Fix: Correction plantage lors ajout facture si la note contient des quot.

Fix: Correction plantage lors ajout ligne facture si le descriptif contient des quot.
This commit is contained in:
Laurent Destailleur 2004-05-09 17:45:30 +00:00
parent 8382e35e5d
commit 150021cf1d

View File

@ -123,9 +123,9 @@ class Facture
$totalht = ($amount - $remise); $totalht = ($amount - $remise);
$tva = tva($totalht); $tva = tva($totalht);
$total = $totalht + $tva; $total = $totalht + $tva;
$sql = "INSERT INTO $this->db_table (facnumber, fk_soc, datec, amount, remise, remise_percent, datef, note, fk_user_author,fk_projet, fk_cond_reglement, date_lim_reglement) "; $sql = "INSERT INTO $this->db_table (facnumber, fk_soc, datec, amount, remise, remise_percent, datef, note, fk_user_author,fk_projet, fk_cond_reglement, date_lim_reglement) ";
$sql .= " VALUES ('$number', $socid, now(), $totalht, $remise, $this->remise_percent, ".$this->db->idate($this->date).",'$this->note',$user->id, $this->projetid, $this->cond_reglement,".$this->db->idate($datelim).")"; $sql .= " VALUES ('$number', $socid, now(), $totalht, $remise, $this->remise_percent, ".$this->db->idate($this->date).",'".addslashes($this->note)."',$user->id, $this->projetid, $this->cond_reglement,".$this->db->idate($datelim).")";
if ( $this->db->query($sql) ) if ( $this->db->query($sql) )
{ {
$this->id = $this->db->last_insert_id(); $this->id = $this->db->last_insert_id();
@ -206,7 +206,7 @@ class Facture
} }
else else
{ {
print $this->db->error() . '<b><br>'.$sql; print "Erreur facture.class fonction create: ".$this->db->error() . '<br>'.$sql.'<br>';
return 0; return 0;
} }
} }
@ -429,7 +429,7 @@ class Facture
*/ */
Function get_libstatut() Function get_libstatut()
{ {
return LibStatut($this->paye,$this->statut); return $this->LibStatut($this->paye,$this->statut);
} }
/** /**
@ -558,7 +558,7 @@ class Facture
} }
$sql = "INSERT INTO ".MAIN_DB_PREFIX."facturedet (fk_facture,description,price,qty,tva_taux, fk_product, remise_percent, subprice, remise)"; $sql = "INSERT INTO ".MAIN_DB_PREFIX."facturedet (fk_facture,description,price,qty,tva_taux, fk_product, remise_percent, subprice, remise)";
$sql .= " VALUES ($facid, '$desc', $price, $qty, $txtva, $fk_product, $remise_percent, $subprice, $remise) ;"; $sql .= " VALUES ($facid, '".addslashes($desc)."', $price, $qty, $txtva, $fk_product, $remise_percent, $subprice, $remise) ;";
if ( $this->db->query( $sql) ) if ( $this->db->query( $sql) )
{ {
@ -567,7 +567,7 @@ class Facture
} }
else else
{ {
print "<br>$sql<br>"; print "Erreur facture.class fonction addline : ".$this->db->error()."<br>$sql<br>";
return -1; return -1;
} }
} }