Bug 26592: [20.05] Prevent XSS vulnerabilities when circ/ysearch.pl is used
[koha.git] / koha-tmpl / intranet-tmpl / prog / en / includes / payments.inc
1 [% USE AuthorisedValues %]
2 [%- BLOCK account_payment_types -%]
3     [% SET payment_types = [] %]
4     [% FOR pt IN AuthorisedValues.GetAuthValueDropbox('PAYMENT_TYPE') %]
5         [% NEXT IF pt.authorised_value.grep("^SIP[[:digit:]]{2}$").size() %]
6         [% payment_types.push(pt) %]
7     [% END %]
8     [% IF payment_types.size > 0 %]
9         <li>
10             <label for="payment_type">Payment type: </label>
11             [% IF Koha.Preference('UseCashRegisters') %]
12             <select name="payment_type" id="payment_type" required>
13             [% ELSE %]
14             <select name="payment_type" id="payment_type">
15                 <option value=""></option>
16             [% END %]
17                 [% FOREACH pt IN payment_types %]
18                     <option value="[% pt.authorised_value | html %]">[% pt.lib | html %]</option>
19                 [% END %]
20             </select>
21         </li>
22     [% END %]
23 [%- END -%]