Additional Sql-injection functions and techniques for escaping;
[openemr.git] / interface / forms / note / print.php
blobd7a90cb2b520f3553d9fe1de828020c5b47009f0
1 <?php
3 $fake_register_globals=false;
4 $sanitize_all_escapes=true;
6 include_once("../../globals.php");
7 include_once("$srcdir/api.inc");
8 formHeader("Form: note");
9 $returnurl = $GLOBALS['concurrent_layout'] ? 'encounter_top.php' : 'patient_encounter.php';
10 $provider_results = sqlQuery("select fname, lname from users where username=?",array($_SESSION{"authUser"}));
12 /* name of this form */
13 $form_name = "note";
15 // get the record from the database
16 if ($_GET['id'] != "") $obj = formFetch("form_".$form_name, $_GET["id"]);
17 /* remove the time-of-day from the date fields */
18 if ($obj['date_of_signature'] != "") {
19 $dateparts = split(" ", $obj['date_of_signature']);
20 $obj['date_of_signature'] = $dateparts[0];
23 <html><head>
24 <?php html_header_show();?>
25 <link rel="stylesheet" href="<?php echo $css_header;?>" type="text/css">
27 <!-- supporting javascript code -->
28 <script type="text/javascript" src="<?php echo $GLOBALS['webroot'] ?>/library/js/jquery.js"></script>
30 </head>
31 <body class="body_top">
33 <form method=post action="">
34 <span class="title"><?php echo xlt('Work/School Note'); ?></span><br></br>
35 <?php echo xlt('Printed'); ?> <?php echo dateformat(); ?>
36 <br><br>
37 <select name="note_type">
38 <option value="WORK NOTE" <?php if ($obj['note_type']=="WORK NOTE") echo " SELECTED"; ?>><?php echo xlt('WORK NOTE'); ?></option>
39 <option value="SCHOOL NOTE" <?php if ($obj['note_type']=="SCHOOL NOTE") echo " SELECTED"; ?>><?php echo xlt('SCHOOL NOTE'); ?></option>
40 </select>
41 <br>
42 <b><?php echo xlt('MESSAGE:'); ?></b>
43 <br>
44 <div style="border: 1px solid black; padding: 5px; margin: 5px;"><?php echo text($obj["message"]);?></div>
45 <br></br>
47 <table>
48 <tr><td>
49 <span class=text><?php echo xlt('Doctor:'); ?> </span><input type=text name="doctor" value="<?php echo attr($obj["doctor"]);?>">
50 </td><td>
51 <span class="text"><?php echo xlt('Date'); ?></span>
52 <input type='text' size='10' name='date_of_signature' id='date_of_signature'
53 value='<?php echo attr($obj['date_of_signature']); ?>'
55 </td></tr>
56 </table>
58 </form>
60 </body>
62 <script language="javascript">
63 // jQuery stuff to make the page a little easier to use
65 $(document).ready(function(){
66 window.print();
67 window.close();
68 });
70 </script>
72 </html>