List Filters

The Novusoft list-filter fragments declare feature-specific controls and hidden scope inputs. They are useful for locating field names, defaults, and option sources, but the fragments alone do not prove rendering, submitted-value consumption, successful filtering, or server-enforced authorization.

Feature controls

Source: imspr/novusoft/include/activity-log/filter.php

  • Date range: range[start] and range[end], each initialized with date(LONGDATE).
  • Module: module_id with all / All.
  • Particular status: done with 0 / Pending selected, 1 / Done, and all / All.

Source: imspr/novusoft/include/consolidation/view/filter.php

  • Year: year.
  • The source sets $yearfrom = 2023 and $yearto = date('Y')+1.
  • The inclusive loop emits years from $yearfrom through $yearto; the current date('Y') option is marked selected.

Source: imspr/novusoft/include/office-map/view/filter.php

  • Mapping state: mapped with ALL, YES, and NO.
  • Keyword: empty text input keyword.

Source: imspr/novusoft/include/ppmp-management/view/filter.php

  • Status tabs: PENDING, APPROVED, DISAPPROVED, CANCELED, and UNAPPROVED.
  • Year: year, generated inclusively from 2023 through $year+4; the current year is marked selected.
  • Lock state: lock with all / All, 1 / Yes, and 0 / No.
  • Conditional hidden scope input: office_id contains $dept when $user_role_id!=1.
  • Hidden status input: pr_status is unconditionally set to PENDING.

The companion option helper in imspr/novusoft/include/ppmp-management/editor.php defines an ALL option when $wall is true. For category, it supplies POLICY, QUALITY PROCEDURE, WORK INSTRUCTION, and FORM. Other types use distinct rows from tbl_h_master_category, mapping department, devision, section, and unit to the source fields DEPT, ABBREV, ABBREV1, and ABBREV2, with display fields DEPT, DIV, SECTION, and UNIT.

Source: imspr/novusoft/include/pr-catalog/view/filter.php

  • Status tabs: PENDING, APPROVED, DISAPPROVED, CANCELED, and UNAPPROVED.
  • Year: year, with inclusive bounds of 2023 through 2023.
  • Conditional hidden scope input: office_id contains $dept when $user_role_id!=1.
  • Hidden status input: pr_status is unconditionally set to PENDING.

The user_id_created hidden input appears between /* ?> and <?php */ inside the $role==3 branch. It is block-commented out rather than emitted by the shown fragment.

Source: imspr/novusoft/include/pr/view/filter.php

  • Status tabs: PENDING, APPROVED, DISAPPROVED, CANCELED, and UNAPPROVED.
  • Year: year, generated inclusively from 2023 through date('Y')+1; the current year is marked selected.
  • Conditional hidden scope input: office_id contains $dept when $user_role_id!=1.
  • Hidden status input: pr_status is unconditionally set to PENDING.

The user_id_created hidden input appears between /* ?> and <?php */ inside the $role==3 branch. It is block-commented out rather than emitted by the shown fragment.

The companion option helper in imspr/novusoft/include/pr/editor.php defines an ALL option when $wall is true. It supplies the same static category values—POLICY, QUALITY PROCEDURE, WORK INSTRUCTION, and FORM—and builds other type options from distinct rows in tbl_h_master_category using the department, devision, section, and unit mappings.

Source: imspr/novusoft/include/track/view/filter.php

  • PR created date range: range[start] and range[end], each initialized with date(LONGDATE).
  • Group stage: gs with all / ALL, plus values from $json['filtergroup'].
  • Fields: sfld with exclude.
  • Value: text input sval.
  • Submission control: Submit.
  • Hidden date field: range[field] is set to pr_created_date.

Source: imspr/novusoft/include/view-ppmp/view/filter.php

  • Year: year, generated inclusively from 2023 through $year+4; the current year is marked selected.

Scope and authorization boundary

[!WARNING] The hidden office_id value is a client-side scope input populated with $dept when $user_role_id!=1; it is not evidence of server-enforced access control. The user_id_created restrictions in the PPMP-management, PR-catalog, and PR fragments are block-commented out, so those shown controls do not provide an active creator-scope restriction. Verify the consuming implementation separately before treating any filter as an authorization boundary.

Updated