<br>
<table cellspacing="0" cellpadding="4" width="100%" border="0">
<tr>
- <td align="center"> Anuko Time Tracker 1.18.29.4616 | Copyright © <a href="https://www.anuko.com/lp/tt_3.htm" target="_blank">Anuko</a> |
+ <td align="center"> Anuko Time Tracker 1.18.29.4617 | Copyright © <a href="https://www.anuko.com/lp/tt_3.htm" target="_blank">Anuko</a> |
<a href="https://www.anuko.com/lp/tt_4.htm" target="_blank">{$i18n.footer.credits}</a> |
<a href="https://www.anuko.com/lp/tt_5.htm" target="_blank">{$i18n.footer.license}</a> |
<a href="https://www.anuko.com/lp/tt_7.htm" target="_blank">{$i18n.footer.improve}</a>
</tr>
<tr>
<td align="right">{$i18n.label.cost} (*):</td>
- <td>{$forms.predefinedExpenseForm.cost.control} {$user->currency|escape}</td>
+ <td>{$forms.predefinedExpenseForm.cost.control} {$user->getCurrency()|escape}</td>
</tr>
<tr>
<td height="40"></td>
</tr>
<tr>
<td align="right">{$i18n.label.cost} (*):</td>
- <td>{$forms.predefinedExpenseForm.cost.control} {$user->currency|escape}</td>
+ <td>{$forms.predefinedExpenseForm.cost.control} {$user->getCurrency()|escape}</td>
</tr>
<tr>
<td height="40"></td>
header('Location: feature_disabled.php');
exit();
}
-
$cl_predefined_expense_id = (int)$request->getParameter('id');
$predefined_expense = ttPredefinedExpenseHelper::get($cl_predefined_expense_id);
+if (!$predefined_expense) {
+ header('Location: access_denied.php');
+ exit();
+}
+// End of access checks.
+
+
$predefined_expense_to_delete = $predefined_expense['name'];
$form = new Form('predefinedExpenseDeleteForm');
if ($request->isPost()) {
if ($request->getParameter('btn_delete')) {
- if(ttPredefinedExpenseHelper::get($cl_predefined_expense_id)) {
- if (ttPredefinedExpenseHelper::delete($cl_predefined_expense_id)) {
- header('Location: predefined_expenses.php');
- exit();
- } else
- $err->add($i18n->get('error.db'));
+ if (ttPredefinedExpenseHelper::delete($cl_predefined_expense_id)) {
+ header('Location: predefined_expenses.php');
+ exit();
} else
$err->add($i18n->get('error.db'));
} elseif ($request->getParameter('btn_cancel')) {
header('Location: feature_disabled.php');
exit();
}
-
$predefined_expense_id = (int) $request->getParameter('id');
+$predefined_expense = ttPredefinedExpenseHelper::get($predefined_expense_id);
+if (!$predefined_expense) {
+ header('Location: access_denied.php');
+ exit();
+}
+// End of access checks.
if ($request->isPost()) {
$cl_name = trim($request->getParameter('name'));
$cl_cost = trim($request->getParameter('cost'));
} else {
- $predefined_expense = ttPredefinedExpenseHelper::get($predefined_expense_id);
$cl_name = $predefined_expense['name'];
$cl_cost = $predefined_expense['cost'];
}
header('Location: feature_disabled.php');
exit();
}
+// End of access checks.
$form = new Form('predefinedExpensesForm');