www/includes/db_product.php

changeset 166
635033a29c48
parent 164
0a5abea575a9
child 185
4c25db9e8102
equal deleted inserted replaced
165:5970c8377b89 166:635033a29c48
49 $stageno = 10; 49 $stageno = 10;
50 else if ($stage == 'Closed') 50 else if ($stage == 'Closed')
51 $stageno = 11; 51 $stageno = 11;
52 52
53 // Basic settings 53 // Basic settings
54 $sql .= "uuid='" . $_POST['uuid']; 54 if (isset($_POST['uuid'])) {
55 $sql .= "uuid='" . $_POST['uuid'];
56 syslog(LOG_NOTICE, 'Keep uuid ');
57 } else {
58 $uuid = str_replace("\n", "", file_get_contents('/proc/sys/kernel/random/uuid'));
59 $sql .= "uuid='" . $uuid;
60 syslog(LOG_NOTICE, 'New uuid ');
61 }
55 $sql .= "', name='" . mysqli_real_escape_string($connect, $_POST['name']); 62 $sql .= "', name='" . mysqli_real_escape_string($connect, $_POST['name']);
56 $sql .= "', code='" . mysqli_real_escape_string($connect, $_POST['code']); 63 $sql .= "', code='" . mysqli_real_escape_string($connect, $_POST['code']);
57 $sql .= "', birth='" . $_POST['birth']; 64 $sql .= "', birth='" . $_POST['birth'];
58 $sql .= "', stage='" . $_POST['stage']; 65 $sql .= "', stage='" . $_POST['stage'];
59 $sql .= "', notes='" . mysqli_real_escape_string($connect, $_POST['notes']); 66 $sql .= "', notes='" . mysqli_real_escape_string($connect, $_POST['notes']);

mercurial