Complete security audit fixes
This commit is contained in:
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -10,14 +9,15 @@
|
||||
$sql = "SELECT `log`
|
||||
FROM md_product_category
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
$table_log = json_decode($row['log'] ?? '[]', true);
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -10,14 +9,15 @@
|
||||
$sql = "SELECT `log`
|
||||
FROM md_product
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
$table_log = json_decode($row['log'] ?? '[]', true);
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
@@ -17,10 +16,8 @@ $sth->execute([
|
||||
':id' => $id,
|
||||
]);
|
||||
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
db_check($sth, $answer);
|
||||
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
$table_log = json_decode($row['log'] ?? '[]', true);
|
||||
@@ -89,10 +86,7 @@ if ($id > 0) {
|
||||
]);
|
||||
}
|
||||
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["success"] = 1;
|
||||
exit(json_encode($answer));
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
@@ -17,10 +16,8 @@ $sth->execute([
|
||||
':id' => $id,
|
||||
]);
|
||||
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
db_check($sth, $answer);
|
||||
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
$table_log = json_decode($row['log'] ?? '[]', true);
|
||||
@@ -76,10 +73,7 @@ if ($id > 0) {
|
||||
|
||||
}
|
||||
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["success"] = 1;
|
||||
exit(json_encode($answer));
|
||||
|
||||
@@ -1,19 +1,14 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT *
|
||||
FROM user
|
||||
WHERE
|
||||
username not in ('support','extra')";
|
||||
$sth = $pdo1->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth = $pdo1->query($sql);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT *
|
||||
@@ -9,11 +8,10 @@
|
||||
WHERE
|
||||
company_id = {$company_id}";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT *
|
||||
@@ -9,11 +8,10 @@
|
||||
WHERE
|
||||
company_id = {$company_id}";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -10,14 +9,14 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_product_category
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
$json = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
$json = json_encode($json);
|
||||
|
||||
@@ -26,25 +25,26 @@
|
||||
// delete data
|
||||
$sql = "DELETE FROM md_product_category
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
|
||||
|
||||
// insert into archive
|
||||
$sql = "INSERT INTO archive (`company_id`,`user_id`,`date`,`json`) VALUES ({$company_id},{$user_id},NOW(),'{$jsona}')";
|
||||
$sql = "INSERT INTO archive (`company_id`,`user_id`,`date`,`json`) VALUES (:company_id,:user_id,NOW(),:json)";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":user_id" => $user_id,
|
||||
":json" => $json
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -9,15 +8,15 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_product_category
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -9,15 +8,15 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_product
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -9,15 +8,15 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_storage
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -9,15 +8,15 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_warehouse
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT a.*, b.warehouse_name
|
||||
@@ -10,13 +9,12 @@
|
||||
a.company_id = b.company_id and
|
||||
a.warehouse = b.id
|
||||
WHERE
|
||||
a.company_id = {$company_id}";
|
||||
a.company_id = :company_id ";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
|
||||
|
||||
@@ -1,19 +1,17 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT a.*
|
||||
FROM md_warehouse a
|
||||
WHERE
|
||||
a.company_id = {$company_id}";
|
||||
a.company_id = :company_id";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user