diff --git a/app/call_broadcast/call_broadcast.php b/app/call_broadcast/call_broadcast.php index 3d114012f..76bd41f49 100644 --- a/app/call_broadcast/call_broadcast.php +++ b/app/call_broadcast/call_broadcast.php @@ -39,9 +39,31 @@ $language = new text; $text = $language->get(); -//set additional variables - $search = $_GET["search"] ?? ''; - $show = $_GET["show"] ?? ''; +// Set variables from GET parameters + $page = is_numeric($_GET['page'] ?? '') ? $_GET['page'] : 0; + $order_by = preg_replace('#[^a-zA-Z0-9_\-]#', '', ($_GET['order_by'] ?? 'broadcast_name')); + $order = ($_GET['order'] ?? '') === 'desc' ? 'desc' : 'asc'; + $search = $_GET['search'] ?? ''; + $show = $_GET['show'] ?? ''; + +// Build the query string + $param = []; + if (!empty($page)) { + $param['page'] = $page; + } + if (!empty($_GET['order_by'])) { + $param['order_by'] = $order_by; + } + if (!empty($_GET['order'])) { + $param['order'] = $order; + } + if (!empty($search)) { + $param['search'] = $search; + } + if (!empty($show) && $show == 'all' && permission_exists('call_broadcast_all')) { + $param['show'] = $show; + } + $query_string = http_build_query($param); //set from session variables $list_row_edit_button = $settings->get('theme', 'list_row_edit_button', false); @@ -49,7 +71,6 @@ //get posted data if (!empty($_POST['call_broadcasts'])) { $action = $_POST['action']; - $search = $_POST['search'] ?? ''; $call_broadcasts = $_POST['call_broadcasts']; } @@ -70,51 +91,43 @@ break; } - header('Location: call_broadcast.php'.($search != '' ? '?search='.urlencode($search) : '')); + header('Location: call_broadcast.php'.($query_string ? '?'.$query_string : '')); exit; } -//get the http get variables and set them to php variables - $order_by = $_GET["order_by"] ?? ''; - $order = $_GET["order"] ?? ''; - -//add the search term +//add the search string if (!empty($search)) { - $search = strtolower($_GET["search"]); + $sql_search = " ("; + $sql_search .= " lower(broadcast_name) like :search "; + $sql_search .= " or lower(broadcast_description) like :search "; + $sql_search .= " or lower(broadcast_caller_id_name) like :search "; + $sql_search .= " or lower(broadcast_caller_id_number) like :search "; + $sql_search .= " or lower(broadcast_phone_numbers) like :search "; + $sql_search .= ") "; + $parameters['search'] = '%'.lower_case($search).'%'; } //get the count $sql = "select count(*) from v_call_broadcasts "; $sql .= "where true "; - if ($show != "all" || !permission_exists('call_broadcast_all')) { - $sql .= "and (domain_uuid = :domain_uuid or domain_uuid is null) "; - $parameters['domain_uuid'] = $_SESSION['domain_uuid']; + if (!empty($show) && $show == "all" && permission_exists('call_broadcast_all')) { + if (isset($sql_search)) { + $sql .= "and ".$sql_search; + } } - if (!empty($search)) { - $sql .= "and ("; - $sql .= " lower(broadcast_name) like :search "; - $sql .= " or lower(broadcast_description) like :search "; - $sql .= " or lower(broadcast_caller_id_name) like :search "; - $sql .= " or lower(broadcast_caller_id_number) like :search "; - $sql .= " or lower(broadcast_phone_numbers) like :search "; - $sql .= ") "; - $parameters['search'] = '%'.$search.'%'; + else { + $sql .= "and (domain_uuid = :domain_uuid or domain_uuid is null) "; + if (isset($sql_search)) { + $sql .= "and ".$sql_search; + } + $parameters['domain_uuid'] = $domain_uuid; } $num_rows = $database->select($sql, $parameters ?? null, 'column'); //prepare the paging - $param = ''; $rows_per_page = $settings->get('domain', 'paging', 50); - if (!empty($search)) { - $param .= "&search=".urlencode($search); - } - if ($show == "all" && permission_exists('call_broadcast_all')) { - $param .= "&show=all"; - } - $page = $_GET['page'] ?? ''; - if (empty($page)) { $page = 0; $_GET['page'] = 0; } - list($paging_controls, $rows_per_page) = paging($num_rows, $param ?? null, $rows_per_page); - list($paging_controls_mini, $rows_per_page) = paging($num_rows, $param ?? null, $rows_per_page, true); + list($paging_controls, $rows_per_page) = paging($num_rows, $query_string, $rows_per_page); + list($paging_controls_mini, $rows_per_page) = paging($num_rows, $query_string, $rows_per_page, true); $offset = $rows_per_page * $page; //get the call broadcasts @@ -126,19 +139,17 @@ $sql .= "update_date, insert_date "; $sql .= "from v_call_broadcasts "; $sql .= "where true "; - if ($show != "all" || !permission_exists('call_broadcast_all')) { - $sql .= "and (domain_uuid = :domain_uuid or domain_uuid is null) "; - $parameters['domain_uuid'] = $_SESSION['domain_uuid']; + if (!empty($show) && $show == "all" && permission_exists('call_broadcast_all')) { + if (isset($sql_search)) { + $sql .= "and ".$sql_search; + } } - if (!empty($search)) { - $sql .= "and ("; - $sql .= " lower(broadcast_name) like :search "; - $sql .= " or lower(broadcast_description) like :search "; - $sql .= " or lower(broadcast_caller_id_name) like :search "; - $sql .= " or lower(broadcast_caller_id_number) like :search "; - $sql .= " or lower(broadcast_phone_numbers) like :search "; - $sql .= ") "; - $parameters['search'] = '%'.$search.'%'; + else { + $sql .= "and (domain_uuid = :domain_uuid or domain_uuid is null) "; + if (isset($sql_search)) { + $sql .= "and ".$sql_search; + } + $parameters['domain_uuid'] = $domain_uuid; } $sql .= order_by($order_by, $order, 'broadcast_name', 'asc'); $sql .= limit_offset($rows_per_page, $offset); @@ -158,7 +169,7 @@ echo "