From: naina Date: Wed, 9 Jan 2013 14:06:58 +0000 (+0530) Subject: Final bug fix X-Git-Tag: whats-been-changed~460 X-Git-Url: https://repo.or.cz/w/openemr.git/commitdiff_plain/6b6743586899a1e5f97082d6e18752ed1fc0810e Final bug fix Formdata function removed from save.php --- diff --git a/interface/forms/aftercare_plan/save.php b/interface/forms/aftercare_plan/save.php index 3e3aa73bc..a891b2fa0 100644 --- a/interface/forms/aftercare_plan/save.php +++ b/interface/forms/aftercare_plan/save.php @@ -28,8 +28,7 @@ include_once("../../globals.php"); include_once("$srcdir/api.inc"); include_once("$srcdir/forms.inc"); -require_once("$srcdir/htmlspecialchars.inc.php"); -require_once("$srcdir/formdata.inc.php"); + if (! $encounter) { // comes from globals.php die(xl("Internal error: we do not seem to be in an encounter!")); @@ -40,17 +39,17 @@ $sets = "pid = {$_SESSION["pid"]}, groupname = '" . $_SESSION["authProvider"] . "', user = '" . $_SESSION["authUser"] . "', authorized = $userauthorized, activity=1, date = NOW(), - provider = '" . add_escape_custom(formData("provider")) . "', - client_name = '" . add_escape_custom(formData("client_name")) . "', - admit_date = '" . add_escape_custom(formData("admit_date")) . "', - discharged = '" . add_escape_custom(formData("discharged")) . "', - goal_a_acute_intoxication = '" . add_escape_custom(formData("goal_a_acute_intoxication")) . "', - goal_a_acute_intoxication_I = '" . add_escape_custom(formData("goal_a_acute_intoxication_I")) . "', - goal_a_acute_intoxication_II = '" . add_escape_custom(formData("goal_a_acute_intoxication_II")) . "', - goal_b_emotional_behavioral_conditions = '" . add_escape_custom(formData("goal_b_emotional_behavioral_conditions")) . "', - goal_b_emotional_behavioral_conditions_I = '" . add_escape_custom(formData("goal_b_emotional_behavioral_conditions_I")) . "', - goal_c_relapse_potential = '" . add_escape_custom(formData("goal_c_relapse_potential")) . "', - goal_c_relapse_potential_I = '" . add_escape_custom(formData("goal_c_relapse_potential_I")) . "'"; + provider = '" .add_escape_custom($_POST["provider"]) . "', + client_name = '" .add_escape_custom($_POST["client_name"]) . "', + admit_date = '" .add_escape_custom($_POST["admit_date"]) . "', + discharged = '" .add_escape_custom($_POST["discharged"]) . "', + goal_a_acute_intoxication = '" . add_escape_custom($_POST["goal_a_acute_intoxication"]) . "', + goal_a_acute_intoxication_I = '" . add_escape_custom($_POST["goal_a_acute_intoxication_I"]) . "', + goal_a_acute_intoxication_II = '" . add_escape_custom($_POST["goal_a_acute_intoxication_II"]) . "', + goal_b_emotional_behavioral_conditions = '" . add_escape_custom($_POST["goal_b_emotional_behavioral_conditions"]) . "', + goal_b_emotional_behavioral_conditions_I = '" . add_escape_custom($_POST["goal_b_emotional_behavioral_conditions_I"]) . "', + goal_c_relapse_potential = '" . add_escape_custom($_POST["goal_c_relapse_potential"]) . "', + goal_c_relapse_potential_I = '" . add_escape_custom($_POST["goal_c_relapse_potential_I"]) . "'"; if (empty($id)) { diff --git a/interface/forms/transfer_summary/save.php b/interface/forms/transfer_summary/save.php index d78dd8ffc..c961ab801 100644 --- a/interface/forms/transfer_summary/save.php +++ b/interface/forms/transfer_summary/save.php @@ -40,14 +40,14 @@ $sets = "pid = {$_SESSION["pid"]}, groupname = '" . $_SESSION["authProvider"] . "', user = '" . $_SESSION["authUser"] . "', authorized = $userauthorized, activity=1, date = NOW(), - provider = '" . add_escape_custom(formData("provider")) . "', - client_name = '" . add_escape_custom(formData("client_name")) . "', - transfer_to = '" . add_escape_custom(formData("transfer_to")) . "', - transfer_date = '" . add_escape_custom(formData("transfer_date")) . "', - status_of_admission = '" . add_escape_custom(formData("status_of_admission")) . "', - diagnosis = '" . add_escape_custom(formData("diagnosis")) . "', - intervention_provided = '" . add_escape_custom(formData("intervention_provided")) . "', - overall_status_of_discharge = '" . add_escape_custom(formData("overall_status_of_discharge")) ."'"; + provider = '" . add_escape_custom($_POST["provider"]) . "', + client_name = '" . add_escape_custom($_POST["client_name"]) . "', + transfer_to = '" . add_escape_custom($_POST["transfer_to"]) . "', + transfer_date = '" . add_escape_custom($_POST["transfer_date"]) . "', + status_of_admission = '" . add_escape_custom($_POST["status_of_admission"]) . "', + diagnosis = '" . add_escape_custom($_POST["diagnosis"]) . "', + intervention_provided = '" . add_escape_custom($_POST["intervention_provided"]) . "', + overall_status_of_discharge = '" . add_escape_custom($_POST["overall_status_of_discharge"]) ."'"; if (empty($id)) { diff --git a/interface/forms/treatment_plan/save.php b/interface/forms/treatment_plan/save.php index ccf1e531e..810be3aca 100644 --- a/interface/forms/treatment_plan/save.php +++ b/interface/forms/treatment_plan/save.php @@ -39,17 +39,17 @@ $sets = "pid = {$_SESSION["pid"]}, groupname = '" . $_SESSION["authProvider"] . "', user = '" . $_SESSION["authUser"] . "', authorized = $userauthorized, activity=1, date = NOW(), - provider = '" . add_escape_custom(formData("provider")) . "', - client_name = '" . add_escape_custom(formData("client_name")) . "', - client_number = '" . add_escape_custom(formData("client_number")) . "', - admit_date = '" . add_escape_custom(formData("admit_date")) . "', - presenting_issues = '" . add_escape_custom(formData("presenting_issues")) . "', - patient_history = '" . add_escape_custom(formData("patient_history")) . "', - medications = '" . add_escape_custom(formData("medications")) . "', - anyother_relevant_information = '" . add_escape_custom(formData("anyother_relevant_information")) . "', - diagnosis = '" . add_escape_custom(formData("diagnosis")) . "', - treatment_received = '" . add_escape_custom(formData("treatment_received")) . "', - recommendation_for_follow_up = '" . add_escape_custom(formData("recommendation_for_follow_up")) . "'"; + provider = '" . add_escape_custom($_POST["provider"]) . "', + client_name = '" . add_escape_custom($_POST["client_name"]) . "', + client_number = '" . add_escape_custom($_POST["client_number"]) . "', + admit_date = '" . add_escape_custom($_POST["admit_date"]) . "', + presenting_issues = '" . add_escape_custom($_POST["presenting_issues"]) . "', + patient_history = '" . add_escape_custom($_POST["patient_history"]) . "', + medications = '" . add_escape_custom($_POST["medications"]) . "', + anyother_relevant_information = '" . add_escape_custom($_POST["anyother_relevant_information"]) . "', + diagnosis = '" . add_escape_custom($_POST["diagnosis"]) . "', + treatment_received = '" . add_escape_custom($_POST["treatment_received"]) . "', + recommendation_for_follow_up = '" . add_escape_custom($_POST["recommendation_for_follow_up"]) . "'";