X-Git-Url: http://git.freeside.biz/gitweb/?a=blobdiff_plain;f=httemplate%2Fview%2Fcust_bill-logo.cgi;h=75321ef82b772b947178ceccc8b50edf29cccef4;hb=e41880cfb8d9835bca858ec13c96724b08fa0af7;hp=3e9c67fccbfcd8b91616d3cc4009687e594d98c8;hpb=df185d34f354c5788e8c4693182b7689a3333839;p=freeside.git diff --git a/httemplate/view/cust_bill-logo.cgi b/httemplate/view/cust_bill-logo.cgi index 3e9c67fcc..75321ef82 100755 --- a/httemplate/view/cust_bill-logo.cgi +++ b/httemplate/view/cust_bill-logo.cgi @@ -1,15 +1,32 @@ -<% +<% $conf->config_binary("logo$templatename.png", $agentnum) %> +<%init> -##untaint invnum -#my($query) = $cgi->keywords; -#$query =~ /^((.+)-)?(\d+)$/; -#my $templatename = $2; -#my $invnum = $3; +die "access denied" + unless $FS::CurrentUser::CurrentUser->access_right('View invoices') + or $FS::CurrentUser::CurrentUser->access_right('Configuration'); -my $templatename = ''; +my $conf; -my $conf = new FS::Conf; -http_header('Content-Type' => 'image/png' ); +my $templatename; +my $agentnum = ''; +if ( $cgi->param('invnum') ) { + $templatename = $cgi->param('template') || $cgi->param('templatename'); + my $cust_bill = qsearchs('cust_bill', { 'invnum' => $cgi->param('invnum') } ) + or die 'unknown invnum'; + $conf = $cust_bill->conf; + $agentnum = $cust_bill->cust_main->agentnum; +} else { + my($query) = $cgi->keywords; + $query =~ /^([^\.\/]*)$/ or die 'illegal query'; + $templatename = $1; +} + +if ( $templatename && $conf->exists("logo_$templatename.png") ) { + $templatename = "_$templatename"; +} else { + $templatename = ''; +} http_header('Content-Type' => 'image/png' ); -%><%= $conf->config_binary("logo$templatename.png") %> + +