diff --git a/admin/post/document_template.php b/admin/post/document_template.php
index 2dbbb3b9..bfe7f00d 100644
--- a/admin/post/document_template.php
+++ b/admin/post/document_template.php
@@ -8,12 +8,24 @@ if (isset($_POST['add_document_template'])) {
$name = sanitizeInput($_POST['name']);
$description = sanitizeInput($_POST['description']);
- $content = mysqli_real_escape_string($mysqli,$_POST['content']);
- mysqli_query($mysqli,"INSERT INTO document_templates SET document_template_name = '$name', document_template_description = '$description', document_template_content = '$content', document_template_created_by = $session_user_id");
+ mysqli_query($mysqli,"INSERT INTO document_templates SET document_template_name = '$name', document_template_description = '$description', document_template_content = '', document_template_created_by = $session_user_id");
$document_template_id = mysqli_insert_id($mysqli);
+ $processed_content = mysqli_escape_string(
+ $mysqli,
+ saveBase64Images(
+ $_POST['content'],
+ $_SERVER['DOCUMENT_ROOT'] . "/uploads/document_templates/",
+ "uploads/document_templates/",
+ $document_template_id
+ )
+ );
+
+ // Document template update content
+ mysqli_query($mysqli,"UPDATE document_templates SET document_template_content = '$processed_content' WHERE document_template_id = $document_template_id");
+
logAction("Document Template", "Create", "$session_name created document template $name", 0, $document_template_id);
flash_alert("Document template $name created");
@@ -27,10 +39,19 @@ if (isset($_POST['edit_document_template'])) {
$document_template_id = intval($_POST['document_template_id']);
$name = sanitizeInput($_POST['name']);
$description = sanitizeInput($_POST['description']);
- $content = mysqli_real_escape_string($mysqli,$_POST['content']);
+
+ $processed_content = mysqli_escape_string(
+ $mysqli,
+ saveBase64Images(
+ $_POST['content'],
+ $_SERVER['DOCUMENT_ROOT'] . "/uploads/document_templates/",
+ "uploads/document_templates/",
+ $document_template_id
+ )
+ );
// Document edit query
- mysqli_query($mysqli,"UPDATE document_templates SET document_template_name = '$name', document_template_description = '$description', document_template_content = '$content', document_template_updated_by = $session_user_id WHERE document_template_id = $document_template_id");
+ mysqli_query($mysqli,"UPDATE document_templates SET document_template_name = '$name', document_template_description = '$description', document_template_content = '$processed_content', document_template_updated_by = $session_user_id WHERE document_template_id = $document_template_id");
logAction("Document Template", "Edit", "$session_name edited document template $name", 0, $document_template_id);
@@ -48,6 +69,9 @@ if (isset($_GET['delete_document_template'])) {
mysqli_query($mysqli,"DELETE FROM document_templates WHERE document_template_id = $document_template_id");
+ // Delete uploads/document_templates/$document_template_id if exists
+ removeDirectory($_SERVER['DOCUMENT_ROOT'] . "/uploads/document_templates/" . $document_template_id);
+
logAction("Document Template", "Delete", "$session_name deleted document template $document_template_name");
flash_alert("Document Template $document_template_name deleted", 'error');