Bug 25898: Prohibit indirect object notation
[koha.git] / circ / reserveratios.pl
blob47b0375387f5a02c4fa0f82d1a620157fdd41de9
1 #!/usr/bin/perl
4 # Copyright 2000-2002 Katipo Communications
6 # This file is part of Koha.
8 # Koha is free software; you can redistribute it and/or modify it
9 # under the terms of the GNU General Public License as published by
10 # the Free Software Foundation; either version 3 of the License, or
11 # (at your option) any later version.
13 # Koha is distributed in the hope that it will be useful, but
14 # WITHOUT ANY WARRANTY; without even the implied warranty of
15 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 # GNU General Public License for more details.
18 # You should have received a copy of the GNU General Public License
19 # along with Koha; if not, see <http://www.gnu.org/licenses>.
21 use Modern::Perl;
23 use CGI qw ( -utf8 );
24 use Date::Calc qw/Today Add_Delta_YM/;
25 use POSIX qw( ceil );
27 use C4::Context;
28 use C4::Output;
29 use C4::Auth;
30 use C4::Debug;
31 use C4::Acquisition qw/GetOrdersByBiblionumber/;
32 use Koha::DateUtils;
33 use Koha::Acquisition::Baskets;
35 my $input = CGI->new;
36 my $startdate = $input->param('from');
37 my $enddate = $input->param('to');
38 my $ratio = $input->param('ratio');
39 my $include_ordered = $input->param('include_ordered');
40 my $include_suspended = $input->param('include_suspended');
42 my ( $template, $loggedinuser, $cookie ) = get_template_and_user(
44 template_name => "circ/reserveratios.tt",
45 query => $input,
46 type => "intranet",
47 flagsrequired => { circulate => "circulate_remaining_permissions" },
48 debug => 1,
52 my $booksellerid = $input->param('booksellerid') // '';
53 my $basketno = $input->param('basketno') // '';
54 if ($booksellerid && $basketno) {
55 $template->param( booksellerid => $booksellerid, basketno => $basketno );
58 my $effective_create_items = q{};
59 if ( $basketno ){
60 my $basket = Koha::Acquisition::Baskets->find( $basketno );
61 if ($basket){
62 $effective_create_items = $basket->effective_create_items;
63 } else {
64 $effective_create_items = C4::Context->preference('AcqCreateItem');
68 $startdate = eval { dt_from_string( $startdate ) } if $startdate;
69 $enddate = eval { dt_from_string( $enddate ) } if $enddate;
71 my $todaysdate = dt_from_string;
73 # A default of the prior years's holds is a reasonable way to pull holds
74 $enddate = $todaysdate unless $enddate;
75 $startdate = $todaysdate->clone->subtract( years => 1 ) unless $startdate;
77 if (!defined($ratio)) {
78 $ratio = 3;
80 # Force to be a number
81 $ratio += 0;
82 if ($ratio <= 0) {
83 $ratio = 1; # prevent division by zero
86 my $dbh = C4::Context->dbh;
87 my $sqldatewhere = "";
88 $debug and warn output_pref({ dt => $startdate, dateformat => 'iso', dateonly => 1 }) . "\n" . output_pref({ dt => $enddate, dateformat => 'iso', dateonly => 1 });
89 my @query_params = ();
91 $sqldatewhere .= " AND reservedate >= ?";
92 push @query_params, output_pref({ dt => $startdate, dateformat => 'iso' }) ;
93 $sqldatewhere .= " AND reservedate <= ?";
94 push @query_params, output_pref({ dt => $enddate, dateformat => 'iso' });
96 my $include_aqorders_qty =
97 $effective_create_items eq 'receiving'
98 ? '+ COALESCE(aqorders.quantity, 0) - COALESCE(aqorders.quantityreceived, 0)'
99 : q{};
101 my $include_aqorders_qty_join =
102 $effective_create_items eq 'receiving'
103 ? 'LEFT JOIN aqorders ON reserves.biblionumber=aqorders.biblionumber'
104 : q{};
106 my $nfl_comparison = $include_ordered ? '<=' : '=';
107 my $sus_comparison = $include_suspended ? '<=' : '<';
108 my $strsth =
109 "SELECT reservedate,
110 reserves.borrowernumber as borrowernumber,
111 reserves.biblionumber,
112 reserves.branchcode as branch,
113 items.holdingbranch,
114 items.itemcallnumber,
115 items.itemnumber,
116 GROUP_CONCAT(DISTINCT items.itemcallnumber
117 ORDER BY items.itemnumber SEPARATOR '|') as listcall,
118 GROUP_CONCAT(DISTINCT homebranch
119 ORDER BY items.itemnumber SEPARATOR '|') as homebranch_list,
120 GROUP_CONCAT(DISTINCT holdingbranch
121 ORDER BY items.itemnumber SEPARATOR '|') as holdingbranch_list,
122 GROUP_CONCAT(DISTINCT items.location
123 ORDER BY items.itemnumber SEPARATOR '|') as l_location,
124 GROUP_CONCAT(DISTINCT items.itype
125 ORDER BY items.itemnumber SEPARATOR '|') as l_itype,
127 reserves.found,
128 biblio.title,
129 biblio.subtitle,
130 biblio.medium,
131 biblio.part_number,
132 biblio.part_name,
133 biblio.author,
134 count(DISTINCT reserves.borrowernumber) as reservecount,
135 count(DISTINCT items.itemnumber) $include_aqorders_qty as itemcount
136 FROM reserves
137 LEFT JOIN items ON items.biblionumber=reserves.biblionumber
138 LEFT JOIN biblio ON reserves.biblionumber=biblio.biblionumber
139 $include_aqorders_qty_join
140 WHERE
141 notforloan $nfl_comparison 0 AND damaged = 0 AND itemlost = 0 AND withdrawn = 0
142 AND suspend $sus_comparison 1
143 $sqldatewhere
146 if (C4::Context->preference('IndependentBranches')){
147 $strsth .= " AND items.holdingbranch=? ";
148 push @query_params, C4::Context->userenv->{'branch'};
151 $strsth .= " GROUP BY reserves.biblionumber ORDER BY reservecount DESC";
153 $template->param(sql => $strsth);
154 my $sth = $dbh->prepare($strsth);
155 $sth->execute(@query_params);
157 my @reservedata;
158 while ( my $data = $sth->fetchrow_hashref ) {
159 my $thisratio = $data->{reservecount} / $data->{itemcount};
160 my $ratiocalc = ceil($data->{reservecount}/$ratio - $data->{itemcount});
161 $ratiocalc >= 1 or next; # TODO: tighter targeting -- get ratio limit into SQL using HAVING clause
162 push(
163 @reservedata,
165 reservedate => $data->{reservedate},
166 priority => $data->{priority},
167 name => $data->{borrower},
168 title => $data->{title},
169 subtitle => $data->{subtitle},
170 medium => $data->{medium},
171 part_number => $data->{part_number},
172 part_name => $data->{part_name},
173 author => $data->{author},
174 itemnum => $data->{itemnumber},
175 biblionumber => $data->{biblionumber},
176 holdingbranch => $data->{holdingbranch},
177 homebranch_list => [split('\|', $data->{homebranch_list})],
178 holdingbranch_list => [split('\|', $data->{holdingbranch_list})],
179 branch => $data->{branch},
180 itemcallnumber => $data->{itemcallnumber},
181 location => [split('\|', $data->{l_location})],
182 itype => [split('\|', $data->{l_itype})],
183 reservecount => $data->{reservecount},
184 itemcount => $data->{itemcount},
185 ratiocalc => sprintf( "%.0d", $ratiocalc ),
186 thisratio => sprintf( "%.2f", $thisratio ),
187 thisratio_atleast1 => ( $thisratio >= 1 ) ? 1 : 0,
188 listcall => [split('\|', $data->{listcall})]
193 for my $rd ( @reservedata ) {
194 next unless $rd->{biblionumber};
195 $rd->{pendingorders} = CountPendingOrdersByBiblionumber( $rd->{biblionumber} );
198 $template->param(
199 todaysdate => $todaysdate,
200 from => $startdate,
201 to => $enddate,
202 ratio => $ratio,
203 include_ordered => $include_ordered,
204 include_suspended => $include_suspended,
205 reserveloop => \@reservedata,
208 output_html_with_http_headers $input, $cookie, $template->output;
210 sub CountPendingOrdersByBiblionumber {
211 my $biblionumber = shift;
212 my @orders = GetOrdersByBiblionumber( $biblionumber );
213 my $cnt = 0;
214 if (scalar(@orders)) {
215 for my $order ( @orders ) {
216 next if $order->{datecancellationprinted};
217 my $onum = $order->{quantity} // 0;
218 my $rnum = $order->{quantityreceived} // 0;
219 next if $rnum >= $onum;
220 $cnt += ($onum - $rnum);
223 return $cnt;