modrequest.pl did not previously have auth checking, security bug!
[koha_ffzg] / acqui / basket.pl
index ea6db1b..d127ca1 100755 (executable)
 #script to show display basket of orders
 #written by chris@katipo.co.nz 24/2/2000
 
-use C4::Acquisitions;
-use C4::Biblio;
+# Copyright 2000-2002 Katipo Communications
+#
+# This file is part of Koha.
+#
+# Koha is free software; you can redistribute it and/or modify it under the
+# terms of the GNU General Public License as published by the Free Software
+# Foundation; either version 2 of the License, or (at your option) any later
+# version.
+#
+# Koha is distributed in the hope that it will be useful, but WITHOUT ANY
+# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
+# A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License along with
+# Koha; if not, write to the Free Software Foundation, Inc., 59 Temple Place,
+# Suite 330, Boston, MA  02111-1307 USA
+
+
+use strict;
+use C4::Auth;
+use C4::Koha;
 use C4::Output;
 use CGI;
-use strict;
+use C4::Acquisition;
+use C4::Bookfund;
+use C4::Bookseller;
+use C4::Dates qw/format_date/;
+
+use vars qw($debug);
+
+BEGIN {
+       $debug = $ENV{DEBUG} || 1;
+}
+
+=head1 NAME
+
+basket.pl
+
+=head1 DESCRIPTION
+
+ This script display all informations about basket for the supplier given
+ on input arg. Moreover, it allow to add a new order for this supplier from
+ an existing record, a suggestion or from a new record.
+
+=head1 CGI PARAMETERS
+
+=over 4
+
+=item $basketno
+
+this parameter seems to be unused.
+
+=item supplierid
+
+the supplier this script have to display the basket.
 
-my $input=new CGI;
-print $input->header();
-my $basket=$input->param('basket');
-my ($count,@results)=basket($basket);
-print startpage;
+=item order
 
-my @inp=startmenu('acquisitions');
 
-my $count3=@inp;
-for (my $i=0;$i<$count3;$i++){
-      $inp[$i]=~ s/leftmargin=0 topmargin=0\>/leftmargin=0 topmargin=0 onload='update(orderform)'\>/;
+
+=back
+
+=cut
+
+my $query        = new CGI;
+my $basketno     = $query->param('basketno');
+my $booksellerid = $query->param('supplierid');
+my $order        = $query->param('order');
+my ( $template, $loggedinuser, $cookie ) = get_template_and_user(
+    {
+        template_name   => "acqui/basket.tmpl",
+        query           => $query,
+        type            => "intranet",
+        authnotrequired => 0,
+        flagsrequired   => { acquisition => 1 },
+        debug           => 1,
+    }
+);
+
+my $basket = GetBasket($basketno);
+
+# FIXME : the query->param('supplierid') below is probably useless. The bookseller is always known from the basket
+# if no booksellerid in parameter, get it from basket
+# warn "=>".$basket->{booksellerid};
+$booksellerid = $basket->{booksellerid} unless $booksellerid;
+my @booksellers = GetBookSeller($booksellerid);
+my $count2 = scalar @booksellers;
+
+# get librarian branch...
+if ( C4::Context->preference("IndependantBranches") ) {
+    my $userenv = C4::Context->userenv;
+    unless ( $userenv->{flags} == 1 ) {
+        my $validtest = ( $basket->{creationdate} eq '' )
+          || ( $basket->{branch}  eq '' )
+          || ( $userenv->{branch} eq $basket->{branch} )
+          || ( $userenv->{branch} eq '' )
+          || ( $basket->{branch}  eq '' );
+        unless ($validtest) {
+            print $query->redirect("../mainpage.pl");
+            exit 1;
+        }
     }
-print @inp;
-# print $count;
-my ($count2,@booksellers)=bookseller($results[0]->{'booksellerid'});
-
-print <<printend
-<div align=right>
-Our Reference: $basket<br>
-Authorised By: $results[0]->{'authorisedby'}<br>
-$results[0]->{'entrydate'};
-</div>
-<FONT SIZE=6><em>Shopping Basket For: <a href=supplier.pl?id=$results[0]->{'booksellerid'}></a> $booksellers[0]->{'name'}</em></FONT>  
-<a href=newbasket.pl?id=$results[0]->{'booksellerid'}&basket=$basket>Add more orders</a>
-<CENTER>
-<FORM ACTION="/cgi-bin/koha/search.pl" method=post>
- <b>Search ISBN, Title or Author:</b> <INPUT TYPE="text"  SIZE="25"   NAME="recieve">
-</form>
-<p>
-<FORM ACTION="/cgi-bin/koha/acqui/modorders.pl" method=post name=orderform>
-<table border=0 cellspacing=0 cellpadding=5>
-<tr valign=top bgcolor=#99cc33>
-  <td background="/images/background-mem.gif"><b>ORDER</b></td>
-  <td background="/images/background-mem.gif"><b>ISBN</b></td>
-  <td background="/images/background-mem.gif"><b>TITLE</b></td>
-  <td background="/images/background-mem.gif"><b>AUTHOR</b></td>
-  <td background="/images/background-mem.gif"><b>RRP</b></td>
-  <td background="/images/background-mem.gif"><b>\$EST</b></td>
-  <td background="/images/background-mem.gif"><b>QUANTITY</b></td>
-  <td background="/images/background-mem.gif"><b>TOTAL</b></td></tr>
-printend
-;
-
-
-my $line_total; # total of each line
-my $sub_total; # total of line totals
-my $gist;      # GST
-my $grand_total; # $subttotal + $gist
-
-for (my $i=0;$i<$count;$i++){
-my $rrp=$results[$i]->{'listprice'};
-if ($results[$i]->{'currency'} ne 'NZD'){
-$rrp=curconvert($results[$i]->{'currency'},$rrp);
 }
 
-$line_total=$results[$i]->{'quantity'}*$results[$i]->{'ecost'};
-$sub_total+=$line_total;
-$gist=sprintf("%.2f",$sub_total*0.125);
-$grand_total=$sub_total+$gist;
-
-print <<EOP      
-<tr valign=top bgcolor=#ffffcc>
-  <td>$results[$i]->{'ordernumber'}</td>
-  <td>$results[$i]->{'isbn'}</td>
-  <td><a href="newbiblio.pl?ordnum=$results[$i]->{'ordernumber'}&id=$results[$i]->{'booksellerid'}&basket=$basket">$results[$i]->{'title'}</a></td>
-  <td>$results[$i]->{'author'}</td>
-  <td>\$<input type=text name=rrp$i size=6 value="$results[$i]->{'rrp'}"></td>
-  <td>\$<input type=text name=eup$i size=6 value="$results[$i]->{'ecost'}"></td>
-  <td><input type=text name=quantity$i size=6 value=$results[$i]->{'quantity'} onchange='update(this.form)'></td>
-  <td>\$<input type=text name=total$i size=10 value=$line_total></td>
-  <input type=hidden name=ordnum$i value=$results[$i]->{'ordernumber'}>
-  <input type=hidden name=bibnum$i value=$results[$i]->{'biblionumber'}> 
-</tr>
-EOP
-;
+# if new basket, pre-fill infos
+$basket->{creationdate} = ""            unless ( $basket->{creationdate} );
+$basket->{authorisedby} = $loggedinuser unless ( $basket->{authorisedby} );
+$debug and warn 
+       sprintf "loggedinuser: $loggedinuser; creationdate: %s; authorisedby: %s",
+               $basket->{creationdate}, $basket->{authorisedby} ;
+
+
+my ( $count, @results );
+@results  = GetOrders( $basketno, $order );
+$count = scalar @results;
+
+my $line_total;     # total of each line
+my $sub_total;      # total of line totals
+my $gist;           # GST
+my $grand_total;    # $subttotal + $gist
+my $toggle = 0;
+
+
+# my $line_total_est; # total of each line
+my $sub_total_est;      # total of line totals
+my $gist_est;           # GST
+my $grand_total_est;    # $subttotal + $gist
+
+my $qty_total;
+
+my @books_loop;
+for ( my $i = 0 ; $i < $count ; $i++ ) {
+    my $rrp = $results[$i]->{'listprice'};
+    $rrp = ConvertCurrency( $results[$i]->{'currency'}, $rrp );
+
+    $sub_total_est += $results[$i]->{'quantity'} * $results[$i]->{'rrp'};
+    $line_total = $results[$i]->{'quantity'} * $results[$i]->{'ecost'};
+    $sub_total += $line_total;
+    $qty_total += $results[$i]->{'quantity'};
+    my %line;
+    %line=%{$results[$i]};
+   if ( $toggle == 0 ) {
+        $line{color} = '#EEEEEE';
+        $toggle = 1;
+    }
+    else {
+        $line{color} = 'white';
+        $toggle = 0;
+    }
+    $line{basketno}         = $basketno;
+    $line{i}                = $i;
+    $line{rrp}              = sprintf( "%.2f", $line{'rrp'} );
+    $line{ecost}            = sprintf( "%.2f", $line{'ecost'} );
+    $line{line_total}       = sprintf( "%.2f", $line_total );
+    $line{odd}              = $i % 2;
+    push @books_loop, \%line;
 }
-# 
-print "<input type=hidden name=number value=$count>
-<input type=hidden name=basketno value=\"$basket\">";
-print <<EOP
-<tr valign=top bgcolor=white><td colspan=6 rowspan=3  bgcolor=#cccc99  background="/images/background-mem.gif">
-  <b>HELP</b><br>
-  To cancel an order, just change the quantity to 0 and click "save changes".<br>
-  To change any of the catalogue or accounting information attached to an order,  click on the title.<br>
-  To add new orders to this supplier, start with a search. </td> 
-  <td><b>SubTotal</b></td>
-  <td>\$<input type=text name=subtotal size=10 value=$sub_total></td></tr>
-<tr valign=top bgcolor=white>
-  <td><b>GST</b></td>
-  <td>\$<input type=text name=gst size=10 value=$gist></td></tr>
-<tr valign=top bgcolor=white><td><b>TOTAL</b></td>
-  <td>\$<input type=text name=grandtotal size=10 value=$grand_total></td></tr>
-<tr valign=top bgcolor=white>
-  <td></td>
-  <td></td>
-  <td></td>
-  <td></td>
-  <td></td>
-  <td></td>
-  <td colspan=3><input type=image  name=submit src=/images/save-changes.gif border=0 width=187 height=42 align=right></td></tr>
-</table>
-</CENTER>  
-EOP
-  ;
-
-print endmenu('acquisitions');
-
-print endpage;
+my $prefgist = C4::Context->preference("gist");
+$gist            = sprintf( "%.2f", $sub_total * $prefgist );
+$grand_total     = $sub_total + $gist;
+$grand_total_est =
+  $sub_total_est + sprintf( "%.2f", $sub_total_est * $prefgist );
+$gist_est = sprintf( "%.2f", $sub_total_est * $prefgist );
+$template->param(
+    basketno         => $basketno,
+    creationdate     => format_date( $basket->{creationdate} ),
+    authorisedby     => $basket->{authorisedby},
+    authorisedbyname => $basket->{authorisedbyname},
+    closedate        => format_date( $basket->{closedate} ),
+    active           => $booksellers[0]->{'active'},
+    booksellerid     => $booksellers[0]->{'id'},
+    name             => $booksellers[0]->{'name'},
+    address1         => $booksellers[0]->{'address1'},
+    address2         => $booksellers[0]->{'address2'},
+    address3         => $booksellers[0]->{'address3'},
+    address4         => $booksellers[0]->{'address4'},
+    entrydate        => format_date( $results[0]->{'entrydate'} ),
+    books_loop       => \@books_loop,
+    count            => $count,
+    sub_total        => $sub_total,
+    gist             => $gist,
+    grand_total      => $grand_total,
+    sub_total_est    => $sub_total_est,
+    gist_est         => $gist_est,
+    grand_total_est  => $grand_total_est,
+    currency         => $booksellers[0]->{'listprice'},
+    qty_total        => $qty_total,
+    GST => C4::Context->preference("gist"),
+);
+output_html_with_http_headers $query, $cookie, $template->output;