X-Git-Url: http://git.freeside.biz/gitweb/?p=freeside.git;a=blobdiff_plain;f=httemplate%2Fedit%2Fprocess%2Fcust_pkg.cgi;h=82a9e23753800c134388e4a2e2f819a8eae93d15;hp=0dc82a6005f8719f30d6061b747a50c6b75df242;hb=3f2a7b01b59902faed5767d81e2959e131bdbdfd;hpb=acd8edaf5852735359e32c70b78dabfeb7b32a89 diff --git a/httemplate/edit/process/cust_pkg.cgi b/httemplate/edit/process/cust_pkg.cgi index 0dc82a600..82a9e2375 100755 --- a/httemplate/edit/process/cust_pkg.cgi +++ b/httemplate/edit/process/cust_pkg.cgi @@ -1,70 +1,65 @@ % if ($error) { % $cgi->param('error', $error); -% $cgi->redirect(popurl(3). $error_redirect. '?'. $cgi->query_string ); -% } elsif ( $action eq 'change' ) { - - <% header("Package changed") %> - - - - -% } elsif ( $action eq 'bulk' ) { -<% $cgi->redirect(popurl(3). "view/cust_main.cgi?$custnum") %> +% $cgi->redirect(popurl(3). 'edit/cust_pkg.cgi?'. $cgi->query_string ); % } else { -% die "guru exception #5: action is neither change nor bulk!"; +<% $cgi->redirect(popurl(3). "view/cust_main.cgi?$custnum") %> % } <%init> +use Data::Dumper; +my $DEBUG = 0; +my $curuser = $FS::CurrentUser::CurrentUser; -my $error = ''; - -#untaint custnum -$cgi->param('custnum') =~ /^(\d+)$/; -my $custnum = $1; +die "access denied" + unless $curuser->access_right('Bulk change customer packages'); -my @remove_pkgnums = map { - /^(\d+)$/ or die "Illegal remove_pkg value!"; - $1; -} $cgi->param('remove_pkg'); +my $error = ''; +my %param = $cgi->Vars; -my $curuser = $FS::CurrentUser::CurrentUser; +my $custnum = $param{custnum}; +$error = "Invalid custnum ($custnum)" if $custnum =~ /\D/; -my( $action, $error_redirect ) = ( '', '' ); -my @pkgparts = (); -if ( $cgi->param('action') eq 'change' ) { #came from misc/change_pkg.cgi +my $locationnum = $param{locationnum}; +$error = "Invalid locationnum ($locationnum)" if $locationnum =~ /\D/; - $action = 'change'; - $error_redirect = "misc/change_pkg.cgi"; - @pkgparts = ($1); +my @remove_pkgnum = + map { $_ =~ /remove_cust_pkg\[(\d+)\]/ ? $1 : () } + keys %param; - die "access denied" - unless $curuser->access_right('Change customer package'); +my @pkgparts; +for my $k ( keys %param ) { + next unless $k =~ /qty_part_pkg\[(\d+)\]/; + my $pkgpart = $1; + my $qty = $param{$k}; + $qty =~ s/(^\s+|\s+$)//g; -} elsif ( $cgi->param('action') eq 'bulk' ) { #came from edit/cust_pkg.cgi + warn "k($k) param{k}($param{$k}) pkgpart($pkgpart) qty($qty)\n" + if $DEBUG; - $action = 'bulk'; - $error_redirect = "edit/cust_pkg.cgi"; + if ( $qty =~ /\D/ ) { + $error = "Invalid quantity $qty for pkgpart $pkgpart - please use a number"; + last; + } - die "access denied" - unless $curuser->access_right('Bulk change customer packages'); + next if $qty == 0; - foreach my $pkgpart ( map /^pkg(\d+)$/ ? $1 : (), $cgi->param ) { - if ( $cgi->param("pkg$pkgpart") =~ /^(\d+)$/ ) { - my $num_pkgs = $1; - while ( $num_pkgs-- ) { - push @pkgparts,$pkgpart; - } - } else { - $error = "Illegal quantity"; - last; - } - } + push ( @pkgparts, $pkgpart ) for ( 1..$qty ); +} -} else { - die "guru exception #5: action is neither change nor bulk!"; +if ( $DEBUG ) { + warn Dumper({ + custnum => $custnum, + locationnum => $locationnum, + remove_pkgnum => \@remove_pkgnum, + pkgparts => \@pkgparts, + param => \%param, + }); } -$error ||= FS::cust_pkg::order($custnum,\@pkgparts,\@remove_pkgnums); +$error ||= FS::cust_pkg::order({ + custnum => $custnum, + pkgparts => \@pkgparts, + remove_pkgnum => \@remove_pkgnum, + locationnum => $locationnum, +});