Author: jleroux
Date: Tue May 19 08:15:38 2009 New Revision: 776229 URL: http://svn.apache.org/viewvc?rev=776229&view=rev Log: "Applied fix from trunk for revision: 776227" ------------------------------------------------------------------------ r776227 | jleroux | 2009-05-19 10:11:44 +0200 (mar., 19 mai 2009) | 1 line A patch from Aswath Satrasala "Show Lookup field - security related error" (https://issues.apache.org/jira/browse/OFBIZ-2490) - OFBIZ-2490 ------------------------------------------------------------------------ Modified: ofbiz/branches/release09.04/ (props changed) ofbiz/branches/release09.04/applications/content/src/org/ofbiz/content/webapp/ftl/RenderSubContentTransform.java ofbiz/branches/release09.04/applications/order/webapp/ordermgr/order/findOrders.ftl Propchange: ofbiz/branches/release09.04/ ------------------------------------------------------------------------------ --- svn:mergeinfo (original) +++ svn:mergeinfo Tue May 19 08:15:38 2009 @@ -1 +1 @@ -/ofbiz/trunk:765933,766011,766015,766293,766307,766316,766325,766462,766522,766800,767060,767072,767093,767098-767099,767102,767123,767125,767127,767279,767287,767671,767688,767694,767822,767845,768358,768490,768550,768675,768686,768705,768811,768815,768960,769030,769500,770272,770997,771073,772401,772464-772465,773076,773557,773628,773659,773697,774014,774632,774661,774995,775292 +/ofbiz/trunk:765933,766011,766015,766293,766307,766316,766325,766462,766522,766800,767060,767072,767093,767098-767099,767102,767123,767125,767127,767279,767287,767671,767688,767694,767822,767845,768358,768490,768550,768675,768686,768705,768811,768815,768960,769030,769500,770272,770997,771073,772401,772464-772465,773076,773557,773628,773659,773697,774014,774632,774661,774995,775292,776227 Modified: ofbiz/branches/release09.04/applications/content/src/org/ofbiz/content/webapp/ftl/RenderSubContentTransform.java URL: http://svn.apache.org/viewvc/ofbiz/branches/release09.04/applications/content/src/org/ofbiz/content/webapp/ftl/RenderSubContentTransform.java?rev=776229&r1=776228&r2=776229&view=diff ============================================================================== --- ofbiz/branches/release09.04/applications/content/src/org/ofbiz/content/webapp/ftl/RenderSubContentTransform.java (original) +++ ofbiz/branches/release09.04/applications/content/src/org/ofbiz/content/webapp/ftl/RenderSubContentTransform.java Tue May 19 08:15:38 2009 @@ -138,8 +138,9 @@ try { if (subContentId != null) { ContentWorker.renderContentAsText(dispatcher, delegator, subContentId, out, templateRoot, locale, mimeTypeId, false); + } else { - ContentWorker.renderSubContentAsText(dispatcher, delegator, contentId, out, mapKey, templateRoot, locale, mimeTypeId, false); + ContentWorker.renderSubContentAsText(delegator, contentId, out, mapKey, subContentId, subContentDataResourceView, templateRoot, locale, mimeTypeId, userLogin, fromDate); } //Map results = ContentWorker.renderSubContentAsText(delegator, contentId, out, mapKey, subContentId, subContentDataResourceView, templateRoot, locale, mimeTypeId, userLogin, fromDate); } catch (GeneralException e) { Modified: ofbiz/branches/release09.04/applications/order/webapp/ordermgr/order/findOrders.ftl URL: http://svn.apache.org/viewvc/ofbiz/branches/release09.04/applications/order/webapp/ordermgr/order/findOrders.ftl?rev=776229&r1=776228&r2=776229&view=diff ============================================================================== --- ofbiz/branches/release09.04/applications/order/webapp/ordermgr/order/findOrders.ftl (original) +++ ofbiz/branches/release09.04/applications/order/webapp/ordermgr/order/findOrders.ftl Tue May 19 08:15:38 2009 @@ -62,6 +62,40 @@ </script> <#if security.hasEntityPermission("ORDERMGR", "_VIEW", session)> +<#if parameters.hideFields?has_content> +<form name='lookupandhidefields${requestParameters.hideFields}' method="POST" action="<@ofbizUrl>searchorders</@ofbizUrl>"> + <#if parameters.hideFields?default("N")=='Y'> + <input type="hidden" name="hideFields" value="N"/> + <#else> + <input type='hidden' name='hideFields' value='Y'/> + </#if> + <input type="hidden" name="viewSize" value="${viewSize}"/> + <input type="hidden" name="viewIndex" value="${viewIndex}"/> + <input type='hidden' name='correspondingPoId' value='${requestParameters.correspondingPoId?if_exists}'/> + <input type='hidden' name='internalCode' value='${requestParameters.internalCode?if_exists}'/> + <input type='hidden' name='productId' value='${requestParameters.productId?if_exists}'/> + <input type='hidden' name='inventoryItemId' value='${requestParameters.inventoryItemId?if_exists}'/> + <input type='hidden' name='serialNumber' value='${requestParameters.serialNumber?if_exists}'/> + <input type='hidden' name='softIdentifier' value='${requestParameters.softIdentifier?if_exists}'/> + <input type='hidden' name='partyId' value='${requestParameters.partyId?if_exists}'/> + <input type='hidden' name='userLoginId' value='${requestParameters.userLoginId?if_exists}'/> + <input type='hidden' name='billingAccountId' value='${requestParameters.billingAccountId?if_exists}'/> + <input type='hidden' name='createdBy' value='${requestParameters.createdBy?if_exists}'/> + <input type='hidden' name='minDate' value='${requestParameters.minDate?if_exists}'/> + <input type='hidden' name='maxDate' value='${requestParameters.maxDate?if_exists}'/> + <input type='hidden' name='roleTypeId' value="${requestParameters.roleTypeId?if_exists}"/> + <input type='hidden' name='orderTypeId' value='${requestParameters.orderTypeId?if_exists}'/> + <input type='hidden' name='salesChannelEnumId' value='${requestParameters.salesChannelEnumId?if_exists}'/> + <input type='hidden' name='productStoreId' value='${requestParameters.productStoreId?if_exists}'/> + <input type='hidden' name='orderWebSiteId' value='${requestParameters.orderWebSiteId?if_exists}'/> + <input type='hidden' name='orderStatusId' value='${requestParameters.orderStatusId?if_exists}'/> + <input type='hidden' name='hasBackOrders' value='${requestParameters.hasBackOrders?if_exists}'/> + <input type='hidden' name='filterInventoryProblems' value='${requestParameters.filterInventoryProblems?if_exists}'/> + <input type='hidden' name='filterPartiallyReceivedPOs' value='${requestParameters.filterPartiallyReceivedPOs?if_exists}'/> + <input type='hidden' name='filterPOsOpenPastTheirETA' value='${requestParameters.filterPOsOpenPastTheirETA?if_exists}'/> + <input type='hidden' name='filterPOsWithRejectedItems' value='${requestParameters.filterPOsWithRejectedItems?if_exists}'/> +</form> +</#if> <form method="post" name="lookuporder" action="<@ofbizUrl>searchorders</@ofbizUrl>" onsubmit="javascript:lookupOrders();"> <input type="hidden" name="lookupFlag" value="Y"/> <input type="hidden" name="hideFields" value="Y"/> @@ -73,9 +107,9 @@ <ul> <li class="h3">${uiLabelMap.OrderFindOrder}</li> <#if requestParameters.hideFields?default("N") == "Y"> - <li><a href="<@ofbizUrl>searchorders?hideFields=N&viewSize=${viewSize}&viewIndex=${viewIndex}&${paramList}</@ofbizUrl>">${uiLabelMap.CommonShowLookupFields}</a></li> + <li><a href="javascript:document.lookupandhidefields${requestParameters.hideFields}.submit()">${uiLabelMap.CommonShowLookupFields}</a></li> <#else> - <#if orderList?exists><li><a href="<@ofbizUrl>searchorders?hideFields=Y&viewSize=${viewSize}&viewIndex=${viewIndex}&${paramList}</@ofbizUrl>">${uiLabelMap.CommonHideFields}</a></li></#if> + <#if orderList?exists><li><a href="javascript:document.lookupandhidefields${requestParameters.hideFields}.submit()">${uiLabelMap.CommonHideFields}</a></li></#if> <li><a href="/partymgr/control/findparty?externalLoginKey=${requestAttributes.externalLoginKey?if_exists}">${uiLabelMap.PartyLookupParty}</a></li> <li><a href="javascript:lookupOrders(true);">${uiLabelMap.OrderLookupOrder}</a></li> </#if> |
Free forum by Nabble | Edit this page |