Mysql escaped notes and itew name and descriptions when you copy an invoice to a recurring invoice as well as fix the cron.php when it converts Recurring into regular invoices

This commit is contained in:
johnny@pittpc.com
2019-09-18 18:13:14 -04:00
parent 705b2cb454
commit e3800e295d
3 changed files with 7 additions and 7 deletions

View File

@@ -35,8 +35,8 @@ if(isset($_GET['o'])){
$disp = "ASC"; $disp = "ASC";
} }
}else{ }else{
$o = "ASC"; $o = "DESC";
$disp = "DESC"; $disp = "ASC";
} }
$sql = mysqli_query($mysqli,"SELECT SQL_CALC_FOUND_ROWS * FROM tickets $sql = mysqli_query($mysqli,"SELECT SQL_CALC_FOUND_ROWS * FROM tickets

View File

@@ -130,10 +130,10 @@ while($row = mysqli_fetch_array($sql_companies)){
$recurring_last_sent = $row['recurring_last_sent']; $recurring_last_sent = $row['recurring_last_sent'];
$recurring_next_date = $row['recurring_next_date']; $recurring_next_date = $row['recurring_next_date'];
$recurring_amount = $row['recurring_amount']; $recurring_amount = $row['recurring_amount'];
$recurring_note = $row['recurring_note']; $recurring_note = mysqli_real_escape_string($mysqli,$row['recurring_note']); //Escape SQL
$category_id = $row['category_id']; $category_id = $row['category_id'];
$client_id = $row['client_id']; $client_id = $row['client_id'];
$client_name = $row['client_name']; $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); //Escape SQL just in case a name is like Safran's etc
$client_net_terms = $row['client_net_terms']; $client_net_terms = $row['client_net_terms'];
//Get the last Invoice Number and add 1 for the new invoice number //Get the last Invoice Number and add 1 for the new invoice number
@@ -153,8 +153,8 @@ while($row = mysqli_fetch_array($sql_companies)){
while($row = mysqli_fetch_array($sql_invoice_items)){ while($row = mysqli_fetch_array($sql_invoice_items)){
$item_id = $row['item_id']; $item_id = $row['item_id'];
$item_name = $row['item_name']; $item_name = mysqli_real_escape_string($mysqli,$row['item_name']); //SQL Escape incase of ,
$item_description = $row['item_description']; $item_description = mysqli_real_escape_string($mysqli,$row['item_description']); //SQL Escape incase of ,
$item_quantity = $row['item_quantity']; $item_quantity = $row['item_quantity'];
$item_price = $row['item_price']; $item_price = $row['item_price'];
$item_subtotal = $row['item_price']; $item_subtotal = $row['item_price'];

View File

@@ -1348,7 +1348,7 @@ if(isset($_POST['add_invoice_recurring'])){
$row = mysqli_fetch_array($sql); $row = mysqli_fetch_array($sql);
$invoice_date = $row['invoice_date']; $invoice_date = $row['invoice_date'];
$invoice_amount = $row['invoice_amount']; $invoice_amount = $row['invoice_amount'];
$invoice_note = $row['invoice_note']; $invoice_note = mysqli_real_escape_string($mysqli,$row['invoice_note']); //SQL Escape in case notes have , them
$client_id = $row['client_id']; $client_id = $row['client_id'];
$category_id = $row['category_id']; $category_id = $row['category_id'];