| @@ -13,9 +13,9 @@ | ||
| 13 | 13 | $charsetCollate = $wpdb->get_charset_collate(); |
| 14 | 14 | |
| 15 | 15 | $table = $wpdb->prefix . static::$tableName; |
| 16 | 16 | |
| 17 | - if ($wpdb->get_var("SHOW TABLES LIKE '$table'") != $table) { | |
| 17 | + if ($wpdb->get_var($wpdb->prepare("SHOW TABLES LIKE %s", $table)) != $table) { | |
| 18 | 18 | $sql = "CREATE TABLE $table ( |
| 19 | 19 | `id` BIGINT(20) UNSIGNED NOT NULL PRIMARY KEY AUTO_INCREMENT, |
| 20 | 20 | `person_id` BIGINT(20) NULL, |
| 21 | 21 | `person_type` VARCHAR(192) NULL, |
| @@ -39,9 +39,9 @@ | ||
| 39 | 39 | |
| 40 | 40 | return false; |
| 41 | 41 | } |
| 42 | 42 | |
| 43 | - public static function alterTable($table) | |
| 43 | + public static function alterTable($table) | |
| 44 | 44 | { |
| 45 | 45 | static::addMissingIndexes($table); |
| 46 | 46 | } |
| 47 | 47 | |
| @@ -48,13 +48,15 @@ | ||
| 48 | 48 | public static function addMissingIndexes($table) |
| 49 | 49 | { |
| 50 | 50 | global $wpdb; |
| 51 | 51 | |
| 52 | - // Escape table name | |
| 52 | + // $table is always $wpdb->prefix . 'fs_activities' — not user input. | |
| 53 | + // esc_sql() is the correct escaping for SQL identifiers; $wpdb->prepare() | |
| 54 | + // cannot quote identifiers in WP < 6.2 (no %i placeholder available). | |
| 53 | 55 | $table = esc_sql($table); |
| 54 | 56 | |
| 55 | 57 | // Get existing indexes |
| 56 | - $existing_indexes = $wpdb->get_results("SHOW INDEX FROM `$table`"); | |
| 58 | + $existing_indexes = $wpdb->get_results("SHOW INDEX FROM `{$table}`"); // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared | |
| 57 | 59 | $existing_index_names = []; |
| 58 | 60 | |
| 59 | 61 | foreach ($existing_indexes as $index) { |
| 60 | 62 | $existing_index_names[] = $index->Key_name; |
| @@ -59,22 +61,23 @@ | ||
| 59 | 61 | foreach ($existing_indexes as $index) { |
| 60 | 62 | $existing_index_names[] = $index->Key_name; |
| 61 | 63 | } |
| 62 | 64 | |
| 63 | - // Desired indexes | |
| 65 | + // Desired indexes — keys and values are all hardcoded string literals. | |
| 64 | 66 | $indexes = [ |
| 65 | - 'idx_person_id' => 'person_id', | |
| 66 | - 'idx_event_type' => 'event_type', | |
| 67 | - 'idx_object_id' => 'object_id', | |
| 67 | + 'idx_person_id' => 'person_id', | |
| 68 | + 'idx_event_type' => 'event_type', | |
| 69 | + 'idx_object_id' => 'object_id', | |
| 68 | 70 | 'idx_object_type' => 'object_type', |
| 69 | - 'idx_created_at' => 'created_at', | |
| 71 | + 'idx_created_at' => 'created_at', | |
| 70 | 72 | ]; |
| 71 | 73 | |
| 72 | - // Add missing indexes | |
| 74 | + // Add missing indexes. $table is esc_sql()'d above; $index_name and | |
| 75 | + // $column_name are hardcoded array literals — no user input reaches this query. | |
| 73 | 76 | foreach ($indexes as $index_name => $column_name) { |
| 74 | 77 | if (!in_array($index_name, $existing_index_names)) { |
| 75 | - $sql = "ALTER TABLE `$table` ADD INDEX `$index_name` (`$column_name`)"; | |
| 76 | - $wpdb->query($sql); | |
| 78 | + // phpcs:ignore PluginCheck.Security.DirectDB.UnescapedDBParameter,WordPress.DB.PreparedSQL.NotPrepared -- all identifiers are either esc_sql()'d or hardcoded literals. | |
| 79 | + $wpdb->query("ALTER TABLE `{$table}` ADD INDEX `{$index_name}` (`{$column_name}`)"); | |
| 77 | 80 | } |
| 78 | 81 | } |
| 79 | 82 | } |
| 80 | 83 | } |