From c9317e6374542186432f90f0c54c5a97b791bf71 Mon Sep 17 00:00:00 2001 From: mattf Date: Fri, 16 Mar 2012 16:14:43 +0000 Subject: [PATCH] Removed single-quotes and backslashes in custom field data where it had not previously been filtered Fixed DIALABLE counts for Completed statuses git-svn-id: svn://192.168.202.10@1797 3d104415-ff17-0410-8863-d5cf3c621b8a --- www/agc/vdc_form_display.php | 9 ++++++--- www/vicidial/admin.php | 23 +++++++++++++++++------ www/vicidial/non_agent_api.php | 7 +++++++ 3 files changed, 30 insertions(+), 9 deletions(-) diff --git a/www/agc/vdc_form_display.php b/www/agc/vdc_form_display.php index de71058b..928fe0ed 100644 --- a/www/agc/vdc_form_display.php +++ b/www/agc/vdc_form_display.php @@ -1,7 +1,7 @@ LICENSE: AGPLv2 +# Copyright (C) 2012 Matt Florell LICENSE: AGPLv2 # # This script is designed display the contents of the FORM tab in the agent # interface, as well as take submission of the form submission when the agent @@ -15,10 +15,11 @@ # 110719-0856 - Added HIDEBLOB type # 110730-2335 - Added call_id variable # 111025-1433 - Fixed case sensitivity on list fields +# 120315-1729 - Filtere out single quotes and backslashes from custom fields # -$version = '2.4-7'; -$build = '111025-1433'; +$version = '2.4-8'; +$build = '120315-1729'; require("dbconnect.php"); require_once("functions.php"); @@ -286,6 +287,8 @@ if ($stage=='SUBMIT') if (isset($_GET["$field_name_id"])) {$form_field_value=$_GET["$field_name_id"];} elseif (isset($_POST["$field_name_id"])) {$form_field_value=$_POST["$field_name_id"];} + $form_field_value = preg_replace("/\'/","",$form_field_value); // remove single-quote + $form_field_value = preg_replace("/\\b/","",$form_field_value); // remove backslashes if ( ($A_field_type[$o]=='MULTI') or ($A_field_type[$o]=='CHECKBOX') or ($A_field_type[$o]=='RADIO') ) { diff --git a/www/vicidial/admin.php b/www/vicidial/admin.php index 0f98ec27..30fc577b 100644 --- a/www/vicidial/admin.php +++ b/www/vicidial/admin.php @@ -3043,12 +3043,13 @@ else # 120213-1512 - Added remote agent max stats display and campaign VLC hopper dup check option # 120221-0054 - Fixed Call Time and User Group restrictions on several pages # 120221-1647 - Added inventory report options to lists and shifts +# 120316-1203 - Fixed DIALBLE counts for completed statuses # # make sure you have added a user to the vicidial_users MySQL table with at least user_level 8 to access this page the first time -$admin_version = '2.4-361a'; -$build = '120221-1647'; +$admin_version = '2.4-362a'; +$build = '120316-1203'; $STARTtime = date("U"); $SQLdate = date("Y-m-d H:i:s"); @@ -21704,7 +21705,7 @@ if ($ADD==31) if ( ($display_leads_count == 'Y') and (strlen($camp_lists) > 3) ) { # grab names of global statuses and statuses in the selected campaign - $stmt="SELECT status,status_name from vicidial_statuses order by status;"; + $stmt="SELECT status,status_name,completed from vicidial_statuses order by status;"; $rslt=mysql_query($stmt, $link); $statuses_to_print = mysql_num_rows($rslt); @@ -21713,10 +21714,11 @@ if ($ADD==31) { $rowx=mysql_fetch_row($rslt); $statuses_name_list["$rowx[0]"] = "$rowx[1]"; + $statuses_complete_list["$rowx[0]"] = "$rowx[2]"; $o++; } - $stmt="SELECT status,status_name from vicidial_campaign_statuses where campaign_id='$campaign_id' $LOGallowed_campaignsSQL order by status;"; + $stmt="SELECT status,status_name,completed from vicidial_campaign_statuses where campaign_id='$campaign_id' $LOGallowed_campaignsSQL order by status;"; $rslt=mysql_query($stmt, $link); $Cstatuses_to_print = mysql_num_rows($rslt); @@ -21725,6 +21727,7 @@ if ($ADD==31) { $rowx=mysql_fetch_row($rslt); $statuses_name_list["$rowx[0]"] = "$rowx[1]"; + $statuses_complete_list["$rowx[0]"] = "$rowx[2]"; $o++; } # end grab status names @@ -21823,7 +21826,10 @@ if ($ADD==31) ### call function to calculate dialable leads $single_status=1; $dial_statuses=" $dispo -"; - $Xdialable_count = dialable_leads($DB,$link,$local_call_time,$dial_statuses,$camp_lists,$drop_lockout_time,$call_count_limit,$single_status,$fSQL); + if ($statuses_complete_list[$dispo] == 'Y') + {$Xdialable_count=0;} + else + {$Xdialable_count = dialable_leads($DB,$link,$local_call_time,$dial_statuses,$camp_lists,$drop_lockout_time,$call_count_limit,$single_status,$fSQL);} $dialable_total = ($dialable_total + $Xdialable_count); ### get number of complete calls of this status for penetration calculations @@ -24130,6 +24136,7 @@ if ($ADD==311) { $rowx=mysql_fetch_row($rslt); $statuses_list["$rowx[0]"] = "$rowx[1]"; + $statuses_complete_list["$rowx[0]"] = "$rowx[11]"; $o++; } @@ -24142,6 +24149,7 @@ if ($ADD==311) { $rowx=mysql_fetch_row($rslt); $statuses_list["$rowx[0]"] = "$rowx[1]"; + $statuses_complete_list["$rowx[0]"] = "$rowx[12]"; $o++; } # end grab status names @@ -24355,7 +24363,10 @@ if ($ADD==311) $single_status=1; $dial_statuses=" $dispo -"; $camp_lists=$list_id; - $Xdialable_count = dialable_leads($DB,$link,$local_call_time,$dial_statuses,$camp_lists,$drop_lockout_time,$call_count_limit,$single_status,$fSQL); + if ($statuses_complete_list[$dispo] == 'Y') + {$Xdialable_count=0;} + else + {$Xdialable_count = dialable_leads($DB,$link,$local_call_time,$dial_statuses,$camp_lists,$drop_lockout_time,$call_count_limit,$single_status,$fSQL);} $dialable_total = ($dialable_total + $Xdialable_count); ### get number of complete calls of this status for penetration calculations diff --git a/www/vicidial/non_agent_api.php b/www/vicidial/non_agent_api.php index c081c09d..61f75f95 100644 --- a/www/vicidial/non_agent_api.php +++ b/www/vicidial/non_agent_api.php @@ -63,6 +63,7 @@ # 120127-1331 - Small fix for plus replacement in custom fields strings for add/update_lead functions # 120210-1215 - Small change for hopper adding vendor_lead_code # 120213-1613 - Added optional logging of all non-admin.php requests, enabled in options.php +# 120315-1537 - Added filter for single-quotes and backslashes on custom field data # $version = '2.4-42'; @@ -3902,6 +3903,8 @@ if ($function == 'add_lead') elseif (isset($_POST["$field_name_id"])) {$form_field_value=$_POST["$field_name_id"];} $form_field_value = preg_replace("/\+/"," ",$form_field_value); + $form_field_value = preg_replace("/\'/","",$form_field_value); + $form_field_value = preg_replace("/\\b/","",$form_field_value); $A_field_value[$o] = $form_field_value; if ( ($A_field_type[$o]=='DISPLAY') or ($A_field_type[$o]=='SCRIPT') ) @@ -4568,6 +4571,8 @@ if ($function == 'update_lead') elseif (isset($_POST["$field_name_id"])) {$form_field_value=$_POST["$field_name_id"];} $form_field_value = preg_replace("/\+/"," ",$form_field_value); + $form_field_value = preg_replace("/\'/","",$form_field_value); + $form_field_value = preg_replace("/\\b/","",$form_field_value); $A_field_value[$o] = $form_field_value; if ( ($A_field_type[$o]=='DISPLAY') or ($A_field_type[$o]=='SCRIPT') ) @@ -4762,6 +4767,8 @@ if ($function == 'update_lead') elseif (isset($_POST["$field_name_id"])) {$form_field_value=$_POST["$field_name_id"];} $form_field_value = preg_replace("/\+/"," ",$form_field_value); + $form_field_value = preg_replace("/\'/","",$form_field_value); + $form_field_value = preg_replace("/\\b/","",$form_field_value); $A_field_value[$o] = $form_field_value; if ( ($A_field_type[$o]=='DISPLAY') or ($A_field_type[$o]=='SCRIPT') )