Fix escaping

This commit is contained in:
Laurent Destailleur 2020-09-20 01:53:24 +02:00
parent 216b3c885d
commit fa86b62198
7 changed files with 80 additions and 76 deletions

View File

@ -872,7 +872,7 @@ class ImportXlsx extends ModeleImports
if (!$error && !$updatedone) { if (!$error && !$updatedone) {
// Build SQL INSERT request // Build SQL INSERT request
$sqlstart = 'INSERT INTO '.$tablename.'('.implode(', ', $listfields).', import_key'; $sqlstart = 'INSERT INTO '.$tablename.'('.implode(', ', $listfields).', import_key';
$sqlend = ') VALUES('.implode(', ', $listvalues).", '".$db->escape($importid)."'"; $sqlend = ') VALUES('.implode(', ', $listvalues).", '".$this->db->escape($importid)."'";
if (!empty($tablewithentity_cache[$tablename])) { if (!empty($tablewithentity_cache[$tablename])) {
$sqlstart .= ', entity'; $sqlstart .= ', entity';
$sqlend .= ', '.$conf->entity; $sqlend .= ', '.$conf->entity;

View File

@ -96,7 +96,7 @@ class modCron extends DolibarrModules
// Cronjobs // Cronjobs
$this->cronjobs = array( $this->cronjobs = array(
0=>array('entity'=>0, 'label'=>'PurgeDeleteTemporaryFilesShort', 'jobtype'=>'method', 'class'=>'core/class/utils.class.php', 'objectname'=>'Utils', 'method'=>'purgeFiles', 'parameters'=>'', 'comment'=>'PurgeDeleteTemporaryFiles', 'frequency'=>2, 'unitfrequency'=>3600 * 24 * 7, 'priority'=>50, 'status'=>1, 'test'=>true), 0=>array('entity'=>0, 'label'=>'PurgeDeleteTemporaryFilesShort', 'jobtype'=>'method', 'class'=>'core/class/utils.class.php', 'objectname'=>'Utils', 'method'=>'purgeFiles', 'parameters'=>'', 'comment'=>'PurgeDeleteTemporaryFiles', 'frequency'=>2, 'unitfrequency'=>3600 * 24 * 7, 'priority'=>50, 'status'=>1, 'test'=>true),
1=>array('entity'=>0, 'label'=>'MakeLocalDatabaseDumpShort', 'jobtype'=>'method', 'class'=>'core/class/utils.class.php', 'objectname'=>'Utils', 'method'=>'dumpDatabase', 'parameters'=>'none,auto,1,auto,10', 'comment'=>'MakeLocalDatabaseDump', 'frequency'=>1, 'unitfrequency'=>3600 * 24 * 7, 'priority'=>90, 'status'=>0, 'test'=>in_array($db->type, array('mysql', 'mysqli'))), 1=>array('entity'=>0, 'label'=>'MakeLocalDatabaseDumpShort', 'jobtype'=>'method', 'class'=>'core/class/utils.class.php', 'objectname'=>'Utils', 'method'=>'dumpDatabase', 'parameters'=>'none,auto,1,auto,10', 'comment'=>'MakeLocalDatabaseDump', 'frequency'=>1, 'unitfrequency'=>3600 * 24 * 7, 'priority'=>90, 'status'=>0, 'test'=>in_array($this->db->type, array('mysql', 'mysqli'))),
// 1=>array('entity'=>0, 'label'=>'My label', 'jobtype'=>'command', 'command'=>'', 'parameters'=>'', 'comment'=>'Comment', 'frequency'=>1, 'unitfrequency'=>3600*24) // 1=>array('entity'=>0, 'label'=>'My label', 'jobtype'=>'command', 'command'=>'', 'parameters'=>'', 'comment'=>'Comment', 'frequency'=>1, 'unitfrequency'=>3600*24)
); );

View File

@ -242,17 +242,17 @@ class pdf_stdandard extends ModelePDFMovement
// Initialize technical object to manage hooks of page. Note that conf->hooks_modules contains array of hook context // Initialize technical object to manage hooks of page. Note that conf->hooks_modules contains array of hook context
$hookmanager->initHooks(array('movementlist')); $hookmanager->initHooks(array('movementlist'));
$extrafields = new ExtraFields($db); $extrafields = new ExtraFields($this->db);
// fetch optionals attributes and labels // fetch optionals attributes and labels
$extrafields->fetch_name_optionals_label('movement'); $extrafields->fetch_name_optionals_label('movement');
$search_array_options = $extrafields->getOptionalsFromPost('movement', '', 'search_'); $search_array_options = $extrafields->getOptionalsFromPost('movement', '', 'search_');
$productlot = new ProductLot($db); $productlot = new ProductLot($this->db);
$productstatic = new Product($db); $productstatic = new Product($this->db);
$warehousestatic = new Entrepot($db); $warehousestatic = new Entrepot($this->db);
$movement = new MouvementStock($db); $movement = new MouvementStock($this->db);
$userstatic = new User($db); $userstatic = new User($this->db);
$element = 'movement'; $element = 'movement';
$sql = "SELECT p.rowid, p.ref as product_ref, p.label as produit, p.tobatch, p.fk_product_type as type, p.entity,"; $sql = "SELECT p.rowid, p.ref as product_ref, p.label as produit, p.tobatch, p.fk_product_type as type, p.entity,";
@ -285,11 +285,11 @@ class pdf_stdandard extends ModelePDFMovement
if ($month > 0) if ($month > 0)
{ {
if ($year > 0) if ($year > 0)
$sql .= " AND m.datem BETWEEN '".$db->idate(dol_get_first_day($year, $month, false))."' AND '".$db->idate(dol_get_last_day($year, $month, false))."'"; $sql .= " AND m.datem BETWEEN '".$this->db->idate(dol_get_first_day($year, $month, false))."' AND '".$this->db->idate(dol_get_last_day($year, $month, false))."'";
else $sql .= " AND date_format(m.datem, '%m') = '$month'"; else $sql .= " AND date_format(m.datem, '%m') = '$month'";
} elseif ($year > 0) } elseif ($year > 0)
{ {
$sql .= " AND m.datem BETWEEN '".$db->idate(dol_get_first_day($year, 1, false))."' AND '".$db->idate(dol_get_last_day($year, 12, false))."'"; $sql .= " AND m.datem BETWEEN '".$this->db->idate(dol_get_first_day($year, 1, false))."' AND '".$this->db->idate(dol_get_last_day($year, 12, false))."'";
} }
if ($idproduct > 0) $sql .= " AND p.rowid = ".((int) $idproduct); if ($idproduct > 0) $sql .= " AND p.rowid = ".((int) $idproduct);
if (!empty($search_ref)) $sql .= natural_search('m.rowid', $search_ref, 1); if (!empty($search_ref)) $sql .= natural_search('m.rowid', $search_ref, 1);
@ -297,24 +297,24 @@ class pdf_stdandard extends ModelePDFMovement
if (!empty($search_inventorycode)) $sql .= natural_search('m.inventorycode', $search_inventorycode); if (!empty($search_inventorycode)) $sql .= natural_search('m.inventorycode', $search_inventorycode);
if (!empty($search_product_ref)) $sql .= natural_search('p.ref', $search_product_ref); if (!empty($search_product_ref)) $sql .= natural_search('p.ref', $search_product_ref);
if (!empty($search_product)) $sql .= natural_search('p.label', $search_product); if (!empty($search_product)) $sql .= natural_search('p.label', $search_product);
if ($search_warehouse > 0) $sql .= " AND e.rowid = ".((int) $db->escape($search_warehouse)); if ($search_warehouse > 0) $sql .= " AND e.rowid = ".((int) $this->db->escape($search_warehouse));
if (!empty($search_user)) $sql .= natural_search('u.login', $search_user); if (!empty($search_user)) $sql .= natural_search('u.login', $search_user);
if (!empty($search_batch)) $sql .= natural_search('m.batch', $search_batch); if (!empty($search_batch)) $sql .= natural_search('m.batch', $search_batch);
if ($search_qty != '') $sql .= natural_search('m.value', $search_qty, 1); if ($search_qty != '') $sql .= natural_search('m.value', $search_qty, 1);
if ($search_type_mouvement > 0) $sql .= " AND m.type_mouvement = '".$db->escape($search_type_mouvement)."'"; if ($search_type_mouvement > 0) $sql .= " AND m.type_mouvement = '".$this->db->escape($search_type_mouvement)."'";
// Add where from extra fields // Add where from extra fields
include DOL_DOCUMENT_ROOT.'/core/tpl/extrafields_list_search_sql.tpl.php'; include DOL_DOCUMENT_ROOT.'/core/tpl/extrafields_list_search_sql.tpl.php';
// Add where from hooks // Add where from hooks
$parameters = array(); $parameters = array();
$reshook = $hookmanager->executeHooks('printFieldListWhere', $parameters); // Note that $action and $object may have been modified by hook $reshook = $hookmanager->executeHooks('printFieldListWhere', $parameters); // Note that $action and $object may have been modified by hook
$sql .= $hookmanager->resPrint; $sql .= $hookmanager->resPrint;
$sql .= $db->order($sortfield, $sortorder); $sql .= $this->db->order($sortfield, $sortorder);
$nbtotalofrecords = ''; $nbtotalofrecords = '';
if (empty($conf->global->MAIN_DISABLE_FULL_SCANLIST)) if (empty($conf->global->MAIN_DISABLE_FULL_SCANLIST))
{ {
$result = $db->query($sql); $result = $this->db->query($sql);
$nbtotalofrecords = $db->num_rows($result); $nbtotalofrecords = $this->db->num_rows($result);
if (($page * $limit) > $nbtotalofrecords) // if total resultset is smaller then paging size (filtering), goto and load page 0 if (($page * $limit) > $nbtotalofrecords) // if total resultset is smaller then paging size (filtering), goto and load page 0
{ {
$page = 0; $page = 0;
@ -322,11 +322,11 @@ class pdf_stdandard extends ModelePDFMovement
} }
} }
if (empty($search_inventorycode)) $sql .= $db->plimit($limit + 1, $offset); if (empty($search_inventorycode)) $sql .= $this->db->plimit($limit + 1, $offset);
$resql = $db->query($sql); $resql = $this->db->query($sql);
$nbtotalofrecords = $db->num_rows($result); $nbtotalofrecords = $this->db->num_rows($result);
/* /*
* END TODO * END TODO
@ -338,8 +338,8 @@ class pdf_stdandard extends ModelePDFMovement
{ {
if ($resql) if ($resql)
{ {
$product = new Product($db); $product = new Product($this->db);
$object = new Entrepot($db); $object = new Entrepot($this->db);
if ($idproduct > 0) if ($idproduct > 0)
{ {
@ -350,11 +350,11 @@ class pdf_stdandard extends ModelePDFMovement
$result = $object->fetch($id, $ref); $result = $object->fetch($id, $ref);
if ($result < 0) if ($result < 0)
{ {
dol_print_error($db); dol_print_error($this->db);
} }
} }
$num = $db->num_rows($resql); $num = $this->db->num_rows($resql);
$arrayofselected = is_array($toselect) ? $toselect : array(); $arrayofselected = is_array($toselect) ? $toselect : array();
@ -384,7 +384,7 @@ class pdf_stdandard extends ModelePDFMovement
$supplierprices = $stockFournisseur->list_product_fournisseur_price($object->id); $supplierprices = $stockFournisseur->list_product_fournisseur_price($object->id);
$object->supplierprices = $supplierprices; $object->supplierprices = $supplierprices;
$productstatic = new Product($db); $productstatic = new Product($this->db);
if (!file_exists($dir)) if (!file_exists($dir))
{ {
@ -473,15 +473,15 @@ class pdf_stdandard extends ModelePDFMovement
$arrayofuniqueproduct = array(); $arrayofuniqueproduct = array();
//dol_syslog('List products', LOG_DEBUG); //dol_syslog('List products', LOG_DEBUG);
$resql = $db->query($sql); $resql = $this->db->query($sql);
if ($resql) if ($resql)
{ {
$num = $db->num_rows($resql); $num = $this->db->num_rows($resql);
$i = 0; $i = 0;
$nblines = $num; $nblines = $num;
for ($i = 0; $i < $nblines; $i++) for ($i = 0; $i < $nblines; $i++)
{ {
$objp = $db->fetch_object($resql); $objp = $this->db->fetch_object($resql);
// Multilangs // Multilangs
if (!empty($conf->global->MAIN_MULTILANGS)) // si l'option est active if (!empty($conf->global->MAIN_MULTILANGS)) // si l'option est active
@ -492,10 +492,10 @@ class pdf_stdandard extends ModelePDFMovement
$sql .= " AND lang='".$this->db->escape($langs->getDefaultLang())."'"; $sql .= " AND lang='".$this->db->escape($langs->getDefaultLang())."'";
$sql .= " LIMIT 1"; $sql .= " LIMIT 1";
$result = $db->query($sql); $result = $this->db->query($sql);
if ($result) if ($result)
{ {
$objtp = $db->fetch_object($result); $objtp = $this->db->fetch_object($result);
if ($objtp->label != '') $objp->produit = $objtp->label; if ($objtp->label != '') $objp->produit = $objtp->label;
} }
} }
@ -562,7 +562,7 @@ class pdf_stdandard extends ModelePDFMovement
$pdf->SetFont('', '', $default_font_size - 1); // On repositionne la police par defaut $pdf->SetFont('', '', $default_font_size - 1); // On repositionne la police par defaut
// $objp = $db->fetch_object($resql); // $objp = $this->db->fetch_object($resql);
$userstatic->id = $objp->fk_user_author; $userstatic->id = $objp->fk_user_author;
$userstatic->login = $objp->login; $userstatic->login = $objp->login;
@ -599,7 +599,7 @@ class pdf_stdandard extends ModelePDFMovement
// Date. // Date.
$pdf->SetXY($this->posxdatemouv, $curY); $pdf->SetXY($this->posxdatemouv, $curY);
$pdf->MultiCell($this->posxdesc - $this->posxdatemouv - 0.8, 6, dol_print_date($db->jdate($objp->datem), 'dayhour'), 0, 'L'); $pdf->MultiCell($this->posxdesc - $this->posxdatemouv - 0.8, 6, dol_print_date($this->db->jdate($objp->datem), 'dayhour'), 0, 'L');
// Ref. // Ref.
$pdf->SetXY($this->posxdesc, $curY); $pdf->SetXY($this->posxdesc, $curY);
@ -683,7 +683,7 @@ class pdf_stdandard extends ModelePDFMovement
} }
} }
$db->free($resql); $this->db->free($resql);
/** /**
* footer table * footer table
@ -707,7 +707,7 @@ class pdf_stdandard extends ModelePDFMovement
$pdf->SetXY($this->postotalht, $curY); $pdf->SetXY($this->postotalht, $curY);
$pdf->MultiCell($this->page_largeur - $this->marge_droite - $this->postotalht, 3, $totalunit, 0, 'R', 0); $pdf->MultiCell($this->page_largeur - $this->marge_droite - $this->postotalht, 3, $totalunit, 0, 'R', 0);
} else { } else {
dol_print_error($db); dol_print_error($this->db);
} }
if ($notetoshow) if ($notetoshow)
@ -1014,7 +1014,7 @@ class pdf_stdandard extends ModelePDFMovement
$posy += 4; $posy += 4;
$pdf->SetXY($posx - 50, $posy); $pdf->SetXY($posx - 50, $posy);
$e = new MouvementStock($db); $e = new MouvementStock($this->db);
if (!empty($object->fk_parent) && $e->fetch($object->fk_parent) > 0) if (!empty($object->fk_parent) && $e->fetch($object->fk_parent) > 0)
{ {
$pdf->MultiCell(150, 3, $e->label, '', 'R'); $pdf->MultiCell(150, 3, $e->label, '', 'R');
@ -1050,13 +1050,13 @@ class pdf_stdandard extends ModelePDFMovement
$sql = "SELECT max(m.datem) as datem"; $sql = "SELECT max(m.datem) as datem";
$sql .= " FROM ".MAIN_DB_PREFIX."stock_mouvement as m"; $sql .= " FROM ".MAIN_DB_PREFIX."stock_mouvement as m";
$sql .= " WHERE m.fk_entrepot = ".((int) $object->id); $sql .= " WHERE m.fk_entrepot = ".((int) $object->id);
$resqlbis = $db->query($sql); $resqlbis = $this->db->query($sql);
if ($resqlbis) if ($resqlbis)
{ {
$obj = $db->fetch_object($resqlbis); $obj = $this->db->fetch_object($resqlbis);
$lastmovementdate = $db->jdate($obj->datem); $lastmovementdate = $this->db->jdate($obj->datem);
} else { } else {
dol_print_error($db); dol_print_error($this->db);
} }
if ($lastmovementdate) if ($lastmovementdate)

View File

@ -313,7 +313,7 @@ class mod_codeproduct_elephant extends ModeleProductCode
{ {
// phpcs:enable // phpcs:enable
$sql = "SELECT ref FROM ".MAIN_DB_PREFIX."product"; $sql = "SELECT ref FROM ".MAIN_DB_PREFIX."product";
$sql .= " WHERE ref = '".$this->db->escape($code)."'"; $sql .= " WHERE ref = '".$db->escape($code)."'";
if ($product->id > 0) $sql .= " AND rowid <> ".$product->id; if ($product->id > 0) $sql .= " AND rowid <> ".$product->id;
$resql = $db->query($sql); $resql = $db->query($sql);

View File

@ -220,7 +220,7 @@ class pdf_standard extends ModelePDFStock
$supplierprices = $stockFournisseur->list_product_fournisseur_price($object->id); $supplierprices = $stockFournisseur->list_product_fournisseur_price($object->id);
$object->supplierprices = $supplierprices; $object->supplierprices = $supplierprices;
$productstatic = new Product($db); $productstatic = new Product($this->db);
if (!file_exists($dir)) if (!file_exists($dir))
{ {
@ -313,13 +313,13 @@ class pdf_standard extends ModelePDFStock
$sql .= " WHERE ps.fk_product = p.rowid"; $sql .= " WHERE ps.fk_product = p.rowid";
$sql .= " AND ps.reel <> 0"; // We do not show if stock is 0 (no product in this warehouse) $sql .= " AND ps.reel <> 0"; // We do not show if stock is 0 (no product in this warehouse)
$sql .= " AND ps.fk_entrepot = ".$object->id; $sql .= " AND ps.fk_entrepot = ".$object->id;
$sql .= $db->order($sortfield, $sortorder); $sql .= $this->db->order($sortfield, $sortorder);
//dol_syslog('List products', LOG_DEBUG); //dol_syslog('List products', LOG_DEBUG);
$resql = $db->query($sql); $resql = $this->db->query($sql);
if ($resql) if ($resql)
{ {
$num = $db->num_rows($resql); $num = $this->db->num_rows($resql);
$i = 0; $i = 0;
$nblines = $num; $nblines = $num;
@ -330,7 +330,7 @@ class pdf_standard extends ModelePDFStock
{ {
$curY = $nexY; $curY = $nexY;
$objp = $db->fetch_object($resql); $objp = $this->db->fetch_object($resql);
// Multilangs // Multilangs
if (!empty($conf->global->MAIN_MULTILANGS)) // si l'option est active if (!empty($conf->global->MAIN_MULTILANGS)) // si l'option est active
@ -338,13 +338,13 @@ class pdf_standard extends ModelePDFStock
$sql = "SELECT label"; $sql = "SELECT label";
$sql .= " FROM ".MAIN_DB_PREFIX."product_lang"; $sql .= " FROM ".MAIN_DB_PREFIX."product_lang";
$sql .= " WHERE fk_product=".$objp->rowid; $sql .= " WHERE fk_product=".$objp->rowid;
$sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'"; $sql .= " AND lang='".$this->db->escape($langs->getDefaultLang())."'";
$sql .= " LIMIT 1"; $sql .= " LIMIT 1";
$result = $db->query($sql); $result = $this->db->query($sql);
if ($result) if ($result)
{ {
$objtp = $db->fetch_object($result); $objtp = $this->db->fetch_object($result);
if ($objtp->label != '') $objp->produit = $objtp->label; if ($objtp->label != '') $objp->produit = $objtp->label;
} }
} }
@ -501,7 +501,7 @@ class pdf_standard extends ModelePDFStock
} }
} }
$db->free($resql); $this->db->free($resql);
/** /**
* Footer table * Footer table
@ -542,7 +542,7 @@ class pdf_standard extends ModelePDFStock
} }
} }
} else { } else {
dol_print_error($db); dol_print_error($this->db);
} }
// Displays notes // Displays notes
@ -825,7 +825,7 @@ class pdf_standard extends ModelePDFStock
$pdf->SetTextColor(0, 0, 60); $pdf->SetTextColor(0, 0, 60);
// Parent entrepot // Parent entrepot
$e = new Entrepot($db); $e = new Entrepot($this->db);
$hasparent = (!empty($object->fk_parent) && $e->fetch($object->fk_parent) > 0); $hasparent = (!empty($object->fk_parent) && $e->fetch($object->fk_parent) > 0);
if ($hasparent) { if ($hasparent) {
@ -864,13 +864,13 @@ class pdf_standard extends ModelePDFStock
$sql = "SELECT max(m.datem) as datem"; $sql = "SELECT max(m.datem) as datem";
$sql .= " FROM ".MAIN_DB_PREFIX."stock_mouvement as m"; $sql .= " FROM ".MAIN_DB_PREFIX."stock_mouvement as m";
$sql .= " WHERE m.fk_entrepot = ".((int) $object->id); $sql .= " WHERE m.fk_entrepot = ".((int) $object->id);
$resqlbis = $db->query($sql); $resqlbis = $this->db->query($sql);
if ($resqlbis) if ($resqlbis)
{ {
$obj = $db->fetch_object($resqlbis); $obj = $this->db->fetch_object($resqlbis);
$lastmovementdate = $db->jdate($obj->datem); $lastmovementdate = $this->db->jdate($obj->datem);
} else { } else {
dol_print_error($db); dol_print_error($this->db);
} }
if ($lastmovementdate) if ($lastmovementdate)

View File

@ -106,7 +106,7 @@ class InterfaceZapierTriggers extends DolibarrTriggers
if ($action != '') { if ($action != '') {
$actions = explode('_', $action); $actions = explode('_', $action);
$sql = 'SELECT rowid, url FROM '.MAIN_DB_PREFIX.'zapier_hook'; $sql = 'SELECT rowid, url FROM '.MAIN_DB_PREFIX.'zapier_hook';
$sql .= ' WHERE module="'.$db->escape(strtolower($actions[0])).'" AND action="'.$db->escape(strtolower($actions[1])).'"'; $sql .= ' WHERE module="'.$this->db->escape(strtolower($actions[0])).'" AND action="'.$this->db->escape(strtolower($actions[1])).'"';
//setEventMessages($sql, null); //setEventMessages($sql, null);
} }
@ -130,9 +130,9 @@ class InterfaceZapierTriggers extends DolibarrTriggers
//$logtriggeraction = true; //$logtriggeraction = true;
break; break;
case 'ACTION_CREATE': case 'ACTION_CREATE':
$resql = $db->query($sql); $resql = $this->db->query($sql);
// TODO voir comment regrouper les webhooks en un post // TODO voir comment regrouper les webhooks en un post
while ($resql && $obj = $db->fetch_array($resql)) { while ($resql && $obj = $this->db->fetch_array($resql)) {
$cleaned = cleanObjectDatas(dol_clone($object)); $cleaned = cleanObjectDatas(dol_clone($object));
$cleaned = cleanAgendaEventsDatas($cleaned); $cleaned = cleanAgendaEventsDatas($cleaned);
$json = json_encode($cleaned); $json = json_encode($cleaned);
@ -153,8 +153,8 @@ class InterfaceZapierTriggers extends DolibarrTriggers
// Companies // Companies
case 'COMPANY_CREATE': case 'COMPANY_CREATE':
$resql = $db->query($sql); $resql = $this->db->query($sql);
while ($resql && $obj = $db->fetch_array($resql)) { while ($resql && $obj = $this->db->fetch_array($resql)) {
$cleaned = cleanObjectDatas(dol_clone($object)); $cleaned = cleanObjectDatas(dol_clone($object));
$json = json_encode($cleaned); $json = json_encode($cleaned);
// call the zapierPostWebhook() function // call the zapierPostWebhook() function
@ -163,8 +163,8 @@ class InterfaceZapierTriggers extends DolibarrTriggers
$logtriggeraction = true; $logtriggeraction = true;
break; break;
case 'COMPANY_MODIFY': case 'COMPANY_MODIFY':
$resql = $db->query($sql); $resql = $this->db->query($sql);
while ($resql && $obj = $db->fetch_array($resql)) { while ($resql && $obj = $this->db->fetch_array($resql)) {
$cleaned = cleanObjectDatas(dol_clone($object)); $cleaned = cleanObjectDatas(dol_clone($object));
$json = json_encode($cleaned); $json = json_encode($cleaned);
// call the zapierPostWebhook() function // call the zapierPostWebhook() function
@ -200,8 +200,8 @@ class InterfaceZapierTriggers extends DolibarrTriggers
// Customer orders // Customer orders
case 'ORDER_CREATE': case 'ORDER_CREATE':
$resql = $db->query($sql); $resql = $this->db->query($sql);
while ($resql && $obj = $db->fetch_array($resql)) { while ($resql && $obj = $this->db->fetch_array($resql)) {
$cleaned = cleanObjectDatas(dol_clone($object)); $cleaned = cleanObjectDatas(dol_clone($object));
$json = json_encode($cleaned); $json = json_encode($cleaned);
// call the zapierPostWebhook() function // call the zapierPostWebhook() function

View File

@ -167,18 +167,22 @@ class CodingPhpTest extends PHPUnit\Framework\TestCase
$filecontent=file_get_contents($file['fullname']); $filecontent=file_get_contents($file['fullname']);
if (preg_match('/\.class\.php/', $file['relativename']) if (preg_match('/\.class\.php/', $file['relativename'])
|| preg_match('/^core\/boxes\/box_/', $file['relativename']) || preg_match('/boxes\/box_/', $file['relativename'])
|| in_array($file['relativename'], array('core/boxes/modules_boxes.php'))) { || preg_match('/modules\/.*\/doc\/(doc|pdf)_/', $file['relativename'])
if (! in_array($file['relativename'], array( || preg_match('/modules\/(import|mailings|printing)\//', $file['relativename'])
'api/class/api.class.php', || in_array($file['name'], array('modules_boxes.php', 'rapport.pdf.php'))) {
'core/class/commonobject.class.php', if (! in_array($file['name'], array(
'core/class/conf.class.php', 'api.class.php',
'core/class/html.form.class.php', 'commonobject.class.php',
'core/class/html.formmail.class.php', 'conf.class.php',
'core/class/infobox.class.php', 'html.form.class.php',
'core/class/link.class.php', 'html.formmail.class.php',
'core/class/translate.class.php', 'infobox.class.php',
'core/class/utils.class.php' 'link.class.php',
'translate.class.php',
'utils.class.php',
'modules_product.class.php',
'modules_societe.class.php'
))) { ))) {
// Must must not found $db-> // Must must not found $db->
$ok=true; $ok=true;
@ -195,8 +199,8 @@ class CodingPhpTest extends PHPUnit\Framework\TestCase
//exit; //exit;
} }
} else { } else {
if (! in_array($file['relativename'], array( if (! in_array($file['name'], array(
'core/extrafieldsinexport.inc.php' 'extrafieldsinexport.inc.php'
))) { ))) {
// Must must not found $this->db-> // Must must not found $this->db->
$ok=true; $ok=true;