Skip to content
Snippets Groups Projects
Commit b96782c2 authored by Laurent Destailleur's avatar Laurent Destailleur
Browse files

Fix: 22757

Another way to fix this bug because first fix was using not portable code.
parent 96a6be29
Branches
Tags
No related merge requests found
...@@ -112,7 +112,7 @@ if ($action == 'add_paiement') ...@@ -112,7 +112,7 @@ if ($action == 'add_paiement')
$paiement->amounts = $amounts; // Array of amounts $paiement->amounts = $amounts; // Array of amounts
$paiement->paiementid = $_POST['paiementid']; $paiement->paiementid = $_POST['paiementid'];
$paiement->num_paiement = $_POST['num_paiement']; $paiement->num_paiement = $_POST['num_paiement'];
$paiement->note = mysql_real_escape_string($_POST['comment']); $paiement->note = $_POST['comment'];
$paiement_id = $paiement->create($user); $paiement_id = $paiement->create($user);
if ($paiement_id > 0) if ($paiement_id > 0)
......
...@@ -122,7 +122,7 @@ class PaiementFourn ...@@ -122,7 +122,7 @@ class PaiementFourn
$error = 0; $error = 0;
// Nettoyage parametres // Clean parameters
$this->total = 0; $this->total = 0;
foreach ($this->amounts as $key => $value) foreach ($this->amounts as $key => $value)
{ {
...@@ -141,7 +141,7 @@ class PaiementFourn ...@@ -141,7 +141,7 @@ class PaiementFourn
$sql = 'INSERT INTO '.MAIN_DB_PREFIX.'paiementfourn ('; $sql = 'INSERT INTO '.MAIN_DB_PREFIX.'paiementfourn (';
$sql.= 'datec, datep, amount, fk_paiement, num_paiement, note, fk_user_author, fk_bank)'; $sql.= 'datec, datep, amount, fk_paiement, num_paiement, note, fk_user_author, fk_bank)';
$sql.= ' VALUES (now(),'; $sql.= ' VALUES (now(),';
$sql.= ' '.$this->db->idate($this->datepaye).', \''.$this->total.'\', '.$this->paiementid.', \''.$this->num_paiement.'\', \''.$this->note.'\', '.$user->id.', 0)'; $sql.= " ".$this->db->idate($this->datepaye).", '".$this->total."', ".$this->paiementid.", '".$this->num_paiement."', '".addslashes($this->note)."', ".$user->id.", 0)";
dolibarr_syslog("PaiementFourn::create sql=".$sql); dolibarr_syslog("PaiementFourn::create sql=".$sql);
$resql = $this->db->query($sql); $resql = $this->db->query($sql);
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment