[fix] report_timesheet: replace string concatenation in sql query with sql parameteri...