diff --git a/app/contacts/contact_times.php b/app/contacts/contact_times.php index d3336cdb3e..fba1b474d8 100644 --- a/app/contacts/contact_times.php +++ b/app/contacts/contact_times.php @@ -17,22 +17,26 @@ The Initial Developer of the Original Code is Mark J Crane - Portions created by the Initial Developer are Copyright (C) 2008-2015 + Portions created by the Initial Developer are Copyright (C) 2008-2018 the Initial Developer. All Rights Reserved. Contributor(s): Mark J Crane */ -require_once "root.php"; -require_once "resources/require.php"; -require_once "resources/check_auth.php"; -if (permission_exists('contact_time_view')) { - //access granted -} -else { - echo "access denied"; - exit; -} + +//includes + require_once "root.php"; + require_once "resources/require.php"; + require_once "resources/check_auth.php"; + +//check permissions + if (permission_exists('contact_time_view')) { + //access granted + } + else { + echo "access denied"; + exit; + } //show the content echo "\n"; @@ -82,7 +86,7 @@ else { echo "
\n"; if ($result_count > 0) { foreach($result as $row) { - $tr_link = (permission_exists('contact_time_edit') && $row['user_uuid'] == $_SESSION["user"]["user_uuid"]) ? "href='contact_time_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_time_uuid']."'" : null; + $tr_link = (permission_exists('contact_time_edit') && $row['user_uuid'] == $_SESSION["user"]["user_uuid"]) ? "href='contact_time_edit.php?contact_uuid=".escape($row['contact_uuid'])."&id=".escape($row['contact_time_uuid'])."'" : null; echo "\n"; if ($row["time_start"] != '' && $row['time_stop'] != '') { $time_start = strtotime($row["time_start"]); @@ -92,10 +96,10 @@ else { else { unset($time); } $tmp = explode(' ', $row['time_start']); $time_start = $tmp[0]; - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; - echo " \n"; + echo " \n"; echo "
".$row["username"]." ".escape($row["username"])." ".$time_start." ".$time." ".$row['time_description']." ".escape($row['time_description'])." "; if (permission_exists('contact_time_edit')) { if ($row['user_uuid'] == $_SESSION["user"]["user_uuid"]) { @@ -107,7 +111,7 @@ else { } if (permission_exists('contact_time_delete')) { if ($row['user_uuid'] == $_SESSION["user"]["user_uuid"]) { - echo "".$v_link_label_delete.""; + echo "".$v_link_label_delete.""; } else { echo "".str_replace("list_control_icon", "list_control_icon_disabled", $v_link_label_delete).""; @@ -144,4 +148,4 @@ else { echo " }"; echo "\n"; -?> \ No newline at end of file +?>