diff --git a/api/v1/assets/asset_model.php b/api/v1/assets/asset_model.php index 56453db6..0700902a 100644 --- a/api/v1/assets/asset_model.php +++ b/api/v1/assets/asset_model.php @@ -72,6 +72,14 @@ if (isset($_POST['asset_mac'])) { $mac = ''; } +if (isset($_POST['asset_uri'])) { + $uri = sanitizeInput($_POST['asset_uri']); +} elseif (isset($asset_row) && isset($asset_row['asset_uri'])) { + $uri = $asset_row['asset_uri']; +} else { + $uri = ''; +} + if (isset($_POST['asset_status'])) { $status = sanitizeInput($_POST['asset_status']); } elseif (isset($asset_row) && isset($asset_row['asset_status'])) { diff --git a/api/v1/assets/create.php b/api/v1/assets/create.php index 77946aac..4dd375b5 100644 --- a/api/v1/assets/create.php +++ b/api/v1/assets/create.php @@ -11,7 +11,7 @@ $insert_id = false; if (!empty($name) && !empty($client_id)) { // Insert into Database - $insert_sql = mysqli_query($mysqli, "INSERT INTO assets SET asset_name = '$name', asset_description = '$description', asset_type = '$type', asset_make = '$make', asset_model = '$model', asset_serial = '$serial', asset_os = '$os', asset_ip = '$aip', asset_mac = '$mac', asset_status = '$status', asset_location_id = $location, asset_vendor_id = $vendor, asset_contact_id = $contact, asset_purchase_date = $purchase_date, asset_warranty_expire = $warranty_expire, asset_install_date = $install_date, asset_notes = '$notes', asset_network_id = $network, asset_client_id = $client_id"); + $insert_sql = mysqli_query($mysqli, "INSERT INTO assets SET asset_name = '$name', asset_description = '$description', asset_type = '$type', asset_make = '$make', asset_model = '$model', asset_serial = '$serial', asset_os = '$os', asset_ip = '$aip', asset_mac = '$mac', asset_uri = '$uri', asset_status = '$status', asset_location_id = $location, asset_vendor_id = $vendor, asset_contact_id = $contact, asset_purchase_date = $purchase_date, asset_warranty_expire = $warranty_expire, asset_install_date = $install_date, asset_notes = '$notes', asset_network_id = $network, asset_client_id = $client_id"); if ($insert_sql) { $insert_id = mysqli_insert_id($mysqli); diff --git a/api/v1/assets/read.php b/api/v1/assets/read.php index b3d4c805..bd90357d 100644 --- a/api/v1/assets/read.php +++ b/api/v1/assets/read.php @@ -37,6 +37,12 @@ if (isset($_GET['asset_id'])) { $mac = mysqli_real_escape_string($mysqli, $_GET['asset_mac']); $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_mac = '$mac' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); +} elseif (isset($_GET['asset_uri'])) { + // Asset query via mac + + $mac = mysqli_real_escape_string($mysqli, $_GET['asset_uri']); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri = '$uri' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + } // All assets else { diff --git a/api/v1/assets/update.php b/api/v1/assets/update.php index 7cdfb89b..f95d15f4 100644 --- a/api/v1/assets/update.php +++ b/api/v1/assets/update.php @@ -16,7 +16,7 @@ if (!empty($asset_id)) { // Variable assignment from POST - assigning the current database value if a value is not provided require_once('asset_model.php'); - $update_sql = mysqli_query($mysqli, "UPDATE assets SET asset_name = '$name', asset_description = '$description', asset_type = '$type', asset_make = '$make', asset_model = '$model', asset_serial = '$serial', asset_os = '$os', asset_ip = '$aip', asset_mac = '$mac', asset_status = '$status', asset_location_id = $location, asset_vendor_id = $vendor, asset_contact_id = $contact, asset_purchase_date = $purchase_date, asset_warranty_expire = $warranty_expire, asset_install_date = $install_date, asset_notes = '$notes', asset_network_id = $network WHERE asset_id = $asset_id AND asset_client_id = $client_id LIMIT 1"); + $update_sql = mysqli_query($mysqli, "UPDATE assets SET asset_name = '$name', asset_description = '$description', asset_type = '$type', asset_make = '$make', asset_model = '$model', asset_serial = '$serial', asset_os = '$os', asset_ip = '$aip', asset_mac = '$mac', asset_uri = '$uri', asset_status = '$status', asset_location_id = $location, asset_vendor_id = $vendor, asset_contact_id = $contact, asset_purchase_date = $purchase_date, asset_warranty_expire = $warranty_expire, asset_install_date = $install_date, asset_notes = '$notes', asset_network_id = $network WHERE asset_id = $asset_id AND asset_client_id = $client_id LIMIT 1"); // Check insert & get insert ID if ($update_sql) {