|
|
@@ -1,11 +1,13 @@
|
|
|
<?php
|
|
|
require_once '../connection.php';
|
|
|
|
|
|
+function e($s): string { return htmlspecialchars((string)($s ?? ''), ENT_QUOTES, 'UTF-8'); }
|
|
|
+
|
|
|
$enquiry_date = date("l dS M \'y");
|
|
|
|
|
|
-$drg = isset($_GET['drg']) ? $_GET['drg'] : '';
|
|
|
+$drg = isset($_GET['drg']) ? (int)$_GET['drg'] : 0;
|
|
|
|
|
|
-if (!empty($_GET['drg'])) {
|
|
|
+if (!empty($drg)) {
|
|
|
include "../table.php";
|
|
|
}
|
|
|
?>
|
|
|
@@ -17,7 +19,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<!-- Basic Page Needs -->
|
|
|
<meta charset="utf-8">
|
|
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
|
- <title><?php echo $title; ?> - Form 71a - <?php echo $street; ?> - <?php echo date("dmY"); ?></title>
|
|
|
+ <title><?php echo e($title); ?> - Form 71a - <?php echo e($street); ?> - <?php echo date("dmY"); ?></title>
|
|
|
<meta name="description" content="">
|
|
|
<meta name="author" content="">
|
|
|
|
|
|
@@ -63,8 +65,8 @@ if (!empty($_GET['drg'])) {
|
|
|
<tr>
|
|
|
<td width="12.5%">To:</td>
|
|
|
<td id="border" width="65%" style="font-weight:bold;">
|
|
|
- <?php echo $building_surveyor; ?> -
|
|
|
- <?php echo $bs_company; ?>
|
|
|
+ <?php echo e($building_surveyor); ?> -
|
|
|
+ <?php echo e($bs_company); ?>
|
|
|
</td>
|
|
|
<td width="27.5%">Building Surveyor</td>
|
|
|
</tr>
|
|
|
@@ -72,7 +74,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<tr>
|
|
|
<td width="12.5%">Address:</td>
|
|
|
<td id="border" width="65%">
|
|
|
- <?php echo $bs_address; ?>
|
|
|
+ <?php echo e($bs_address); ?>
|
|
|
</td>
|
|
|
<td width="27.5%">Address</td>
|
|
|
</tr>
|
|
|
@@ -80,7 +82,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<tr>
|
|
|
<td width="12.5%"> </td>
|
|
|
<td id="border" width="60%">
|
|
|
- <?php echo $bs_email; ?>
|
|
|
+ <?php echo e($bs_email); ?>
|
|
|
</td>
|
|
|
<td width="27.5%">Contact Details</td>
|
|
|
</tr>
|
|
|
@@ -119,26 +121,26 @@ if (!empty($_GET['drg'])) {
|
|
|
<tbody width="100%">
|
|
|
<tr>
|
|
|
<td width="12.5%">Builder:</td>
|
|
|
- <td id="border" width="40%"><?php echo $licenced_builder; ?></td>
|
|
|
+ <td id="border" width="40%"><?php echo e($licenced_builder); ?></td>
|
|
|
<td width="0%"> </td>
|
|
|
<td width="22.5%" style="text-align: right;">Project reference No.</td>
|
|
|
- <td id="border" width="25%">Bison Job # <span style="color: red;"><?php echo $qId; ?></span></td>
|
|
|
+ <td id="border" width="25%">Bison Job # <span style="color: red;"><?php echo e($qId); ?></span></td>
|
|
|
</tr>
|
|
|
|
|
|
<tr>
|
|
|
<td width="12.5%">Business:</td>
|
|
|
- <td id="border" width="40%"><?php echo $lb_company; ?></td>
|
|
|
+ <td id="border" width="40%"><?php echo e($lb_company); ?></td>
|
|
|
<td width="0%"> </td>
|
|
|
<td width="22.5%" style="text-align: right;">Licence No:</td>
|
|
|
- <td id="border"width="25%"><?php echo $lb_licence; ?></td>
|
|
|
+ <td id="border"width="25%"><?php echo e($lb_licence); ?></td>
|
|
|
</tr>
|
|
|
|
|
|
<tr>
|
|
|
<td width="12.5%">Address:</td>
|
|
|
- <td id="border" width="40%"><?php echo $lb_address; ?></td>
|
|
|
+ <td id="border" width="40%"><?php echo e($lb_address); ?></td>
|
|
|
<td width="0%"> </td>
|
|
|
<td width="22.5%" style="text-align: right;">Phone No:</td>
|
|
|
- <td id="border"width="25%"><?php echo $lb_mobile; ?></td>
|
|
|
+ <td id="border"width="25%"><?php echo e($lb_mobile); ?></td>
|
|
|
</tr>
|
|
|
|
|
|
<tr>
|
|
|
@@ -159,7 +161,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<td id="border" width="30%">Builder - Medium Rise</td>
|
|
|
<td width="0%"> </td>
|
|
|
<td width="12.5%" style="text-align: right;">Email Address:</td>
|
|
|
- <td id="border" width="42%"><?php echo $lb_email; ?></td>
|
|
|
+ <td id="border" width="42%"><?php echo e($lb_email); ?></td>
|
|
|
</tr>
|
|
|
|
|
|
</tbody>
|
|
|
@@ -194,7 +196,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<tr>
|
|
|
<td width="12.5%">Owner:</td>
|
|
|
<td id="border" width="88%">
|
|
|
- <?php echo $propertyOwner; ?>
|
|
|
+ <?php echo e($propertyOwner); ?>
|
|
|
</td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
@@ -206,19 +208,19 @@ if (!empty($_GET['drg'])) {
|
|
|
<tr>
|
|
|
<td width="12.5%">Business:</td>
|
|
|
<td id="border" width="40%">
|
|
|
- <?php echo $propertyName ; ?>
|
|
|
+ <?php echo e($propertyName); ?>
|
|
|
</td>
|
|
|
<td width="0%"> </td>
|
|
|
<td width="22.5%" style="text-align: right;">Phone No:</td>
|
|
|
<td id="border" width="25%">
|
|
|
- <?php echo $client_mobile; ?>
|
|
|
+ <?php echo e($client_mobile); ?>
|
|
|
</td>
|
|
|
</tr>
|
|
|
|
|
|
<tr>
|
|
|
<td width="12.5%">Address:</td>
|
|
|
<td id="border" width="40%">
|
|
|
- <?php echo $propertyAddress; ?>
|
|
|
+ <?php echo e($propertyAddress); ?>
|
|
|
</td>
|
|
|
<td width="0%"> </td>
|
|
|
<td width="22.5%" style="text-align: right;">Fax No:</td>
|
|
|
@@ -240,7 +242,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<td width="0%"> </td>
|
|
|
<td width="22.5%" style="text-align: right;">Email Address:</td>
|
|
|
<td id="border" width="42%">
|
|
|
- <?php echo $client_email; ?>
|
|
|
+ <?php echo e($client_email); ?>
|
|
|
</td>
|
|
|
</tr>
|
|
|
|
|
|
@@ -284,9 +286,9 @@ if (!empty($_GET['drg'])) {
|
|
|
<tbody width="100%">
|
|
|
<tr>
|
|
|
<td width="25%" style="text-align: right;">Certificate of Likely Compliance Number:</td>
|
|
|
- <td id="border" width="25%"><?php echo strtoupper(str_replace('_', '/', $compliance_no)); ?></td>
|
|
|
+ <td id="border" width="25%"><?php echo e(strtoupper(str_replace('_', '/', $compliance_no))); ?></td>
|
|
|
<td width="25%" style="text-align: right;">Permit or Certificate of Likely Compliance Number:</td>
|
|
|
- <td id="border" width="25%" class="text-uppercase"><?php echo strtoupper(str_replace('_', '/', $permit_no )); ?></td>
|
|
|
+ <td id="border" width="25%" class="text-uppercase"><?php echo e(strtoupper(str_replace('_', '/', $permit_no))); ?></td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
</table>
|
|
|
@@ -296,16 +298,16 @@ if (!empty($_GET['drg'])) {
|
|
|
<tbody width="100%">
|
|
|
<tr>
|
|
|
<td width="12.5%">Address:</td>
|
|
|
- <td id="border" width="40%"><?php echo $site_address; ?></td>
|
|
|
+ <td id="border" width="40%"><?php echo e($site_address); ?></td>
|
|
|
<td width="22.5%" style="text-align: right;">Lot No:</td>
|
|
|
- <td id="border" width="25%"><?php echo str_replace('_', '/', $volumeId) ; ?></td>
|
|
|
+ <td id="border" width="25%"><?php echo e(str_replace('_', '/', $volumeId)); ?></td>
|
|
|
</tr>
|
|
|
|
|
|
<tr>
|
|
|
<td width="12.5%"> </td>
|
|
|
<td id="border" width="40%"></td>
|
|
|
<td width="22.5%" style="text-align: right;">PID:</td>
|
|
|
- <td id="border" width="25%"><?php echo $propertyId; ?></td>
|
|
|
+ <td id="border" width="25%"><?php echo e($propertyId); ?></td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
</table>
|
|
|
@@ -315,7 +317,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<tbody width="100%">
|
|
|
<tr>
|
|
|
<td width="12.5%">The work:</td>
|
|
|
- <td id="border" width="87.5%">Proposed new <?php echo $size; ?> ( Approximately <?php echo ($length * $width ); ?>m2 ) - <?php echo $type; ?></td>
|
|
|
+ <td id="border" width="87.5%">Proposed new <?php echo e($size); ?> ( Approximately <?php echo e($length * $width); ?>m2 ) - <?php echo e($type); ?></td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
</table>
|
|
|
@@ -326,9 +328,9 @@ if (!empty($_GET['drg'])) {
|
|
|
<tbody width="100%">
|
|
|
<tr>
|
|
|
<td width="12.5%">Use of building:</td>
|
|
|
- <td id="border" width="40%"><?php echo $type; ?></td>
|
|
|
+ <td id="border" width="40%"><?php echo e($type); ?></td>
|
|
|
<td width="22.5%" style="text-align: right;">Building Class(es):</td>
|
|
|
- <td id="border"width="25%"><?php echo $building_class; ?></td>
|
|
|
+ <td id="border"width="25%"><?php echo e($building_class); ?></td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
</table>
|
|
|
@@ -374,7 +376,8 @@ if (!empty($_GET['drg'])) {
|
|
|
</table>
|
|
|
|
|
|
<?php
|
|
|
- $result = mysqli_query($con, " SELECT * FROM `council_forms` WHERE quote = " . $client_quote . " AND form_type = 'F71a' ORDER BY date ASC");
|
|
|
+ $signedDate = '';
|
|
|
+ $result = mysqli_query($con, "SELECT * FROM `council_forms` WHERE quote = " . (int)$client_quote . " AND form_type = 'F71a' ORDER BY date ASC");
|
|
|
if (!$result) {
|
|
|
printf("Error: %s\n", mysqli_error($con));
|
|
|
exit();
|
|
|
@@ -390,15 +393,15 @@ if (!empty($_GET['drg'])) {
|
|
|
<td width="12.5%">Builder:</td>
|
|
|
<!-- (builder or owner builder): -->
|
|
|
<td id="border" width="28%" style="font-size: 19px; color:blue;">
|
|
|
- <?php echo $licenced_builder; ?>
|
|
|
+ <?php echo e($licenced_builder); ?>
|
|
|
</td>
|
|
|
<td width="1.75%"></td>
|
|
|
<td id="border" width="28%" height="40px">
|
|
|
- <div class="signature"> <img src="images/signature/<?php echo strtolower(str_replace(' ', '_', $licenced_builder)); ?>-signature.png" height="40px" /> </div>
|
|
|
+ <div class="signature"> <img src="images/signature/<?php echo e(strtolower(str_replace(' ', '_', $licenced_builder))); ?>-signature.png" height="40px" /> </div>
|
|
|
</td>
|
|
|
<td width="1.75%"></td>
|
|
|
<td id="border" width="28%" style="font-size: 19px; color:blue;">
|
|
|
- <?php echo $signedDate; ?>
|
|
|
+ <?php echo e($signedDate); ?>
|
|
|
</td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
@@ -410,7 +413,7 @@ if (!empty($_GET['drg'])) {
|
|
|
<tr>
|
|
|
<td width="100%">
|
|
|
<p class="footer">
|
|
|
- <?php echo $qId; ?> - [Form 71a] - Document Printed on: <?php echo date("dS M Y");?> at <?php echo date("g:i A");?>
|
|
|
+ <?php echo e($qId); ?> - [Form 71a] - Document Printed on: <?php echo date("dS M Y");?> at <?php echo date("g:i A");?>
|
|
|
</p>
|
|
|
</td>
|
|
|
</tr>
|
|
|
@@ -420,4 +423,4 @@ if (!empty($_GET['drg'])) {
|
|
|
|
|
|
<!-- End Document -->
|
|
|
</body>
|
|
|
-</html>
|
|
|
+</html>
|