From 7b23c04d78907916c608d054cceb8dbcbf2fed85 Mon Sep 17 00:00:00 2001 From: Marcus Hill Date: Sat, 5 Feb 2022 12:59:07 +0000 Subject: [PATCH] Add functionality to edit scheduled tickets. Small other fixes --- client_tickets.php | 2 +- post.php | 26 ++++- ...odal.php => scheduled_ticket_add_modal.php | 8 +- scheduled_tickets.php | 12 ++- scheduled_tickets_edit_modal.php | 98 +++++++++++++++++++ 5 files changed, 134 insertions(+), 12 deletions(-) rename add_scheduled_ticket_modal.php => scheduled_ticket_add_modal.php (96%) create mode 100644 scheduled_tickets_edit_modal.php diff --git a/client_tickets.php b/client_tickets.php index 41647883..9fb65e30 100644 --- a/client_tickets.php +++ b/client_tickets.php @@ -203,5 +203,5 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli,"SELECT FOUND_ROWS()")); diff --git a/post.php b/post.php index 8aeed408..1e6feb5b 100644 --- a/post.php +++ b/post.php @@ -5326,8 +5326,8 @@ if(isset($_POST['add_scheduled_ticket'])){ $priority = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['priority']))); $details = trim(mysqli_real_escape_string($mysqli,$_POST['details'])); $asset_id = intval($_POST['asset']); - $frequency = trim(mysqli_real_escape_string($mysqli,$_POST['frequency'])); - $start_date = mysqli_real_escape_string($mysqli,$_POST['start_date']); + $frequency = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['frequency']))); + $start_date = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['start_date']))); if($client_id > 0 AND $contact == 0){ $sql = mysqli_query($mysqli,"SELECT primary_contact FROM clients WHERE client_id = $client_id AND company_id = $session_company_id"); @@ -5347,6 +5347,28 @@ if(isset($_POST['add_scheduled_ticket'])){ } +if(isset($_POST['edit_scheduled_ticket'])){ + $client_id = intval($_POST['client_id']); + $ticket_id = intval($_POST['ticket_id']); + $subject = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['subject']))); + $priority = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['priority']))); + $details = trim(mysqli_real_escape_string($mysqli,$_POST['details'])); + $asset_id = intval($_POST['asset']); + $frequency = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['frequency']))); + $next_run_date = trim(strip_tags(mysqli_real_escape_string($mysqli,$_POST['next_date']))); + + // Edit scheduled ticket + mysqli_query($mysqli, "UPDATE scheduled_tickets SET scheduled_ticket_subject = '$subject', scheduled_ticket_details = '$details', scheduled_ticket_priority = '$priority', scheduled_ticket_frequency = '$frequency', scheduled_ticket_next_run = '$next_run_date', scheduled_ticket_updated_at = NOW(), scheduled_ticket_asset_id = '$asset_id', company_id = '$session_company_id' WHERE scheduled_ticket_id = '$ticket_id'"); + + // Logging + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Update', log_description = 'Updated scheduled ticket for $subject - $frequency', log_created_at = NOW(), log_client_id = $client_id, company_id = $session_company_id, log_user_id = $session_user_id"); + + $_SESSION['alert_message'] = "Scheduled ticket updated."; + + header("Location: " . $_SERVER["HTTP_REFERER"]); + +} + if(isset($_GET['delete_scheduled_ticket'])){ $scheduled_ticket_id = intval($_GET['delete_scheduled_ticket']); diff --git a/add_scheduled_ticket_modal.php b/scheduled_ticket_add_modal.php similarity index 96% rename from add_scheduled_ticket_modal.php rename to scheduled_ticket_add_modal.php index b8f846b1..649a3e1f 100644 --- a/add_scheduled_ticket_modal.php +++ b/scheduled_ticket_add_modal.php @@ -2,7 +2,7 @@