svn commit: r770929 - /ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

svn commit: r770929 - /ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl

ashish-18
Author: ashish
Date: Sat May  2 11:23:28 2009
New Revision: 770929

URL: http://svn.apache.org/viewvc?rev=770929&view=rev
Log:
Applied patch from jira issue OFBIZ-2416 (Security error on Remove return items)

Thanks Pranay Pandey for your contribution.

Modified:
    ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl

Modified: ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl
URL: http://svn.apache.org/viewvc/ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl?rev=770929&r1=770928&r2=770929&view=diff
==============================================================================
--- ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl (original)
+++ ofbiz/trunk/applications/order/webapp/ordermgr/return/returnItems.ftl Sat May  2 11:23:28 2009
@@ -266,7 +266,7 @@
                 </td>
                 </#if>
                 <#if returnHeader.statusId == "RETURN_REQUESTED" || returnHeader.statusId == "SUP_RETURN_REQUESTED">
-                  <td align='right'><a href="<@ofbizUrl>removeReturnItem?returnId=${item.returnId}&returnItemSeqId=${item.returnItemSeqId}</@ofbizUrl>" class="buttontext">${uiLabelMap.CommonRemove}</a>
+                  <td align='right'><a href='javascript:document.removeReturnItem_${item_index}.submit()' class='buttontext'>${uiLabelMap.CommonRemove}</a>
                 <#else>
                   <td>&nbsp;</td>
                 </#if>
@@ -312,6 +312,14 @@
         </form>
 
         </table>
+        <#if returnItems?has_content>
+          <#list returnItems as item>
+            <form name="removeReturnItem_${item_index}" method="post" action="<@ofbizUrl>removeReturnItem</@ofbizUrl>">
+              <input type="hidden" name="returnId" value="${item.returnId}"/>
+              <input type="hidden" name="returnItemSeqId" value="${item.returnItemSeqId}"/>
+            </form>
+          </#list>
+        </#if>
         <#if (returnHeader.statusId == "RETURN_REQUESTED" || returnHeader.statusId == "SUP_RETURN_REQUESTED") && (rowCount > 0)>
         <br/>
         <form name="acceptReturn" method="post" action="<@ofbizUrl>/updateReturn</@ofbizUrl>">