Requests and RFQs
What this page covers
The tracking sources define detail lookups and presentation for purchase requests (PRs) and request-for-quotations (RFQs), plus linked-request expansion, RFQ deadline editing, and comment retrieval/forms. The central unresolved boundary is record scope: supplied identifiers are interpolated into SQL, while the retrieved predicates do not establish an office, user, tenant, or equivalent ownership check.
[!WARNING] Treat both input safety and record ownership as unresolved in these surfaces. The PR, RFQ, linked-request, deadline, and comment queries shown here do not establish validation or parameterization for supplied identifiers, and their predicates do not prove that the requester may access the selected record.
Trace the source-defined record flow
flowchart TD
prId[Supplied PR identifier] --> prLookup[PR.php lookup]
prLookup --> prRecord[PR detail record]
prRecord --> prView[PR detail table]
rfqId[Supplied RFQ identifier] --> rfqLookup[RFQ.php lookup]
rfqLookup --> rfqRecord[RFQ detail record]
rfqRecord --> rfqView[RFQ detail table]
rfqRecord --> prControl[Split pr-control-no]
prControl --> consolidate[Consolidation lookup]
consolidate -->|truthy| emptyBranch[Empty branch]
consolidate -->|false| linkedPr[Linked PR rows]
linkedPr --> prSummary[PR summary]
linkedPr --> prItems[pr-detail rows]
prItems --> itemEntries[RFQ item entries]
commentInput[Comment type and id] --> commentSelect[Select PR or RFQ comment table]
commentSelect --> commentQuery[Comment lookup]
commentQuery --> commentJson[JSON response]
The PR path in imspr/novusoft/include/track/custom/PR.php selects the purchase-request record whose PR-no equals the supplied $id. The RFQ path in imspr/novusoft/include/track/custom/RFQ.php applies the same pattern to request-quotation and rfq-control-no.
For RFQ linked-request presentation, imspr/novusoft/include/rfq/custom/view-rfq.php reads pr-control-no, splits it on semicolons, and checks tbl_bmct_consolidate. Its truthy branch is empty. Only the false branch retrieves linked purchase-request rows and pr-detail rows, then maps them into the PR summary and pr_data item entries.
This diagram represents source-defined relationships only. The retrieved evidence does not establish route registration, runtime reachability, or successful execution.
Compare PR and RFQ tracking details
| Surface | Lookup | Status predicate | Detail fields presented |
|---|---|---|---|
| PR | PUB."purchase-request" where PR-no equals supplied $id |
$record['PR-approved'] truthy → APPROVED; otherwise PENDING |
certify-by, approved-by, request-by-date, request-by-time, date-approved, date-approved-time |
| RFQ | PUB."request-quotation" where rfq-control-no equals supplied $id |
rfq-approved equal to an empty string → PENDING; otherwise APPROVED |
request-by, approved-by, rfq-date, date-approved |
The custom PR and RFQ sources derive status and place the supplied identifiers in their titles, while the corresponding tracking views consume selected record fields; the retrieved evidence does not establish the runtime order or reachability of that cross-file relationship.
Inspect deadline and comment surfaces
[
{
"title": "RFQ deadline editing",
"body": "The source at `imspr/novusoft/include/track/custom/show-rfq.php` retrieves fields whose action is `rfq-deadline`, ordered by `order` descending. It looks up `tbl_bmct_rfq` using the supplied id and `is_comment = 0`; an existing row selects the `edit` action, while no row selects `add`, and an existing row is exposed as `main_data`. The view at `imspr/novusoft/include/track/view/show-rfq.php` renders the `submit_rfq` Save button with `data-action` and `data-id` attributes. That view does not itself prove a persistence call."
},
{
"title": "PR and RFQ comments",
"body": "In `imspr/novusoft/include/track/custom/get-comment.php`, type `PR` selects `tbl_bmct_pr` with `pr_no`; type `RFQ` selects `tbl_bmct_rfq` with `rfq_no`. The query selects `status`, `comment`, `comment_by`, and `comment_datetime` where the selected identifier equals the supplied id and `is_comment = 1`. Rows are formatted as Date, User, Remarks/Comment, and Status; when no truthy result data is available, the response uses `No Comment Available`, then emits JSON. The form at `imspr/novusoft/include/track/view/comments.php` exposes hidden user, status, id, and type fields, a `comment` text field, and the `commentaction` button in a GET form."
}
]
[!CAUTION] The sources do not establish a completed write handoff. The comments view contains a line-commented permission guard, the RFQ detail source contains a line-commented
insertoperation, and no retrieved source proves a comment persistence handler or deadline Save consumer. The comment source emits JSON, but no exact endpoint, HTTP method, registration, or runtime result is established.
Updated