- $sql = "select l.id as id, TIME_FORMAT(l.start, $sql_time_format) as start,
- TIME_FORMAT(sec_to_time(time_to_sec(l.start) + time_to_sec(l.duration)), $sql_time_format) as finish,
- TIME_FORMAT(l.duration, '%k:%i') as duration,
- p.name as project_name, t.name as task_name, l.comment, l.client_id, l.project_id, l.task_id, l.invoice_id, l.billable, l.paid, l.date
- from tt_log l
- left join tt_projects p on (p.id = l.project_id)
- left join tt_tasks t on (t.id = l.task_id)
- where l.id = $id and l.user_id = $user_id and l.status = 1";
+ $sql = "select l.id as id, TIME_FORMAT(l.start, $sql_time_format) as start,".
+ " TIME_FORMAT(sec_to_time(time_to_sec(l.start) + time_to_sec(l.duration)), $sql_time_format) as finish,".
+ " TIME_FORMAT(l.duration, '%k:%i') as duration,".
+ " p.name as project_name, t.name as task_name, l.comment, l.client_id, l.project_id, l.task_id,".
+ " l.timesheet_id, l.invoice_id, l.billable, l.approved, l.paid, l.date from tt_log l".
+ " left join tt_projects p on (p.id = l.project_id)".
+ " left join tt_tasks t on (t.id = l.task_id)".
+ " where l.id = $id and l.user_id = $user_id and l.group_id = $group_id and l.org_id = $org_id and l.status = 1";
+ $res = $mdb2->query($sql);
+ if (!is_a($res, 'PEAR_Error')) {
+ if (!$res->numRows()) {
+ return false;
+ }
+ if ($val = $res->fetchRow()) {
+ return $val;
+ }
+ }
+ return false;
+ }
+
+ // getRecordForFileView - retrieves a time record identified by its id for
+ // attachment view operation.
+ //
+ // It is different from getRecord, as we want users with appropriate rights
+ // to be able to see other users files, without changing "on behalf" user.
+ // For example, viewing reports for all users and their attached files
+ // from report links.
+ static function getRecordForFileView($id) {
+ // TODO: code this function properly. There are no security checks now.
+ global $user;
+
+ // $user_id = $user->getUser();
+ $group_id = $user->getGroup();
+ $org_id = $user->org_id;
+
+ $mdb2 = getConnection();
+
+ $sql = "select l.id, l.timesheet_id, l.invoice_id, l.approved from tt_log l".
+ " where l.id = $id and l.group_id = $group_id and l.org_id = $org_id and l.status = 1";