Revert "Bug 17902: Fix possible SQL injection in serials editing"
[koha.git] / serials / lateissues-export.pl
blobcc23ddc0c917ff6ee7f8398893e5782b079a85a0
1 #!/usr/bin/perl
3 # This file is part of Koha.
5 # Koha is free software; you can redistribute it and/or modify it
6 # under the terms of the GNU General Public License as published by
7 # the Free Software Foundation; either version 3 of the License, or
8 # (at your option) any later version.
10 # Koha is distributed in the hope that it will be useful, but
11 # WITHOUT ANY WARRANTY; without even the implied warranty of
12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 # GNU General Public License for more details.
15 # You should have received a copy of the GNU General Public License
16 # along with Koha; if not, see <http://www.gnu.org/licenses>.
18 use Modern::Perl;
19 use CGI qw ( -utf8 );
20 use C4::Auth;
21 use C4::Serials;
22 use C4::Acquisition;
23 use C4::Output;
24 use C4::Context;
26 use Koha::CsvProfiles;
28 use Text::CSV_XS;
30 my $query = new CGI;
31 my $supplierid = $query->param('supplierid');
32 my @serialids = $query->multi_param('serialid');
33 my $op = $query->param('op') || q{};
35 my $csv_profile_id = $query->param('csv_profile');
36 my $csv_profile = Koha::CsvProfiles->find( $csv_profile_id );
37 die "There is no valid csv profile given" unless $csv_profile;
39 my $csv = Text::CSV_XS->new({
40 'quote_char' => '"',
41 'escape_char' => '"',
42 'sep_char' => $csv_profile->csv_separator,
43 'binary' => 1
44 });
46 my $content = $csv_profile->content;
47 my ( @headers, @fields );
48 while ( $content =~ /
49 ([^=]+) # header
51 ([^\|]+) # fieldname (table.row or row)
52 \|? /gxms
53 ) {
54 push @headers, $1;
55 my $field = $2;
56 $field =~ s/[^\.]*\.?//; # Remove the table name if exists.
57 push @fields, $field;
60 my @rows;
61 for my $serialid ( @serialids ) {
62 my @missingissues = GetLateOrMissingIssues($supplierid, $serialid);
63 my $issue = $missingissues[0];
64 my @row;
65 for my $field ( @fields ) {
66 push @row, $issue->{$field};
68 push @rows, \@row;
70 # update claim date to let one know they have looked at this missing item
71 updateClaim($serialid);
74 print $query->header(
75 -type => 'plain/text',
76 -attachment => "serials-claims.csv",
79 print join( $csv_profile->csv_separator, @headers ) . "\n";
81 for my $row ( @rows ) {
82 $csv->combine(@$row);
83 my $string = $csv->string;
84 print $string, "\n";