Bug 25898: Prohibit indirect object notation
[koha.git] / acqui / ordered.pl
blob20be8a04622e618320b6885a8c0a9a50ee8c8306
1 #!/usr/bin/perl
3 # Copyright 2008 - 2009 BibLibre SARL
4 # Copyright 2010,2011 Catalyst IT Limited
5 # This file is part of Koha.
7 # Koha is free software; you can redistribute it and/or modify it
8 # under the terms of the GNU General Public License as published by
9 # the Free Software Foundation; either version 3 of the License, or
10 # (at your option) any later version.
12 # Koha is distributed in the hope that it will be useful, but
13 # WITHOUT ANY WARRANTY; without even the implied warranty of
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 # GNU General Public License for more details.
17 # You should have received a copy of the GNU General Public License
18 # along with Koha; if not, see <http://www.gnu.org/licenses>.
20 =head1 NAME
22 ordered.pl
24 =head1 DESCRIPTION
26 this script is to show orders ordered but not yet received
28 =cut
30 use C4::Context;
31 use Modern::Perl;
32 use CGI qw ( -utf8 );
33 use C4::Auth;
34 use C4::Output;
35 use Koha::Acquisition::Invoice::Adjustments;
36 use C4::Acquisition;
38 my $dbh = C4::Context->dbh;
39 my $input = CGI->new;
40 my $fund_id = $input->param('fund');
41 my $fund_code = $input->param('fund_code');
43 my ( $template, $loggedinuser, $cookie ) = get_template_and_user(
45 template_name => "acqui/ordered.tt",
46 query => $input,
47 type => "intranet",
48 flagsrequired => { acquisition => '*' },
49 debug => 1,
53 my $query = <<EOQ;
54 SELECT
55 aqorders.biblionumber, aqorders.basketno, aqorders.ordernumber,
56 quantity-quantityreceived AS tleft,
57 ecost_tax_included, budgetdate, entrydate,
58 aqbasket.booksellerid,
59 aqbooksellers.name as vendorname,
60 GROUP_CONCAT(DISTINCT itype SEPARATOR '|') AS itypes,
61 title
62 FROM aqorders
63 JOIN aqbasket USING (basketno)
64 LEFT JOIN biblio ON
65 biblio.biblionumber=aqorders.biblionumber
66 LEFT JOIN aqorders_items ON
67 aqorders.ordernumber=aqorders_items.ordernumber
68 LEFT JOIN items ON
69 items.itemnumber=aqorders_items.itemnumber
70 LEFT JOIN aqbooksellers ON
71 aqbasket.booksellerid = aqbooksellers.id
72 WHERE
73 budget_id=? AND
74 (datecancellationprinted IS NULL OR
75 datecancellationprinted='0000-00-00') AND
76 (quantity > quantityreceived OR quantityreceived IS NULL)
77 GROUP BY aqorders.biblionumber, aqorders.basketno, aqorders.ordernumber,
78 tleft,
79 ecost_tax_included, budgetdate, entrydate,
80 aqbasket.booksellerid,
81 aqbooksellers.name,
82 title
83 EOQ
85 my $sth = $dbh->prepare($query);
87 $sth->execute($fund_id);
88 if ( $sth->err ) {
89 die "Error occurred fetching records: " . $sth->errstr;
91 my @ordered;
93 my $total = 0;
94 while ( my $data = $sth->fetchrow_hashref ) {
95 $data->{'itemtypes'} = [split('\|', $data->{itypes})];
96 my $left = $data->{'tleft'};
97 if ( !$left || $left eq '' ) {
98 $left = $data->{'quantity'};
100 if ( $left && $left > 0 ) {
101 my $subtotal = $left * get_rounded_price( $data->{'ecost_tax_included'} );
102 $data->{subtotal} = sprintf( "%.2f", $subtotal );
103 $data->{'left'} = $left;
104 push @ordered, $data;
105 $total += $subtotal;
109 my $adjustments = Koha::Acquisition::Invoice::Adjustments->search({budget_id => $fund_id, closedate => undef, encumber_open => 1 }, { prefetch => 'invoiceid' } );
110 while ( my $adj = $adjustments->next ){
111 $total += $adj->adjustment;
114 $total = sprintf( "%.2f", $total );
116 $template->{VARS}->{'fund'} = $fund_id;
117 $template->{VARS}->{'ordered'} = \@ordered;
118 $template->{VARS}->{'total'} = $total;
119 $template->{VARS}->{'fund_code'} = $fund_code;
120 $template->{VARS}->{'adjustments'} = $adjustments;
122 $sth->finish;
124 output_html_with_http_headers $input, $cookie, $template->output;