From: <tim...@us...> - 2010-09-07 21:28:32
|
Revision: 3713 http://web-erp.svn.sourceforge.net/web-erp/?rev=3713&view=rev Author: tim_schofield Date: 2010-09-07 21:28:26 +0000 (Tue, 07 Sep 2010) Log Message: ----------- Correct the sql quoting Modified Paths: -------------- trunk/PDFQuotation.php trunk/doc/Change.log.html Modified: trunk/PDFQuotation.php =================================================================== --- trunk/PDFQuotation.php 2010-09-07 18:44:03 UTC (rev 3712) +++ trunk/PDFQuotation.php 2010-09-07 21:28:26 UTC (rev 3713) @@ -55,7 +55,7 @@ AND salesorders.shipvia=shippers.shipper_id AND salesorders.fromstkloc=locations.loccode AND salesorders.quotation=1 - AND salesorders.orderno=" . $_GET['QuotationNo']; + AND salesorders.orderno='" . $_GET['QuotationNo'] ."'"; $result=DB_query($sql,$db, $ErrMsg); @@ -104,7 +104,7 @@ salesorderdetails.narrative FROM salesorderdetails INNER JOIN stockmaster ON salesorderdetails.stkcode=stockmaster.stockid - WHERE salesorderdetails.orderno=" . $_GET['QuotationNo']; + WHERE salesorderdetails.orderno='" . $_GET['QuotationNo'] . "'"; $result=DB_query($sql,$db, $ErrMsg); @@ -145,7 +145,7 @@ $TaxAuth = $myrow3['taxauthid']; } - $sql4 = "SELECT * FROM taxauthrates WHERE dispatchtaxprovince=" .$TaxProv ." AND taxcatid=" .$TaxCat ." AND taxauthority=" .$TaxAuth; + $sql4 = "SELECT * FROM taxauthrates WHERE dispatchtaxprovince='" .$TaxProv ."' AND taxcatid='" .$TaxCat ."' AND taxauthority='" .$TaxAuth ."'"; $result4=DB_query($sql4,$db, $ErrMsg); while ($myrow4=DB_fetch_array($result4)){ $TaxClass = 100 * $myrow4['taxrate']; @@ -251,4 +251,4 @@ $pdf->OutputI($_SESSION['DatabaseName'] . '_Quotation_' . date('Y-m-d') . '.pdf');//UldisN $pdf->__destruct(); //UldisN } -?> +?> \ No newline at end of file Modified: trunk/doc/Change.log.html =================================================================== --- trunk/doc/Change.log.html 2010-09-07 18:44:03 UTC (rev 3712) +++ trunk/doc/Change.log.html 2010-09-07 21:28:26 UTC (rev 3713) @@ -1,5 +1,6 @@ <p><font SIZE=4 COLOR=BLUE><b>webERP Change Log</b></font></p> <p></p> +<p>07/09/10 Tim: PDFQuotation.php - Correct the sql quoting</p> <p>07/09/10 Tim: PDFPickingList.php - Correct the sql quoting</p> <p>07/09/10 Tim: PDFOrderStatus.php - Improve report layout for readability</p> <p>07/09/10 Tim: PDFOrderInvoiced.php - Improve report layout for readability</p> This was sent by the SourceForge.net collaborative development platform, the world's largest Open Source development site. |