List Filters
The Novusoft list-filter fragments declare feature-specific controls and hidden scope inputs. They are useful for locating field names, defaults, and option sources, but the fragments alone do not prove rendering, submitted-value consumption, successful filtering, or server-enforced authorization.
Feature controls
Source: imspr/novusoft/include/activity-log/filter.php
- Date range:
range[start]andrange[end], each initialized withdate(LONGDATE). - Module:
module_idwithall/All. - Particular status:
donewith0/Pendingselected,1/Done, andall/All.
Source: imspr/novusoft/include/consolidation/view/filter.php
- Year:
year. - The source sets
$yearfrom = 2023and$yearto = date('Y')+1. - The inclusive loop emits years from
$yearfromthrough$yearto; the currentdate('Y')option is marked selected.
Source: imspr/novusoft/include/office-map/view/filter.php
- Mapping state:
mappedwithALL,YES, andNO. - Keyword: empty text input
keyword.
Source: imspr/novusoft/include/ppmp-management/view/filter.php
- Status tabs:
PENDING,APPROVED,DISAPPROVED,CANCELED, andUNAPPROVED. - Year:
year, generated inclusively from2023through$year+4; the current year is marked selected. - Lock state:
lockwithall/All,1/Yes, and0/No. - Conditional hidden scope input:
office_idcontains$deptwhen$user_role_id!=1. - Hidden status input:
pr_statusis unconditionally set toPENDING.
The companion option helper in imspr/novusoft/include/ppmp-management/editor.php defines an ALL option when $wall is true. For category, it supplies POLICY, QUALITY PROCEDURE, WORK INSTRUCTION, and FORM. Other types use distinct rows from tbl_h_master_category, mapping department, devision, section, and unit to the source fields DEPT, ABBREV, ABBREV1, and ABBREV2, with display fields DEPT, DIV, SECTION, and UNIT.
Source: imspr/novusoft/include/pr-catalog/view/filter.php
- Status tabs:
PENDING,APPROVED,DISAPPROVED,CANCELED, andUNAPPROVED. - Year:
year, with inclusive bounds of2023through2023. - Conditional hidden scope input:
office_idcontains$deptwhen$user_role_id!=1. - Hidden status input:
pr_statusis unconditionally set toPENDING.
The user_id_created hidden input appears between /* ?> and <?php */ inside the $role==3 branch. It is block-commented out rather than emitted by the shown fragment.
Source: imspr/novusoft/include/pr/view/filter.php
- Status tabs:
PENDING,APPROVED,DISAPPROVED,CANCELED, andUNAPPROVED. - Year:
year, generated inclusively from2023throughdate('Y')+1; the current year is marked selected. - Conditional hidden scope input:
office_idcontains$deptwhen$user_role_id!=1. - Hidden status input:
pr_statusis unconditionally set toPENDING.
The user_id_created hidden input appears between /* ?> and <?php */ inside the $role==3 branch. It is block-commented out rather than emitted by the shown fragment.
The companion option helper in imspr/novusoft/include/pr/editor.php defines an ALL option when $wall is true. It supplies the same static category values—POLICY, QUALITY PROCEDURE, WORK INSTRUCTION, and FORM—and builds other type options from distinct rows in tbl_h_master_category using the department, devision, section, and unit mappings.
Source: imspr/novusoft/include/track/view/filter.php
- PR created date range:
range[start]andrange[end], each initialized withdate(LONGDATE). - Group stage:
gswithall/ALL, plus values from$json['filtergroup']. - Fields:
sfldwithexclude. - Value: text input
sval. - Submission control:
Submit. - Hidden date field:
range[field]is set topr_created_date.
Source: imspr/novusoft/include/view-ppmp/view/filter.php
- Year:
year, generated inclusively from2023through$year+4; the current year is marked selected.
Scope and authorization boundary
[!WARNING] The hidden
office_idvalue is a client-side scope input populated with$deptwhen$user_role_id!=1; it is not evidence of server-enforced access control. Theuser_id_createdrestrictions in the PPMP-management, PR-catalog, and PR fragments are block-commented out, so those shown controls do not provide an active creator-scope restriction. Verify the consuming implementation separately before treating any filter as an authorization boundary.
Updated