Fix for variable scoping problem
[koha_gimpoz] / admin / authorised_values.pl
index 16f9fff..4d6eb17 100755 (executable)
@@ -22,21 +22,18 @@ use CGI;
 use C4::Auth;
 use C4::Context;
 use C4::Output;
-use C4::Interface::CGI::Output;
-use C4::Search;
-use HTML::Template;
+
 use C4::Context;
 
 
-sub StringSearch  {
-       my ($env,$searchstring,$type)=@_;
+sub AuthorizedValuesForCategory  {
+       my ($searchstring,$type)=@_;
        my $dbh = C4::Context->dbh;
        $searchstring=~ s/\'/\\\'/g;
        my @data=split(' ',$searchstring);
        my $count=@data;
-       my $query="Select id,category,authorised_value,lib from authorised_values where (category like \"$data[0]%\") order by category,authorised_value";
-       my $sth=$dbh->prepare($query);
-       $sth->execute;
+       my $sth=$dbh->prepare("Select id,category,authorised_value,lib from authorised_values where (category = ?) order by category,authorised_value");
+       $sth->execute("$data[0]");
        my @results;
        my $cnt=0;
        while (my $data=$sth->fetchrow_hashref){
@@ -47,18 +44,28 @@ sub StringSearch  {
        return ($cnt,\@results);
 }
 
+sub _already_exists {
+    my ($category, $authorised_value) = @_;
+    my $dbh = C4::Context->dbh;
+    my $sth = $dbh->prepare_cached("SELECT COUNT(*) FROM authorised_values
+                                    WHERE category = ?
+                                    AND authorised_value = ?");
+    $sth->execute($category, $authorised_value);
+    my ($count) = $sth->fetchrow_array();
+    $sth->finish();
+    return $count;
+}
+
 my $input = new CGI;
 my $searchfield=$input->param('searchfield');
 $searchfield=~ s/\,//g;
 my $id = $input->param('id');
-my $reqsel="select category,authorised_value,lib from authorised_values where id='$id'";
-my $reqdel="delete from authorised_values where id='$id'";
 my $offset=$input->param('offset');
 my $script_name="/cgi-bin/koha/admin/authorised_values.pl";
 my $dbh = C4::Context->dbh;
 
 my ($template, $borrowernumber, $cookie)
-    = get_template_and_user({template_name => "parameters/authorised_values.tmpl",
+    = get_template_and_user({template_name => "admin/authorised_values.tmpl",
                             query => $input,
                             type => "intranet",
                             authnotrequired => 0,
@@ -81,51 +88,60 @@ if ($op eq 'add_form') {
        my $data;
        if ($id) {
                my $dbh = C4::Context->dbh;
-               my $sth=$dbh->prepare("select id,category,authorised_value,lib from authorised_values where id='$id'");
-               $sth->execute;
+               my $sth=$dbh->prepare("select id,category,authorised_value,lib from authorised_values where id=?");
+               $sth->execute($id);
                $data=$sth->fetchrow_hashref;
                $sth->finish;
        } else {
                $data->{'category'} = $input->param('category');
        }
-       if ($searchfield) {
-               $template->param(action => "Modify authorised value");
+       if ($id) {
+               $template->param(action_modify => 1);
+               $template->param('heading-modify-authorized-value-p' => 1);
        } elsif ( ! $data->{'category'} ) {
-               $template->param(action => "Add new category");
+               $template->param(action_add_category => 1);
+               $template->param('heading-add-new-category-p' => 1);
        } else {
-               $template->param(action => "Add authorised value");
+               $template->param(action_add_value => 1);
+               $template->param('heading-add-authorized-value-p' => 1);
        }
+       $template->param('use-heading-flags-p' => 1);
        $template->param(category => $data->{'category'},
                                                        authorised_value => $data->{'authorised_value'},
                                                        lib => $data->{'lib'},
                                                        id => $data->{'id'}
                                                        );
-       if ($data->{'category'}) {
-               $template->param(category => "<input type=\"hidden\" name=\"category\" value='$data->{'category'}'>$data->{'category'}");
-       } else {
-               $template->param(category => "<input type=text name=\"category\" size=8 maxlength=8>");
-       }
 ################## ADD_VALIDATE ##################################
 # called by add_form, used to insert/modify data in DB
 } elsif ($op eq 'add_validate') {
        my $dbh = C4::Context->dbh;
-       my $sth=$dbh->prepare("replace authorised_values (id,category,authorised_value,lib) values (?,?,?,?)");
-       my $lib = $input->param('lib');
-       undef $lib if ($lib eq ""); # to insert NULL instead of a blank string
+
+    if (_already_exists($input->param('category'), $input->param('authorised_value'))) {
+        $template->param(duplicate_category => $input->param('category'),
+                         duplicate_value =>  $input->param('authorised_value'),
+                         else => 1);
+        default_form();
+    } else {
+           my $sth=$dbh->prepare("replace authorised_values (id,category,authorised_value,lib) values (?,?,?,?)");
+           my $lib = $input->param('lib');
+           undef $lib if ($lib eq ""); # to insert NULL instead of a blank string
        
-       $sth->execute($input->param('id'), $input->param('category'), $input->param('authorised_value'), $lib);
-       $sth->finish;
-       print "Content-Type: text/html\n\n<META HTTP-EQUIV=Refresh CONTENT=\"0; URL=authorised_values.pl?searchfield=".$input->param('category')."\"></html>";
-       exit;
+           $sth->execute($input->param('id'), $input->param('category'), $input->param('authorised_value'), $lib);
+           $sth->finish;
+           print "Content-Type: text/html\n\n<META HTTP-EQUIV=Refresh CONTENT=\"0; URL=authorised_values.pl?searchfield=".$input->param('category')."\"></html>";
+           exit;
+    }
 ################## DELETE_CONFIRM ##################################
 # called by default form, used to confirm deletion of data in DB
 } elsif ($op eq 'delete_confirm') {
        my $dbh = C4::Context->dbh;
-       my $sth=$dbh->prepare($reqsel);
-       $sth->execute;
+       my $sth=$dbh->prepare("select category,authorised_value,lib from authorised_values where id=?");
+       $sth->execute($id);
        my $data=$sth->fetchrow_hashref;
        $sth->finish;
+       $id = $input->param('id') unless $id;
        $template->param(searchfield => $searchfield,
+                                                       Tlib => $data->{'lib'},
                                                        Tvalue => $data->{'authorised_value'},
                                                        id =>$id,
                                                        );
@@ -135,8 +151,9 @@ if ($op eq 'add_form') {
 # called by delete_confirm, used to effectively confirm deletion of data in DB
 } elsif ($op eq 'delete_confirmed') {
        my $dbh = C4::Context->dbh;
-       my $sth=$dbh->prepare($reqdel);
-       $sth->execute;
+       my $id = $input->param('id');
+       my $sth=$dbh->prepare("delete from authorised_values where id=?");
+       $sth->execute($id);
        $sth->finish;
        print "Content-Type: text/html\n\n<META HTTP-EQUIV=Refresh CONTENT=\"0; URL=authorised_values.pl?searchfield=$searchfield\"></html>";
        exit;
@@ -144,6 +161,13 @@ if ($op eq 'add_form') {
                                                                                                        # END $OP eq DELETE_CONFIRMED
 ################## DEFAULT ##################################
 } else { # DEFAULT
+    default_form();
+} #---- END $OP eq DEFAULT
+output_html_with_http_headers $input, $cookie, $template->output;
+
+exit 0;
+
+sub default_form {
        # build categories list
        my $sth = $dbh->prepare("select distinct category from authorised_values");
        $sth->execute;
@@ -153,31 +177,32 @@ if ($op eq 'add_form') {
        }
        # push koha system categories
        my $tab_list = CGI::scrolling_list(-name=>'searchfield',
+               -id=>'searchfield',
                        -values=> \@category_list,
                        -default=>"",
                        -size=>1,
+                       -tabindex=>'',
                        -multiple=>0,
                        );
        if (!$searchfield) {
                $searchfield=$category_list[0];
        }
-       my $env;
-       my ($count,$results)=StringSearch($env,$searchfield,'web');
-       my $toggle="white";
+       my ($count,$results)=AuthorizedValuesForCategory($searchfield,'web');
+       my $toggle=1;
        my @loop_data = ();
        # builds value list
        for (my $i=$offset; $i < ($offset+$pagesize<$count?$offset+$pagesize:$count); $i++){
-               if ($toggle eq 'white'){
-                       $toggle="#ffffcc";
+               if ($toggle eq 1){
+                       $toggle=1;
                } else {
-                       $toggle="white";
+                       $toggle=0;
                }
                my %row_data;  # get a fresh hash for the row data
                $row_data{category} = $results->[$i]{'category'};
                $row_data{authorised_value} = $results->[$i]{'authorised_value'};
                $row_data{lib} = $results->[$i]{'lib'};
-               $row_data{edit} = "$script_name?op=add_form&id=".$results->[$i]{'id'};
-               $row_data{delete} = "$script_name?op=delete_confirm&searchfield=$searchfield&id=".$results->[$i]{'id'};
+               $row_data{edit} = "$script_name?op=add_form&amp;id=".$results->[$i]{'id'};
+               $row_data{delete} = "$script_name?op=delete_confirm&amp;searchfield=$searchfield&amp;id=".$results->[$i]{'id'};
                push(@loop_data, \%row_data);
        }
 
@@ -187,14 +212,18 @@ if ($op eq 'add_form') {
 
        if ($offset>0) {
                my $prevpage = $offset-$pagesize;
-               $template->param(previous => "<a href=\"$script_name?offset=$prevpage&searchfield=$searchfield\">");
+               $template->param(isprevpage => $offset,
+                                               prevpage=> $prevpage,
+                                               searchfield => $searchfield,
+                                               script_name => $script_name,
+                );
        }
        if ($offset+$pagesize<$count) {
                my $nextpage =$offset+$pagesize;
-               $template->param(next => "<a href=\"$script_name?offset=$nextpage&searchfield=$searchfield\">");
-
-
+               $template->param(nextpage =>$nextpage,
+                                               searchfield => $searchfield,
+                                               script_name => $script_name,
+               );
        }
-} #---- END $OP eq DEFAULT
+}
 
-output_html_with_http_headers $input, $cookie, $template->output;