use strict;
use CGI;
use C4::Context;
+use C4::Auth qw/check_cookie_auth/;
my $input = new CGI;
my $query = $input->param('query');
-# FIXME: charset should be UTF-8 but borrowers table is still ISO-8859-1
-print $input->header(-type => 'text/plain', -charset => 'ISO-8859-1');
+binmode STDOUT, ":utf8";
+print $input->header(-type => 'text/plain', -charset => 'UTF-8');
+
+my ($auth_status, $sessionID) = check_cookie_auth($input->cookie('CGISESSID'), { circulate => '*' });
+if ($auth_status ne "ok") {
+ exit 0;
+}
my $dbh = C4::Context->dbh;
-$query = "SELECT surname, firstname, cardnumber, address, city, zipcode ".
- "FROM borrowers " .
- "WHERE surname LIKE '". $query . "%' " .
- "OR firstname LIKE '" . $query . "%' " .
- #"OR cardnumber LIKE '" . $query . "%' " .
- "ORDER BY surname, firstname ";
-my $sth = $dbh->prepare( $query );
-$sth->execute();
+my $sql = qq(SELECT surname, firstname, cardnumber, address, city, zipcode
+ FROM borrowers
+ WHERE surname LIKE ?
+ OR firstname LIKE ?
+ OR cardnumber LIKE ?);
+if (C4::Context->preference("IndependentBranchPatron")){
+ if (C4::Context->userenv && (C4::Context->userenv->{flags} % 2) !=1 && C4::Context->userenv->{'branch'}){
+ $sql.=" AND borrowers.branchcode =".$dbh->quote(C4::Context->userenv->{'branch'}) unless (C4::Context->userenv->{'branch'} eq "insecure");
+ }
+}
+
+$sql .= qq( ORDER BY surname, firstname);
+my $sth = $dbh->prepare( $sql );
+$sth->execute("$query%", "$query%", "$query%");
+
while ( my $rec = $sth->fetchrow_hashref ) {
print $rec->{surname} . ", " . $rec->{firstname} . "\t" .
$rec->{cardnumber} . "\t" .