|
17 | 17 |
|
18 | 18 | // Perms |
19 | 19 | enforceUserPermission('module_sales'); |
| 20 | +$quote_permission_snippet = ''; |
| 21 | +if (!empty($client_access_string)) { |
| 22 | + $quote_permission_snippet = "AND quote_client_id IN ($client_access_string)"; |
| 23 | +} |
20 | 24 |
|
21 | 25 | $sql = mysqli_query( |
22 | 26 | $mysqli, |
|
25 | 29 | LEFT JOIN categories ON quote_category_id = category_id |
26 | 30 | WHERE (CONCAT(quote_prefix,quote_number) LIKE '%$q%' OR quote_scope LIKE '%$q%' OR category_name LIKE '%$q%' OR quote_status LIKE '%$q%' OR quote_amount LIKE '%$q%' OR client_name LIKE '%$q%') |
27 | 31 | AND DATE(quote_date) BETWEEN '$dtf' AND '$dtt' |
| 32 | + $quote_permission_snippet |
28 | 33 | $client_query |
29 | 34 | ORDER BY $sort $order LIMIT $record_from, $record_to" |
30 | 35 | ); |
|
206 | 211 | <tr> |
207 | 212 | <td class="text-bold"> |
208 | 213 | <a href="quote.php?<?php echo $client_url; ?>quote_id=<?php echo $quote_id; ?>"> |
209 | | - <?php echo "$quote_prefix$quote_number"; ?> |
| 214 | + <?php echo "$quote_prefix$quote_number"; ?> |
210 | 215 | </a> |
211 | 216 | </td> |
212 | 217 | <td><?php echo $quote_scope_display; ?></td> |
|
231 | 236 | </button> |
232 | 237 | <div class="dropdown-menu"> |
233 | 238 | <a class="dropdown-item" href="#" |
234 | | - data-toggle = "ajax-modal" |
| 239 | + data-toggle = "ajax-modal" |
235 | 240 | data-ajax-url = "ajax/ajax_quote_edit.php" |
236 | 241 | data-ajax-id = "<?php echo $quote_id; ?>" |
237 | 242 | > |
238 | 243 | <i class="fas fa-fw fa-edit mr-2"></i>Edit |
239 | 244 | </a> |
240 | 245 | <?php if (lookupUserPermission("module_sales") >= 2) { ?> |
241 | 246 | <a class="dropdown-item" href="#" |
242 | | - data-toggle = "ajax-modal" |
| 247 | + data-toggle = "ajax-modal" |
243 | 248 | data-ajax-url = "ajax/ajax_quote_copy.php" |
244 | 249 | data-ajax-id = "<?php echo $quote_id; ?>" |
245 | 250 | > |
|
0 commit comments