Multiinsert zakazany tam, kde neni zadouci
[mirrors/SokoMan.git] / assistants / store.inc.php
CommitLineData
16261142 1<?php
de77377e 2switch($SUBPATH[0]) {
16261142 3 default: case 1:
aaafc8b7 4 $barcode = isset($_GET['barcode']) ? htmlspecialchars($_GET['barcode']) : ''; //TODO: XSS
35916247 5 echo $this->html->form("$URL/2", 'GET', array(
aaafc8b7 6 array('barcode',$barcode,'text',false,'autofocus','model_barcode:'),
d0e7939c 7 array('quantity','1','text',false,false,'quantity:'),
35916247
TM
8 array(false,'STORE','submit')
9 ));
16261142
TM
10 break;
11 case 2:
12 $model_id = $this->db->map_unique('model_barcode', $_GET['barcode'], 'model_id', 'model');
274c2053
TM
13 $item_price_in = $this->db->map_unique('item_serial', $_GET['barcode'], 'item_price_in', 'item', false);
14 $item_price_out = $this->db->map_unique('item_serial', $_GET['barcode'], 'item_price_out', 'item', false);
15 $model_price_in = $this->db->map_unique('model_barcode', $_GET['barcode'], 'model_price_in', 'model');
16 $model_price_out = $this->db->map_unique('model_barcode', $_GET['barcode'], 'model_price_out', 'model');
d0e7939c
TM
17
18 $disable_cols = array('status_id','item_price_out','item_customer', 'model_id','item_quantity');
19 if($this->db->map_unique('model_barcode', $_GET['barcode'], 'model_countable', 'model')) {
f5baa075 20 $multi_insert = true;
d0e7939c
TM
21 //$disable_cols[] = 'item_quantity';
22 $item_serial = '';
274c2053 23 $item_quantity = $quantity_added = 1;
d0e7939c
TM
24 $action = $_SERVER['SCRIPT_NAME'].'/item/new';
25 } else {
f5baa075 26 $multi_insert = false;
d0e7939c
TM
27 $quantity_added = $_GET['quantity'];
28 if($quantity_added <= 0) $this->post_redirect_get("$URL_INTERNAL/1","Can't store non-possitive amount of items!");
29 if(!is_numeric($quantity_added)) $quantity_added = 1;
30 $quantity_stored = $this->db->map_unique('item_serial', $_GET['barcode'], 'item_quantity', 'item', false);
31 if(!is_numeric($quantity_stored)) $quantity_stored = 0;
d0e7939c
TM
32
33 $disable_cols[] = 'item_serial';
34 $item_serial = $_GET['barcode'];
35 $item_quantity = $quantity_stored + $quantity_added;
36 $action = $_SERVER['SCRIPT_NAME'].'/item/0/edit';
274c2053
TM
37
38 echo('Stock: '.$quantity_stored.'<br />Storing: '.$quantity_added.'<br />Total: '.$item_quantity);
d0e7939c 39 }
16261142 40 $columns = $this->db->get_columns('item');
16261142 41
d0e7939c 42 $selectbox = $this->db->columns_get_selectbox($columns, 'item');
16261142
TM
43 //print_r(array('<pre>', $selectbox));
44 //foreach($selectbox['model_id'] as $id => $name) if($id != $model_id) unset($selectbox['model_id'][$id]);
45 $current = array(array(
46 'model_id' => $model_id,
d0e7939c
TM
47 'item_serial' => $item_serial,
48 'item_quantity' => $item_quantity,
49 'status_id' => 1,
fbf1a4e6
TM
50 'item_price_in' => $item_price_in + ($quantity_added * $model_price_in),
51 'item_price_out' => $item_price_out + ($quantity_added * $model_price_out),
253705f2 52 'item_author' => $this->db->auth->get_user_id()
16261142
TM
53 ));
54
f5baa075 55 echo $this->html->render_insert_form('item', $columns, $selectbox, $current, $disable_cols, $action, $multi_insert);
16261142
TM
56 break;
57}
This page took 0.179645 seconds and 4 git commands to generate.