fix validation lengths per schema - #1001
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Attempted to edit imported product and the validation test for the description failed because it was (still) 50 characters.
Requested Copilot verify validation tests vs schema and implemented recommended changes.
Data validation conflicts in
Stocks.phpvs.stockmasterschemaDescriptionStocks.php:145: rejects ifmb_strlen() > 50; HTMLmaxlength="50"(Stocks.php:1003)varchar(255)BarCodeStocks.php:176: rejects ifmb_strlen() > 20, error message says "20 characters"; HTMLmaxlength="20"(Stocks.php:1305)varchar(50)StockIDStocks.php:157-168: only checks non-empty andContainsIllegalCharacters(); no max-length check in PHP. HTMLmaxlength="20"(Stocks.php:918) is the only length limit, and it's client-side onlyvarchar(64)maxlength=20) is far short of what the schema permits and easily bypassed (direct POST). A submitted StockID between 21–64 chars would be silently rejected by the UI, while one > 64 chars sent directly would hit the DB with no PHP-side check.Other fields checked and found consistent (no conflict):
Units— code limits to 20 chars, matchesunits varchar(20).DiscountCategory— HTMLmaxlength="2"matcheschar(2).CategoryID/TaxCat— populated from<select>lists sourced directly fromstockcategory/taxcategories, so values are inherently constrained by the FK relationship.EOQ,Volume,GrossWeight,NetWeight,Pansize,ShrinkFactor— only numeric/positive checks are needed since the schema columns aredouble/decimal, and that's what's tested.Recommended fix: relax the
Description(50→255) andBarCode(20→50) length checks (and their HTMLmaxlength/error text) to match the schema, and add an explicitmb_strlen($StockID) > 64check (with matching HTMLmaxlength="64") so the PHP validation actually enforces the schema'sstockid varchar(64)limit.