X-Git-Url: http://git.freeside.biz/gitweb/?p=freeside.git;a=blobdiff_plain;f=httemplate%2Fbrowse%2Fpart_event.html;h=4b95b86f58a62dd3a32c3b4f10d5f12ec2a3d0ca;hp=6be28602da79fa6ab1261fd529f7d585138a9c36;hb=85291fb4046b876aa1f33ae3e1a57823c30a446e;hpb=c6e4f9460f44a7440ef2fa7e67ed51dfe40a7668 diff --git a/httemplate/browse/part_event.html b/httemplate/browse/part_event.html index 6be28602d..4b95b86f5 100644 --- a/httemplate/browse/part_event.html +++ b/httemplate/browse/part_event.html @@ -45,8 +45,9 @@ my $link = [ $p.'edit/part_event.html?', 'eventpart' ]; my $event_sub = sub { my $part_event = shift; my $onclick = include('/elements/popup_link_onclick.html', - action => $p.'view/part_event-targets.html?'.$part_event->eventpart, - actionlabel => 'Event query - '.$part_event->event, + action => $p.'view/part_event-targets.html?eventpart='. + $part_event->eventpart, + actionlabel => 'Event query', #no, XSS - '.$part_event->event, width => 650, height => 420, close_text => 'Close', @@ -54,14 +55,14 @@ my $event_sub = sub { [#rows [#subcolumns { - 'data' => $part_event->event, - 'link' => $p.'edit/part_event.html?'.$part_event->eventpart, + 'data' => encode_entities($part_event->event), + 'link' => $p.'edit/part_event.html?'.$part_event->eventpart, }, { - 'data' => ' (query) ', - 'size' => '-1', - 'data_style' => 'b', - 'onclick' => $onclick, + 'data' => '(query) ', + 'size' => '-1', + 'data_style' => 'b', + 'onclick' => $onclick, }, ], ]; @@ -173,9 +174,11 @@ my $html_init = qq!Add a new event!. ' or '. @@ -187,7 +190,7 @@ my $count_query = 'SELECT COUNT(*) FROM part_event WHERE '. 'viewall_right' => 'None', ); -my $join_conditions = FS::part_event_condition->join_conditions_sql; +my $join_conditions = FS::part_event_condition->join_conditions_sql('', 'time' => time); my $order_conditions = FS::part_event_condition->order_conditions_sql;