Fix: security with multi-company

This commit is contained in:
Regis Houssin 2009-05-04 08:48:49 +00:00
parent 8b02eb1f3f
commit 9037816c33
16 changed files with 16 additions and 16 deletions

View File

@ -37,7 +37,7 @@ $langs->load("bills");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -42,7 +42,7 @@ $action=empty($_GET['action']) ? (empty($_POST['action']) ? '' : $_POST['action'
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -44,7 +44,7 @@ $langs->load("stocks");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -39,7 +39,7 @@ $langs->load("bills");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -38,7 +38,7 @@ $langs->load("bills");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -38,7 +38,7 @@ $langs->load("bills");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -39,7 +39,7 @@ $langs->load("products");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -39,7 +39,7 @@ $langs->load("companies");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -39,7 +39,7 @@ $langs->load("companies");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -38,7 +38,7 @@ $langs->load("companies");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -39,7 +39,7 @@ $langs->load("products");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -40,7 +40,7 @@ $langs->load("companies");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -42,7 +42,7 @@ $mode=isset($_GET["mode"])?$_GET["mode"]:'byunit';
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -38,7 +38,7 @@ $langs->load("companies");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -40,7 +40,7 @@ $langs->load("bills");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;

View File

@ -39,7 +39,7 @@ $langs->load("bills");
if (isset($_GET["id"]) || isset($_GET["ref"]))
{
$id = isset($_GET["id"])?$_GET["id"]:(isset($_GET["ref"])?$_GET["ref"]:'');
$fieldid = isset($_REQUEST["ref"])?'ref':'rowid';
$fieldid = isset($_GET["ref"])?'ref':'rowid';
}
if ($user->societe_id) $socid=$user->societe_id;