HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.30
System: Linux iZj6c1151k3ad370bosnmsZ 3.10.0-1160.76.1.el7.x86_64 #1 SMP Wed Aug 10 16:21:17 UTC 2022 x86_64
User: root (0)
PHP: 7.4.30
Disabled: NONE
Upload Files
File: /var/www/html/inventory.breadsecret.com/script/itemList.php
<?php
include_once('../inc/global.php');
include_once("../config/route.php");
$user = unserialize($_SESSION['user']);
$today = Utility\WebSystem::displayDate(date("Y-m-d H:i:s"), 'Y-m-d');

$map = [
    'column_itemID' => 'item.id',
    'column_itemTypeName' => 'itemType.name',
    'column_itemName' => 'item.name',
    'column_supplierName' => 'supplier.name',
    'column_unitName' => 'unit.name',
    'column_itemQty' => 'item.qty',
    'column_itemTotalValue' => 'item.totalValue',
    'column_itemStatus' => 'status.name',
    'column_function' => 'item.id'
];

$draw = $_POST['draw'];
$row = $_POST['start'];
$rowperpage = $_POST['length']; // Rows display per page
$columnIndex = $_POST['order'][0]['column']; // Column index
$columnName = $_POST['columns'][$columnIndex]['data']; // Column name
$columnSortOrder = $_POST['order'][0]['dir']; // asc or desc
$searchValue = $_POST['search']['value']; // Search value
$searchQuery = " ";

$sqlAll = Database\Sql::select(['item', 'item'])
->leftJoin(['supplier', 'supplier'], "item.supplierID = supplier.id")
->leftJoin(['unit', 'unit'], "item.unitID = unit.id")
->leftJoin(['item_type', 'itemType'], "item.itemTypeID = itemType.id")
->leftJoin(['status', 'status'], "item.status = status.id");

$sqlAll->setFieldValue('
   item.id itemID, 
   itemType.name itemTypeName,
   item.name itemName, 
   supplier.name supplierName, 
   unit.name unitName, 
   item.qty itemQty, 
   item.totalValue itemTotalValue, 
   status.name statusName                         
');

$stmAll = $sqlAll->prepare();
$stmAll->execute();

if($searchValue != ''){
    $searchValue = addslashes($searchValue);
    $sqlAll->whereOp("(item.id LIKE '%".$searchValue."%' 
        OR itemType.name LIKE '%".$searchValue."%'   
        OR item.name LIKE '%".$searchValue."%'   
        OR supplier.name LIKE '%".$searchValue."%'   
        OR unit.name LIKE '%".$searchValue."%'   
        OR item.qty LIKE '%".$searchValue."%'   
        OR item.totalValue LIKE '%".$searchValue."%'   
        OR status.name LIKE '%".$searchValue."%'
    )");
}

foreach($_POST['columns'] as $idx => $column){
    if(!empty($column['search']['value'])) {
        $idxSearchValue = substr($column['search']['value'], 1, -1);
        if($_POST['columns'][$idx]['data']=="column_itemStatus"){
           if($idxSearchValue=="有效") {
             $idxSearchValue="Enabled";
           }

           if($idxSearchValue=="無效") {
             $idxSearchValue="Disabled";
           }           
        } 

        $sqlAll->where([$map[$_POST['columns'][$idx]['data']], '=', '"'.strip_tags($idxSearchValue).'"']);
    }
}

if($stmAll->rowCount()==0 && $filter) {
    $sqlAll = Database\Sql::select(['item', 'item'])
    ->leftJoin(['supplier', 'supplier'], "item.supplierID = supplier.id")
    ->leftJoin(['unit', 'unit'], "item.unitID = unit.id")
    ->leftJoin(['item_type', 'itemType'], "item.itemTypeID = itemType.id")
    ->leftJoin(['status', 'status'], "item.status = status.id");
    
    $sqlAll->setFieldValue('
       item.id itemID, 
       itemType.name itemTypeName,
       item.name itemName, 
       supplier.name supplierName, 
       unit.name unitName, 
       item.qty itemQty, 
       item.totalValue itemTotalValue, 
       status.name statusName                         
    ');
};

$sql = $sqlAll->order($map[$columnName],$columnSortOrder)->limit($rowperpage, $row);

$stm = $sql->prepare();
$stm->execute();

$returnArr = [];
$contentArr = [];
$lineCount = 0;
foreach($stm as $data){    

    $dataArr = [
        "column_itemID"=>$data['itemID'],
        "column_itemTypeName"=>$data['itemTypeName'],
        "column_itemName"=>$data['itemName'],       
        "column_supplierName"=>$data['supplierName'],       
        "column_unitName"=>$data['unitName'],       
        "column_itemQty"=>$data['itemQty'],    
        "column_itemTotalValue"=>$data['itemTotalValue'], 
        "column_itemStatus"=>L($data['statusName']), 
        "column_function"=>"
            <div class='btn-group' role='group' aria-label=''>
                <button class='btn btn-sm btn-dark btnView' type='button' data-bs-toggle='tooltip' data-bs-placement='top' title='".L('menu.inventoryMain')."' data-id='".$data['itemID']."'><i class='fas fa-sm fa-th'></i></button>
                <button class='btn btn-sm btn-success btnEdit' type='button' data-bs-toggle='tooltip' data-bs-placement='top' title='".L('Edit')."' data-id='".$data['itemID']."'><i class='fas fa-sm fa-edit'></i></button>
                <button class='btn btn-sm btn-danger btnDel' type='button' data-bs-toggle='tooltip' data-bs-placement='top' title='".L('Delete')."' data-id='".$data['itemID']."'><i class='fas fa-sm fa-trash-alt'></i></button>
            </div>
        "
    ];    

    $lineCount++;
    $contentArr[] = $dataArr;
}

$returnArr['draw'] = intval($draw);
$returnArr["iTotalDisplayRecords"] = $stm->rowCount();
$returnArr["iTotalRecords"] = $stmAll->rowCount();
$returnArr["data"] = $contentArr;

echo json_encode($returnArr);

?>