Complete security audit fixes

This commit is contained in:
Thanakorn S
2026-03-09 14:31:39 +07:00
parent 93d903c4b2
commit 7cb78d013b
33 changed files with 317 additions and 313 deletions
+7 -8
View File
@@ -1,22 +1,21 @@
<?php
session_start();
require '../../../preset.php';
require '../../../assets/utils/db_auth.php';
$sql = "SELECT *
FROM md_product
WHERE
company_id = {$company_id} and
sku like '%{$data["keyword"]}%'
company_id = :company_id and
sku like :keyword
LIMIT 50
";
$sth = $pdo2->prepare($sql);
$sth->execute();
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
exit(json_encode($answer));
}
$sth->execute([
":company_id" => $company_id,
":keyword" => '%'.$data["keyword"].'%'
]);
db_check($sth, $answer);
$result = $sth->fetchAll(PDO::FETCH_ASSOC);
$answer["result"] = $result;
+9 -9
View File
@@ -1,7 +1,6 @@
<?php
session_start();
require '../../../preset.php';
require '../../../assets/utils/db_auth.php';
$id = (int)$data['id'];
@@ -10,17 +9,18 @@
$sql = "SELECT *
FROM md_storage
WHERE
company_id = {$company_id} and
warehouse = {$warehouse} and
`zone` = '{$data["zone"]}'
company_id = :company_id and
warehouse = :warehouse and
`zone` = :zone
";
$sth = $pdo2->prepare($sql);
$sth->execute();
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
exit(json_encode($answer));
}
$sth->execute([
":company_id" => $company_id,
":warehouse" => $warehouse,
":zone" => $data["zone"]
]);
db_check($sth, $answer);
$pre = $sth->fetchAll(PDO::FETCH_ASSOC);
+11 -10
View File
@@ -1,7 +1,6 @@
<?php
session_start();
require '../../../preset.php';
require '../../../assets/utils/db_auth.php';
$id = (int)$data['id'];
@@ -10,18 +9,20 @@
$sql = "SELECT *
FROM md_storage
WHERE
company_id = {$company_id} and
warehouse = {$warehouse} and
`zone` = '{$data["zone"]}' and
'{$data["aisle"]}' between aisle_from and aisle_to
company_id = :company_id and
warehouse = :warehouse and
`zone` = :zone and
:aisle between aisle_from and aisle_to
";
$sth = $pdo2->prepare($sql);
$sth->execute();
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
exit(json_encode($answer));
}
$sth->execute([
":company_id" => $company_id,
":warehouse" => $warehouse,
":zone" => $data["zone"],
":aisle" => $data["aisle"]
]);
db_check($sth, $answer);
$pre = $sth->fetchAll(PDO::FETCH_ASSOC);
+5 -6
View File
@@ -1,7 +1,6 @@
<?php
session_start();
require '../../../preset.php';
require '../../../assets/utils/db_auth.php';
$id = (int)$data['id'];
@@ -14,11 +13,11 @@
warehouse = {$warehouse}";
$sth = $pdo2->prepare($sql);
$sth->execute();
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
exit(json_encode($answer));
}
$sth->execute([
":company_id" => $company_id,
":warehouse" => $warehouse
]);
db_check($sth, $answer);
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
$answer["success"] = 1;