Bug 18689: calendar error with double quotes in title or description of holiday
[koha.git] / svc / bib
blob789951b5eaddba79cb18d66296833a2a5aec3c37
1 #!/usr/bin/perl
3 # Copyright 2007 LibLime
4 # Copyright 2012 software.coop and MJ Ray
6 # This file is part of Koha.
8 # Koha is free software; you can redistribute it and/or modify it
9 # under the terms of the GNU General Public License as published by
10 # the Free Software Foundation; either version 3 of the License, or
11 # (at your option) any later version.
13 # Koha is distributed in the hope that it will be useful, but
14 # WITHOUT ANY WARRANTY; without even the implied warranty of
15 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 # GNU General Public License for more details.
18 # You should have received a copy of the GNU General Public License
19 # along with Koha; if not, see <http://www.gnu.org/licenses>.
22 use strict;
23 use warnings;
25 use CGI qw ( -utf8 );
26 use C4::Auth qw/check_api_auth/;
27 use C4::Biblio;
28 use C4::Items;
29 use XML::Simple;
31 my $query = new CGI;
32 binmode STDOUT, ':encoding(UTF-8)';
34 my ($status, $cookie, $sessionID) = check_api_auth($query, { editcatalogue => 'edit_catalogue'} );
35 unless ($status eq "ok") {
36 print $query->header(-type => 'text/xml', -status => '403 Forbidden');
37 print XMLout({ auth_status => $status }, NoAttr => 1, RootName => 'response', XMLDecl => 1);
38 exit 0;
41 # do initial validation
42 my $path_info = $query->path_info();
44 my $biblionumber = undef;
45 if ($path_info =~ m!^/(\d+)$!) {
46 $biblionumber = $1;
47 } else {
48 print $query->header(-type => 'text/xml', -status => '400 Bad Request');
51 # are we retrieving, updating or deleting a bib?
52 if ($query->request_method eq "GET") {
53 fetch_bib($query, $biblionumber);
54 } elsif ($query->request_method eq "POST") {
55 update_bib($query, $biblionumber);
56 } elsif ($query->request_method eq "DELETE") {
57 delete_bib($query, $biblionumber);
58 } else {
59 print $query->header(-type => 'text/xml', -status => '405 Method not allowed');
60 print XMLout({ error => 'Method not allowed' }, NoAttr => 1, RootName => 'response', XMLDecl => 1);
61 exit 0;
64 exit 0;
66 sub fetch_bib {
67 my $query = shift;
68 my $biblionumber = shift;
69 my $record = GetMarcBiblio( $biblionumber, $query->url_param('items') );
70 if (defined $record) {
71 print $query->header(-type => 'text/xml',-charset => 'utf-8',);
72 print $record->as_xml_record();
73 } else {
74 print $query->header(-type => 'text/xml', -status => '404 Not Found');
78 sub update_bib {
79 my $query = shift;
80 my $biblionumber = shift;
81 my $old_record = GetMarcBiblio($biblionumber);
82 unless (defined $old_record) {
83 print $query->header(-type => 'text/xml', -status => '404 Not Found');
84 return;
87 my $result = {};
88 my $inxml = $query->param('POSTDATA');
89 print $query->header(-type => 'text/xml', -charset => 'utf-8');
91 my $record = eval {MARC::Record::new_from_xml( $inxml, "utf8", C4::Context->preference('marcflavour'))};
92 my $do_not_escape = 0;
93 if ($@) {
94 $result->{'status'} = "failed";
95 $result->{'error'} = $@;
96 } else {
97 my $fullrecord = $record->clone();
98 my ( $itemtag, $itemsubfield ) =
99 GetMarcFromKohaField( "items.itemnumber", '' );
101 # delete any item tags
102 foreach my $field ( $record->field($itemtag) ) {
103 $record->delete_field($field);
106 if ( $query->url_param('items') ) {
107 foreach my $field ( $fullrecord->field($itemtag) ) {
108 my $one_item_record = $record->clone();
109 $one_item_record->add_fields($field);
110 ModItemFromMarc( $one_item_record, $biblionumber,
111 $field->subfield($itemsubfield) );
115 ModBiblio( $record, $biblionumber, '' );
116 my $new_record =
117 GetMarcBiblio( $biblionumber, $query->url_param('items') );
119 $result->{'status'} = "ok";
120 $result->{'biblionumber'} = $biblionumber;
121 my $xml = $new_record->as_xml_record();
122 $xml =~ s/<\?xml.*?\?>//i;
123 $result->{'marcxml'} = $xml;
124 $do_not_escape = 1;
127 print XMLout($result, NoAttr => 1, RootName => 'response', XMLDecl => 1, NoEscape => $do_not_escape);
130 sub delete_bib {
131 my $query = shift;
132 my $biblionumber = shift;
133 my $error = DelBiblio($biblionumber);
135 if (defined $error) {
136 print $query->header(-type => 'text/xml', -status => '400 Bad request');
137 print XMLout({ error => $error }, NoAttr => 1, RootName => 'response', XMLDecl => 1);
138 exit 0;
141 print $query->header(-type => 'text/xml');
142 print XMLout({ status => 'OK, biblio deleted' }, NoAttr => 1, RootName => 'response', XMLDecl => 1);