equal
deleted
inserted
replaced
26 if (isset($_POST["action"]) && $_POST["action"]=="record-user") { |
26 if (isset($_POST["action"]) && $_POST["action"]=="record-user") { |
27 if (!is_array($_POST['rowid'])) { |
27 if (!is_array($_POST['rowid'])) { |
28 $recordOwnerError = 'No records where selected to assign an sub-owner.'; |
28 $recordOwnerError = 'No records where selected to assign an sub-owner.'; |
29 } else { |
29 } else { |
30 foreach ($_POST["rowid"] as $x_user => $recordid){ |
30 foreach ($_POST["rowid"] as $x_user => $recordid){ |
31 $x_userid = $db->queryOne("SELECT id FROM record_owners WHERE user_id = '".$_POST["userid"]."' AND record_id='".$recordid."'"); |
31 $x_userid = $db->queryOne("SELECT id FROM record_owners WHERE user_id = ".$db->quote($_POST["userid"])." AND record_id=".$db->quote($recordid)); |
32 if (empty($x_userid)) { |
32 if (empty($x_userid)) { |
33 add_record_owner($_GET["id"],$_POST["userid"],$recordid); |
33 add_record_owner($_GET["id"],$_POST["userid"],$recordid); |
34 } |
34 } |
35 } |
35 } |
36 } |
36 } |
298 if (level(10) && $domain_type != "SLAVE") |
298 if (level(10) && $domain_type != "SLAVE") |
299 { |
299 { |
300 ?> |
300 ?> |
301 <td class="n"> |
301 <td class="n"> |
302 <? |
302 <? |
303 $x_result = $db->query("SELECT r.user_id,u.username,u.fullname FROM record_owners as r, users as u WHERE r.record_id='".$r['id']."' AND u.id=r.user_id"); |
303 $x_result = $db->query("SELECT r.user_id,u.username,u.fullname FROM record_owners as r, users as u WHERE r.record_id=".$db->quote($r['id'])." AND u.id=r.user_id"); |
304 echo "<select style=\"width:120px;\">"; |
304 echo "<select style=\"width:120px;\">"; |
305 while ($x_r = $x_result->fetchRow()) { |
305 while ($x_r = $x_result->fetchRow()) { |
306 echo "<option value=\"".$x_r["username"]."\">".$x_r["fullname"]."</option>"; |
306 echo "<option value=\"".$x_r["username"]."\">".$x_r["fullname"]."</option>"; |
307 } |
307 } |
308 echo "</select>"; |
308 echo "</select>"; |