171 lines
7.0 KiB
PHP
171 lines
7.0 KiB
PHP
<?php
|
|
session_start();
|
|
require_once 'db/config.php';
|
|
require_once 'auth-check.php';
|
|
require_once 'auth-helpers.php';
|
|
|
|
if (!can($_SESSION['user_role'], 'asset', 'update')) {
|
|
header('Location: index.php?error=access_denied');
|
|
exit;
|
|
}
|
|
|
|
$allowed_fields_str = can($_SESSION['user_role'], 'asset', 'update');
|
|
$allowed_fields = ($allowed_fields_str === '*') ? ['name', 'asset_tag', 'status', 'location', 'manufacturer', 'model', 'purchase_date'] : explode(',', $allowed_fields_str);
|
|
|
|
$success_message = '';
|
|
$error_message = '';
|
|
$asset = null;
|
|
|
|
if (!isset($_GET['id']) || !is_numeric($_GET['id'])) {
|
|
header("Location: index.php");
|
|
exit;
|
|
}
|
|
|
|
$asset_id = $_GET['id'];
|
|
|
|
try {
|
|
$pdo = db();
|
|
$stmt = $pdo->prepare("SELECT * FROM assets WHERE id = ?");
|
|
$stmt->execute([$asset_id]);
|
|
$asset = $stmt->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if (!$asset) {
|
|
header("Location: index.php?error=not_found");
|
|
exit;
|
|
}
|
|
} catch (PDOException $e) {
|
|
$error_message = 'Database error: ' . $e->getMessage();
|
|
}
|
|
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
$data = [];
|
|
$set_parts = [];
|
|
|
|
foreach ($allowed_fields as $field) {
|
|
if (isset($_POST[$field])) {
|
|
$data[] = $_POST[$field];
|
|
$set_parts[] = "$field = ?";
|
|
}
|
|
}
|
|
$data[] = $asset_id;
|
|
|
|
if (empty($set_parts)) {
|
|
$error_message = 'No data submitted.';
|
|
} else {
|
|
try {
|
|
$pdo = db();
|
|
$sql = sprintf("UPDATE assets SET %s WHERE id = ?", implode(', ', $set_parts));
|
|
$stmt = $pdo->prepare($sql);
|
|
$stmt->execute($data);
|
|
|
|
header("Location: index.php?success=asset_updated");
|
|
exit;
|
|
|
|
} catch (PDOException $e) {
|
|
$error_message = 'Database error: ' . $e->getMessage();
|
|
}
|
|
}
|
|
}
|
|
?>
|
|
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<title>Edit Asset - IC-Inventory</title>
|
|
<meta name="description" content="Edit an existing asset in the inventory.">
|
|
<link href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/css/bootstrap.min.css" rel="stylesheet">
|
|
<link rel="stylesheet" href="assets/css/custom.css?v=<?php echo time(); ?>">
|
|
<link rel="preconnect" href="https://fonts.googleapis.com">
|
|
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
|
|
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap" rel="stylesheet">
|
|
<script src="https://unpkg.com/feather-icons"></script>
|
|
</head>
|
|
<body>
|
|
|
|
<div class="wrapper">
|
|
<?php require_once 'templates/sidebar.php'; ?>
|
|
|
|
<main id="content">
|
|
<div class="header">
|
|
<h1>Edit Asset</h1>
|
|
<div class="theme-switcher" id="theme-switcher">
|
|
<i data-feather="moon"></i>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="surface p-4">
|
|
<?php if ($error_message): ?>
|
|
<div class="alert alert-danger"><?php echo htmlspecialchars($error_message); ?></div>
|
|
<?php endif; ?>
|
|
|
|
<?php if ($asset): ?>
|
|
<form action="edit-asset.php?id=<?php echo $asset_id; ?>" method="post">
|
|
<div class="row">
|
|
<?php if (in_array('name', $allowed_fields)): ?>
|
|
<div class="col-md-6 mb-3">
|
|
<label for="name" class="form-label">Asset Name*</label>
|
|
<input type="text" class="form-control" id="name" name="name" value="<?php echo htmlspecialchars($asset['name']); ?>" required>
|
|
</div>
|
|
<?php endif; ?>
|
|
<?php if (in_array('asset_tag', $allowed_fields)): ?>
|
|
<div class="col-md-6 mb-3">
|
|
<label for="asset_tag" class="form-label">Asset Tag*</label>
|
|
<input type="text" class="form-control" id="asset_tag" name="asset_tag" value="<?php echo htmlspecialchars($asset['asset_tag']); ?>" required>
|
|
</div>
|
|
<?php endif; ?>
|
|
</div>
|
|
<div class="row">
|
|
<?php if (in_array('status', $allowed_fields)): ?>
|
|
<div class="col-md-6 mb-3">
|
|
<label for="status" class="form-label">Status</label>
|
|
<select class="form-select" id="status" name="status">
|
|
<option <?php if ($asset['status'] === 'In Service') echo 'selected'; ?>>In Service</option>
|
|
<option <?php if ($asset['status'] === 'Under Repair') echo 'selected'; ?>>Under Repair</option>
|
|
<option <?php if ($asset['status'] === 'Retired') echo 'selected'; ?>>Retired</option>
|
|
</select>
|
|
</div>
|
|
<?php endif; ?>
|
|
<?php if (in_array('location', $allowed_fields)): ?>
|
|
<div class="col-md-6 mb-3">
|
|
<label for="location" class="form-label">Location</label>
|
|
<input type="text" class="form-control" id="location" name="location" value="<?php echo htmlspecialchars($asset['location']); ?>">
|
|
</div>
|
|
<?php endif; ?>
|
|
</div>
|
|
<div class="row">
|
|
<?php if (in_array('manufacturer', $allowed_fields)): ?>
|
|
<div class="col-md-6 mb-3">
|
|
<label for="manufacturer" class="form-label">Manufacturer</label>
|
|
<input type="text" class="form-control" id="manufacturer" name="manufacturer" value="<?php echo htmlspecialchars($asset['manufacturer']); ?>">
|
|
</div>
|
|
<?php endif; ?>
|
|
<?php if (in_array('model', $allowed_fields)): ?>
|
|
<div class="col-md-6 mb-3">
|
|
<label for="model" class="form-label">Model</label>
|
|
<input type="text" class="form-control" id="model" name="model" value="<?php echo htmlspecialchars($asset['model']); ?>">
|
|
</div>
|
|
<?php endif; ?>
|
|
</div>
|
|
<?php if (in_array('purchase_date', $allowed_fields)): ?>
|
|
<div class="mb-3">
|
|
<label for="purchase_date" class="form-label">Purchase Date*</label>
|
|
<input type="date" class="form-control" id="purchase_date" name="purchase_date" value="<?php echo htmlspecialchars($asset['purchase_date']); ?>" required>
|
|
</div>
|
|
<?php endif; ?>
|
|
|
|
<button type="submit" class="btn btn-primary">Update Asset</button>
|
|
<a href="index.php" class="btn btn-secondary">Cancel</a>
|
|
</form>
|
|
<?php endif; ?>
|
|
</div>
|
|
</main>
|
|
</div>
|
|
|
|
<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/js/bootstrap.bundle.min.js"></script>
|
|
<script src="assets/js/main.js?v=<?php echo time(); ?>"></script>
|
|
<script>
|
|
feather.replace();
|
|
</script>
|
|
</body>
|
|
</html>
|