You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@ofbiz.apache.org by mo...@apache.org on 2009/05/26 19:58:59 UTC

svn commit: r778818 - /ofbiz/branches/release09.04/applications/product/webapp/facility/shipment/EditShipmentPackages.ftl

Author: mor
Date: Tue May 26 17:58:58 2009
New Revision: 778818

URL: http://svn.apache.org/viewvc?rev=778818&view=rev
Log:
Applied fix from trunk for revision: 778815 
 Securing URLs in FTL. Patch from Pranay Pandey, part of OFBIZ-2523 (https://issues.apache.org/jira/browse/OFBIZ-2523)

Modified:
    ofbiz/branches/release09.04/applications/product/webapp/facility/shipment/EditShipmentPackages.ftl

Modified: ofbiz/branches/release09.04/applications/product/webapp/facility/shipment/EditShipmentPackages.ftl
URL: http://svn.apache.org/viewvc/ofbiz/branches/release09.04/applications/product/webapp/facility/shipment/EditShipmentPackages.ftl?rev=778818&r1=778817&r2=778818&view=diff
==============================================================================
--- ofbiz/branches/release09.04/applications/product/webapp/facility/shipment/EditShipmentPackages.ftl (original)
+++ ofbiz/branches/release09.04/applications/product/webapp/facility/shipment/EditShipmentPackages.ftl Tue May 26 17:58:58 2009
@@ -75,9 +75,13 @@
                     <input type="text" size="5" name="insuredValue" value="${shipmentPackage.insuredValue?if_exists}"/>
                 </td>
                 <td><a href="javascript:document.updateShipmentPackageForm${shipmentPackageData_index}.submit();" class="buttontext">${uiLabelMap.CommonUpdate}</a></td>
-                <td><a href="<@o...@ofbizUrl>" class="buttontext">${uiLabelMap.CommonDelete}</a></td>
+                <td><a href="javascript:document.deleteShipmentPackage_${shipmentPackageData_index}.submit();" class="buttontext">${uiLabelMap.CommonDelete}</a></td>
             </tr>
             </form>
+            <form name="deleteShipmentPackage_${shipmentPackageData_index}" method="post" action="<@o...@ofbizUrl>">
+                <input type="hidden" name="shipmentId" value="${shipmentId}"/>
+                <input type="hidden" name="shipmentPackageSeqId" value="${shipmentPackage.shipmentPackageSeqId}"/>
+            </form>
         <#list shipmentPackageContents as shipmentPackageContent>
             <tr valign="middle"<#if alt_row> class="alternate-row"</#if>>
                 <td>&nbsp;</td>
@@ -86,12 +90,17 @@
                     <div>
                         <span class="label">${uiLabelMap.ProductQuantity}</span>
                         ${shipmentPackageContent.quantity?if_exists}
-                        <a href="<@o...@ofbizUrl>" class="buttontext">${uiLabelMap.CommonDelete}</a>
+                        <a href="javascript:document.deleteShipmentPackageContent${shipmentPackageData_index}${shipmentPackageContent_index}.submit();" class="buttontext">${uiLabelMap.CommonDelete}</a>
                     </div>
                 </td>
                 <td>&nbsp;</td>
                 <td>&nbsp;</td>
             </tr>
+            <form name="deleteShipmentPackageContent${shipmentPackageData_index}${shipmentPackageContent_index}" method="post" action="<@o...@ofbizUrl>">
+                <input type="hidden" name="shipmentId" value="${shipmentId}"/>
+                <input type="hidden" name="shipmentPackageSeqId" value="${shipmentPackageContent.shipmentPackageSeqId}"/>
+                <input type="hidden" name="shipmentItemSeqId" value="${shipmentPackageContent.shipmentItemSeqId}"/>
+            </form>
         </#list>
             <tr valign="middle"<#if alt_row> class="alternate-row"</#if>>
                 <form action="<@o...@ofbizUrl>" name="createShipmentPackageContentForm${shipmentPackageData_index}">
@@ -120,7 +129,7 @@
                 </form>
             </tr>
         <#list shipmentPackageRouteSegs as shipmentPackageRouteSeg>
-            <form action="<@o...@ofbizUrl>" name="updateShipmentPackageRouteSegForm${shipmentPackageData_index}${shipmentPackageRouteSeg_index}">
+            <form action="<@o...@ofbizUrl>" method="post" name="updateShipmentPackageRouteSegForm${shipmentPackageData_index}${shipmentPackageRouteSeg_index}">
             <input type="hidden" name="shipmentId" value="${shipmentId}"/>
             <input type="hidden" name="shipmentRouteSegmentId" value="${shipmentPackageRouteSeg.shipmentRouteSegmentId}"/>
             <input type="hidden" name="shipmentPackageSeqId" value="${shipmentPackageRouteSeg.shipmentPackageSeqId}"/>
@@ -133,12 +142,17 @@
                         <span class="label">${uiLabelMap.ProductBox}</span>
                         <input type="text" size="5" name="boxNumber" value="${shipmentPackageRouteSeg.boxNumber?if_exists}"/>
                         <a href="javascript:document.updateShipmentPackageRouteSegForm${shipmentPackageData_index}${shipmentPackageRouteSeg_index}.submit();" class="buttontext">${uiLabelMap.CommonUpdate}</a>
-                        <a href="<@o...@ofbizUrl>" class="buttontext">${uiLabelMap.CommonDelete}</a>
+                        <a href="javascript:document.deleteShipmentPackageRouteSeg${shipmentPackageData_index}${shipmentPackageRouteSeg_index}.submit();" class="buttontext">${uiLabelMap.CommonDelete}</a>
                     </div>
                 </td>
                 <td>&nbsp;</td>
             </tr>
             </form>
+            <form name="deleteShipmentPackageRouteSeg${shipmentPackageData_index}${shipmentPackageRouteSeg_index}" method="post" action="<@o...@ofbizUrl>">
+                <input type="hidden" name="shipmentId" value="${shipmentId}"/>
+                <input type="hidden" name="shipmentPackageSeqId" value="${shipmentPackageRouteSeg.shipmentPackageSeqId}"/>
+                <input type="hidden" name="shipmentRouteSegmentId" value="${shipmentPackageRouteSeg.shipmentRouteSegmentId}"/>
+            </form>
         </#list>
             <#--
             <tr valign="middle"<#if alt_row> class="alternate-row"</#if>>