100 (Wed, 14 Jan 2009) | 1 line
  
  Improve security : add new variable
........
  r2296 | danydb | 2009-01-14 20:39:58 +0100 (Wed, 14 Jan 2009) | 1 line
  
  Improve security : modify layout
........
  r2297 | danydb | 2009-01-15 19:21:47 +0100 (Thu, 15 Jan 2009) | 1 line
  
  Improve security : user setting
........
  r2299 | danydb | 2009-01-15 19:28:56 +0100 (Thu, 15 Jan 2009) | 2 lines
  
  Clean code : can_request doens't have a connx parameter
........
  r2300 | danydb | 2009-01-16 19:12:47 +0100 (Fri, 16 Jan 2009) | 1 line
  
  Improve Ecriture directe libelle : new widget js_search_card_control
........
  r2301 | danydb | 2009-01-16 22:29:39 +0100 (Fri, 16 Jan 2009) | 1 line
  
  Improve Quick Writing : remove span, and update the comment field
........
  r2302 | danydb | 2009-01-16 23:01:24 +0100 (Fri, 16 Jan 2009) | 1 line
  
  Improve cosmetic : GL + remove the select topmenu
........
  r2303 | danydb | 2009-01-19 08:41:09 +0100 (Mon, 19 Jan 2009) | 1 line
  
  Cosmetic : a inline
........
  r2304 | danydb | 2009-01-20 23:03:59 +0100 (Tue, 20 Jan 2009) | 6 lines
  
  Code Cleaning
  Security : remove obsolete files & function
  Class_user : add new functions for the security
  Only the menu in text mode with a break line
........
  r2305 | danydb | 2009-01-20 23:05:01 +0100 (Tue, 20 Jan 2009) | 1 line
  
  code cleaning rewriting of Security 
........
  r2306 | danydb | 2009-01-21 21:13:15 +0100 (Wed, 21 Jan 2009) | 1 line
  
  Security printing unicode and fix some bugs
........
  r2309 | danydb | 2009-01-26 19:56:28 +0100 (Mon, 26 Jan 2009) | 1 line
  
  ADD : company without VAT
........
  r2310 | danydb | 2009-01-26 23:33:14 +0100 (Mon, 26 Jan 2009) | 1 line
  
  Add : no vat for Purchase ledger 
........
  r2312 | danydb | 2009-01-28 19:57:30 +0100 (Wed, 28 Jan 2009) | 1 line
  
  Integration 
........
  r2313 | danydb | 2009-01-28 22:46:27 +0100 (Wed, 28 Jan 2009) | 1 line
  
  Work with or without VAT
........
  r2314 | danydb | 2009-01-29 22:18:57 +0100 (Thu, 29 Jan 2009) | 2 lines
  
  Remove debug info
........
  r2315 | danydb | 2009-01-29 23:23:14 +0100 (Thu, 29 Jan 2009) | 1 line
  
  ADD the possibility to enter a piece number
........
  r2316 | danydb | 2009-01-31 23:20:00 +0100 (Sat, 31 Jan 2009) | 1 line
  
  Documentation
........
  r2317 | danydb | 2009-02-04 20:14:54 +0100 (Wed, 04 Feb 2009) | 1 line
  
  Template for ledger
........
  r2318 | danydb | 2009-02-05 15:52:58 +0100 (Thu, 05 Feb 2009) | 1 line
  
  Add PJ setting + default in Ledger, fix bug in listJrn
........
  r2319 | danydb | 2009-02-05 17:09:56 +0100 (Thu, 05 Feb 2009) | 2 lines
  
  Search by PJ
........
  r2320 | danydb | 2009-02-05 17:23:24 +0100 (Thu, 05 Feb 2009) | 1 line
  
  Finished with pj
........
  r2321 | danydb | 2009-02-05 18:11:35 +0100 (Thu, 05 Feb 2009) | 1 line
  
  PJ is readonly
........
  r2322 | danydb | 2009-02-05 20:10:34 +0100 (Thu, 05 Feb 2009) | 1 line
  
  Saldo : write the first saldo (ajax)
........
  r2324 | danydb | 2009-02-06 00:07:50 +0100 (Fri, 06 Feb 2009) | 5 lines
  
  Add database script
  Cosmetic (menu)
  Fix Bug 
........
  r2325 | danydb | 2009-02-06 14:07:07 +0100 (Fri, 06 Feb 2009) | 1 line
  
  Improve Pj seq 
........
  r2326 | danydb | 2009-02-09 22:47:23 +0100 (Mon, 09 Feb 2009) | 6 lines
  
  Fix Bug privilege (compta_ven)
  Fix if the pj is empty do not increment the sequence (class_acc_operation)
  Fix remove PJ if pj is empty (modify_op.php)
  Cosmetic do not print PJ if pj is null or empty (listing)
........
  r2327 | danydb | 2009-02-10 21:04:48 +0100 (Tue, 10 Feb 2009) | 5 lines
  
  Fix bug in PJ seq
  Fix bug in export jrn csv
  Improve avoid the removal of vat rate
  Add security for card
........
  r2328 | danydb | 2009-02-12 20:26:36 +0100 (Thu, 12 Feb 2009) | 4 lines
  
  Cosmetic menu_tool
  Impression add tag PJ
  Cosmetic menu administration
........
  r2329 | danydb | 2009-02-12 21:43:19 +0100 (Thu, 12 Feb 2009) | 5 lines
  
  filter the folder the local admin can access
  add a function check_dossier which must be implemented everywhere
  Printing with PJ
  NoAccess default = javascript
........
  r2330 | danydb | 2009-02-14 18:11:49 +0100 (Sat, 14 Feb 2009) | 2 lines
  
  improve add libelle for balance csv
........
  r2331 | danydb | 2009-02-14 19:10:56 +0100 (Sat, 14 Feb 2009) | 7 lines
  
  Balance csv add label
  Bug Financial ledger list
  BUG period access 
  BUG stock access
  IMPROVE list ledger with PJ
........
  r2332 | danydb | 2009-02-15 18:21:59 +0100 (Sun, 15 Feb 2009) | 1 line
  
  Bug order was not saved for report
........
  r2333 | danydb | 2009-02-15 18:22:17 +0100 (Sun, 15 Feb 2009) | 1 line
  
  Add security for normal user
........
  r2334 | danydb | 2009-02-15 18:23:24 +0100 (Sun, 15 Feb 2009) | 3 lines
  
  Bug forget to import class
........
  r2335 | danydb | 2009-02-17 21:33:17 +0100 (Tue, 17 Feb 2009) | 5 lines
  
  Fix quick writing let write
  Fix card priv
  Remove button if no priv to add card or cancel an op
........
  r2336 | danydb | 2009-02-19 21:01:36 +0100 (Thu, 19 Feb 2009) | 4 lines
  
  Check for CA
  common Bug with the repository
........
  r2337 | danydb | 2009-02-19 21:50:35 +0100 (Thu, 19 Feb 2009) | 2 lines
  
  Test the parameter security part
........
This commit is contained in:
Dany De Bontridder 2009-02-19 21:11:08 +00:00
parent 56f66d3b87
commit 8834d14ee5
127 changed files with 3649 additions and 4181 deletions

View file

@ -134,15 +134,16 @@ function ExecSql($p_connection, $p_string,$p_encoding='utf8') {
echo_debug('postgres.php',__LINE__,"SQL = $p_string");
// probl. with Ubuntu & UTF8
//----
pg_set_client_encoding($p_connection,$p_encoding);
ob_start();
$ret=pg_query($p_connection,$p_string);
if ( ! $ret ) {
ob_end_clean();
throw new Exception (" SQL ERROR $p_string ",1);
}
ob_end_clean();
try {
pg_set_client_encoding($p_connection,$p_encoding);
$ret=pg_query($p_connection,$p_string);
if ( ! $ret ) throw new Exception (" SQL ERROR $p_string ",1);
} catch (Exception $a) {
echo $p_string;
$a->getMessage();
$a->getTrace();
return $ret;
}
return $ret;
}
@ -191,39 +192,7 @@ function GetAllUser() {
}
return $User;
}
/*!
* \brief Check if the User is valid
* and return an array with his property
*/
function GetUid($p_uid) {
$cn=DbConnect();
$Res=ExecSql($cn,"select * from ac_users where use_id=".$p_uid);
$Num=pg_NumRows($Res);
if ( $Num == 0 ) { return false; }
for ($i=0;$i < $Num; $i++) {
$Prop[]=pg_fetch_array($Res,$i);
}
return $Prop;
}
/*!
* \brief Get the privilege of an user on a folder
*/
function GetPriv($p_dossier,$p_login)
{
$cn=DbConnect();
$Res=ExecSql($cn,"select priv_priv
from priv_user left join jnt_use_dos on jnt_id=priv_jnt
inner join ac_users on ac_users.use_id=jnt_use_dos.use_id
where use_login='$p_login' and dos_id=$p_dossier");
$Num=pg_NumRows($Res);
echo_debug('postgres.php',__LINE__,"Found ".$Num." rows in GetPriv");
if ( $Num==0) { return 0;}
for($i=0;$i < $Num;$i++) {
$Right=pg_fetch_array($Res,$i);
$Priv[]=$Right['priv_priv'];
}
return $Priv;
}
/*!
* \brief Get the number of rows
* from table jnt_use_dos where $p_dossier = dos_id and
@ -262,11 +231,15 @@ function GetJnt($p_dossier,$p_user)
*
* \param $p_conn connection handler
* \param $p_sql sql string
* \param $array if not null we use the safer ExecSqlParam
*/
function CountSql($p_conn,$p_sql)
function CountSql($p_conn,$p_sql,$array=null)
{
$r_sql=ExecSql($p_conn,$p_sql);
if ( $array == null )
$r_sql=ExecSql($p_conn,$p_sql);
else
$r_sql=ExecSqlParam($p_conn,$p_sql,$array);
return pg_NumRows($r_sql);
}
@ -315,34 +288,6 @@ function AlterSequence($p_cn,$p_name,$p_value) {
$Res=ExecSql($p_cn,"alter sequence $p_name restart $p_value");
}
function get_login($p_uid)
{
$cn=DbConnect();
$Res=ExecSql($cn,"select use_login from ac_users where use_id=$p_uid");
if ( pg_NumRows($Res) == 0 ) return null;
$a_login=pg_fetch_array($Res,0);
return $a_login['use_login'];
}
/*! SyncRight
* \brief Synchronize les droits par d�faut
* avec les journaux existants
*\param $p_dossier dossier id
* \param $p_user user id
*
*/
function SyncRight($p_dossier,$p_user) {
$priv=GetPriv($p_dossier,$p_user);
$right=$priv[0];
$cn=DbConnect($p_dossier);
$sql="insert into user_sec_jrn(uj_login,uj_jrn_id,uj_priv) ".
"select '".$p_user."',jrn_def_id,'".$right."' from jrn_def ".
"where jrn_def_id not in ".
"(select uj_jrn_id from user_sec_jrn where uj_login='".$p_user."')";
$Res=ExecSql($cn,$sql);
}
/*!
* \brief Get the properties of an user
* it means theme, profile, admin...