Secu: Restriction sur socit

This commit is contained in:
Laurent Destailleur 2005-09-26 22:29:55 +00:00
parent 6430fa5238
commit 9d857ade46
2 changed files with 4 additions and 5 deletions

View File

@ -1108,10 +1108,7 @@ else
$sql .= " AND p.price='".$_GET['search_montant_ht']."'";
}
if ($sall) $sql.= " AND (s.nom like '%".$sall."%' OR p.note like '%".$sall."%' OR pd.description like '%".$sall."%')";
if ($_GET['socidp'])
{
$sql .= ' AND s.idp = '.$_GET['socidp'];
}
if ($socidp) $sql .= ' AND s.idp = '.$socidp;
if ($_GET['viewstatut'] <> '')
{
$sql .= ' AND p.fk_statut in ('.$_GET['viewstatut'].')';

View File

@ -163,6 +163,7 @@ $sql = "SELECT cd.rowid as cid, cd.statut, cd.label, cd.description as note, cd.
$sql.= " FROM ".MAIN_DB_PREFIX."contratdet as cd, ".MAIN_DB_PREFIX."contrat as c, ".MAIN_DB_PREFIX."societe as s";
$sql.= " WHERE c.statut=1 AND cd.statut = 0";
$sql.= " AND cd.fk_contrat = c.rowid AND c.fk_soc = s.idp";
if ($user->societe_id > 0) $sql.= " AND s.idp = ".$user->societe_id;
$sql.= " ORDER BY cd.tms DESC";
if ( $db->query($sql) )
@ -203,12 +204,13 @@ else
print '<br>';
// Last activated services
// Last modified services
$max=5;
$sql = "SELECT cd.rowid as cid, cd.statut, cd.label, cd.description as note, cd.fk_contrat, c.fk_soc, s.nom";
$sql.= " FROM ".MAIN_DB_PREFIX."contratdet as cd, ".MAIN_DB_PREFIX."contrat as c, ".MAIN_DB_PREFIX."societe as s";
$sql.= " WHERE cd.fk_contrat = c.rowid AND c.fk_soc = s.idp";
if ($user->societe_id > 0) $sql.= " AND s.idp = ".$user->societe_id;
$sql.= " ORDER BY cd.tms DESC";
if ( $db->query($sql) )