Fixed quote escaping problem in view.php.
[openemr.git] / interface / forms / brief_aan_verwijzer / autosave.php
blob655c56bbd8616e805fcd762a19aecb1262ffaa64
1 <?php
2 ////////////////////////////////////////////////////////////////////
3 // Form: form_brief_aan_verwijzer - Autosave
4 // Package: letter to... - Dutch specific form
5 // Created by: Larry Lart
6 // Version: 1.0 - 29-03-2008
7 ////////////////////////////////////////////////////////////////////
9 //local includes
10 include_once("../../globals.php");
11 include_once("$srcdir/api.inc");
12 include_once("$srcdir/forms.inc");
15 // escape the strings
16 foreach ($_POST as $k => $var)
18 $_POST[$k] = mysql_real_escape_string($var);
19 // echo "$var\n";
22 /////////////////
23 // here we check to se if there was an autosave version prior to the real save
24 $vectAutosave = sqlQuery( "SELECT id, autosave_flag, autosave_datetime FROM form_brief_aan_verwijzer
25 WHERE pid = ".$_SESSION["pid"].
26 " AND groupname='".$_SESSION["authProvider"].
27 "' AND user='".$_SESSION["authUser"]."' AND
28 authorized=$userauthorized AND activity=1
29 AND autosave_flag=1
30 ORDER by id DESC limit 1" );
32 // if yes then update this else insert
33 if( $vectAutosave['autosave_flag'] == 1 || $_POST["mode"] == "update" )
35 if( $_POST["mode"] == "update" )
36 $newid = $_POST["id"];
37 else
38 $newid = $vectAutosave['id'];
40 $strSql = "UPDATE form_brief_aan_verwijzer
41 SET pid = ".$_SESSION["pid"].", groupname='".$_SESSION["authProvider"]."', user='".$_SESSION["authUser"]."',
42 authorized=$userauthorized, activity=1, date = NOW(),
43 introductie='".$_POST["introductie"]."',
44 reden_van_aanmelding='".$_POST["reden_van_aanmelding"]."',
45 anamnese='".$_POST["anamnese"]."',
46 psychiatrisch_onderzoek='".$_POST["psychiatrisch_onderzoek"]."',
47 beschrijvend_conclusie='".$_POST["beschrijvend_conclusie"]."',
48 advies_beleid='".$_POST["advies_beleid"]."',
49 autosave_flag=1,
50 autosave_datetime=NOW()
51 WHERE id = ".$newid.";";
53 sqlQuery( $strSql );
55 //echo "DEBUG :: id=$newid, sql=$strSql<br>";
57 } else
59 $newid = formSubmit( "form_brief_aan_verwijzer", $_POST, $_GET["id"], $userauthorized );
60 addForm( $encounter, "Brief Aan Verwijzer", $newid, "brief_aan_verwijzer", $pid, $userauthorized );
62 //echo "Debug :: insert<br>";
66 //get timestamp
67 $result = sqlQuery("SELECT autosave_datetime FROM form_brief_aan_verwijzer
68 WHERE pid = ".$_SESSION["pid"].
69 " AND groupname='".$_SESSION["authProvider"].
70 "' AND user='".$_SESSION["authUser"]."' AND
71 authorized=$userauthorized AND activity=1 AND id=$newid
72 AND autosave_flag=1
73 ORDER by id DESC limit 1" );
74 //$timestamp = mysql_result($result, 0);
76 //output timestamp
77 echo 'Last Saved: '.$result['autosave_datetime'];