PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmDb.php +69 -109 6.26 → trunk View file →
@@ -5,49 +5,8 @@
5 5
6 6 class FrmDb {
7 7
8 8 /**
9 - * The table name for Formidable Fields.
10 - *
11 - * @var string
12 - */
13 - public $fields;
14 -
15 - /**
16 - * The table name for Formidable Forms.
17 - *
18 - * @var string
19 - */
20 - public $forms;
21 -
22 - /**
23 - * The table name for Formidable Entries.
24 - *
25 - * @var string
26 - */
27 - public $entries;
28 -
29 - /**
30 - * The table name for Formidable Entry Metas.
31 - *
32 - * @var string
33 - */
34 - public $entry_metas;
35 -
36 - public function __construct() {
37 - if ( ! defined( 'ABSPATH' ) ) {
38 - die( 'You are not allowed to call this page directly.' );
39 - }
40 -
41 - _deprecated_function( __METHOD__, '2.05.06', 'FrmMigrate' );
42 - global $wpdb;
43 - $this->fields = $wpdb->prefix . 'frm_fields';
44 - $this->forms = $wpdb->prefix . 'frm_forms';
45 - $this->entries = $wpdb->prefix . 'frm_items';
46 - $this->entry_metas = $wpdb->prefix . 'frm_item_metas';
47 - }
48 -
49 - /**
50 9 * Change array into format $wpdb->prepare can use
51 10 *
52 11 * @param array $args
53 12 * @param string $starts_with
@@ -54,10 +13,10 @@
54 13 *
55 14 * @return void
56 15 */
57 16 public static function get_where_clause_and_values( &$args, $starts_with = ' WHERE ' ) {
58 - if ( empty( $args ) ) {
59 - // add an arg to prevent prepare from failing
17 + if ( ! $args ) {
18 + // Add an arg to prevent prepare from failing
60 19 $args = array(
61 20 'where' => $starts_with . '1=%d',
62 21 'values' => array( 1 ),
63 22 );
@@ -92,10 +51,11 @@
92 51 unset( $args['or'] );
93 52 }
94 53
95 54 foreach ( $args as $key => $value ) {
96 - $where .= empty( $where ) ? $base_where : $condition;
97 - $array_inc_null = ( ! is_numeric( $key ) && is_array( $value ) && in_array( null, $value ) );
55 + $where .= $where ? $condition : $base_where;
56 + // phpcs:ignore WordPress.PHP.StrictInArray.MissingTrueStrict
57 + $array_inc_null = ! is_numeric( $key ) && is_array( $value ) && in_array( null, $value );
98 58
99 59 if ( is_numeric( $key ) || $array_inc_null ) {
100 60 $where .= ' ( ';
101 61 $nested_where = '';
@@ -120,12 +80,12 @@
120 80 }//end foreach
121 81 }
122 82
123 83 /**
124 - * @param string $key
125 - * @param array|string $value
126 - * @param string $where
127 - * @param array $values
84 + * @param string $key
85 + * @param array|string|null $value
86 + * @param string $where
87 + * @param array $values
128 88 *
129 89 * @return void
130 90 */
131 91 private static function interpret_array_to_sql( $key, $value, &$where, &$values ) {
@@ -130,9 +90,9 @@
130 90 */
131 91 private static function interpret_array_to_sql( $key, $value, &$where, &$values ) {
132 92 $key = trim( $key );
133 93
134 - if ( strpos( $key, 'created_at' ) !== false || strpos( $key, 'updated_at' ) !== false ) {
94 + if ( str_contains( $key, 'created_at' ) || str_contains( $key, 'updated_at' ) ) {
135 95 $k = explode( ' ', $key );
136 96 $where .= ' CAST(' . reset( $k ) . ' as CHAR) ' . str_replace( reset( $k ), '', $key );
137 97 } else {
138 98 $where .= ' ' . $key;
@@ -141,10 +101,10 @@
141 101 $lowercase_key = explode( ' ', strtolower( $key ) );
142 102 $lowercase_key = end( $lowercase_key );
143 103
144 104 if ( is_array( $value ) ) {
145 - // translate array of values to "in"
146 - if ( strpos( $lowercase_key, 'like' ) !== false ) {
105 + // Translate array of values to "in"
106 + if ( str_contains( $lowercase_key, 'like' ) ) {
147 107 $where = preg_replace( '/' . $key . '$/', '', $where );
148 108 $where .= '(';
149 109 $start = true;
150 110
@@ -158,13 +118,13 @@
158 118 $values[] = '%' . self::esc_like( $v ) . '%';
159 119 }
160 120
161 121 $where .= ')';
162 - } elseif ( ! empty( $value ) ) {
122 + } elseif ( $value ) {
163 123 $where .= ' in (' . self::prepare_array_values( $value, '%s' ) . ')';
164 124 $values = array_merge( $values, $value );
165 125 }
166 - } elseif ( strpos( $lowercase_key, 'like' ) !== false ) {
126 + } elseif ( str_contains( $lowercase_key, 'like' ) ) {
167 127 /**
168 128 * Allow string to start or end with the value
169 129 * If the key is like% then skip the first % for starts with
170 130 * If the key is %like then skip the last % for ends with
@@ -182,14 +142,13 @@
182 142 }
183 143
184 144 $where .= ' %s';
185 145 $values[] = $start . self::esc_like( $value ) . $end;
186 -
187 146 } elseif ( $value === null ) {
188 147 $where .= ' IS NULL';
189 148 } else {
190 149 // allow a - to prevent = from being added
191 - if ( substr( $key, - 1 ) === '-' ) {
150 + if ( str_ends_with( $key, '-' ) ) {
192 151 $where = rtrim( $where, '-' );
193 152 } else {
194 153 $where .= '=';
195 154 }
@@ -211,9 +170,9 @@
211 170 *
212 171 * @return void
213 172 */
214 173 private static function add_query_placeholder( $key, $value, &$where ) {
215 - if ( is_numeric( $value ) && ( strpos( $key, 'meta_value' ) === false || strpos( $key, '+0' ) !== false ) ) {
174 + if ( is_numeric( $value ) && ( ! str_contains( $key, 'meta_value' ) || str_contains( $key, '+0' ) ) ) {
216 175 // Switch string to number.
217 176 $value = $value + 0;
218 177 $where .= is_float( $value ) ? '%f' : '%d';
219 178 } else {
@@ -229,9 +188,8 @@
229 188 * @return int
230 189 */
231 190 public static function get_count( $table, $where = array(), $args = array() ) {
232 191 $count = self::get_var( $table, $where, 'COUNT(*)', $args );
233 -
234 192 return (int) $count;
235 193 }
236 194
237 195 /**
@@ -252,14 +210,12 @@
252 210 if ( $type === 'var' && ! isset( $args['limit'] ) ) {
253 211 $args['limit'] = 1;
254 212 }
255 213
256 - $query = self::generate_query_string_from_pieces( $field, $table, $where, $args );
257 -
214 + $query = self::generate_query_string_from_pieces( $field, $table, $where, $args );
258 215 $cache_key = self::generate_cache_key( $where, $args, $field, $type );
259 - $results = self::check_cache( $cache_key, $group, $query, 'get_' . $type );
260 216
261 - return $results;
217 + return self::check_cache( $cache_key, $group, $query, 'get_' . $type );
262 218 }
263 219
264 220 /**
265 221 * Generate a cache key from the where query, field, type, and other arguments
@@ -281,11 +237,10 @@
281 237 $cache_key .= $key . '_' . $value;
282 238 }
283 239
284 240 $cache_key .= implode( '_', $args ) . $field . '_' . $type;
285 - $cache_key = str_replace( array( ' ', ',' ), '_', $cache_key );
286 241
287 - return $cache_key;
242 + return str_replace( array( ' ', ',' ), '_', $cache_key );
288 243 }
289 244
290 245 /**
291 246 * @param string $table
@@ -387,13 +342,13 @@
387 342
388 343 $prefix = $wpdb->base_prefix;
389 344 self::maybe_remove_prefix( $prefix, $group );
390 345
391 - if ( $group == $table ) {
346 + if ( $group === $table ) {
392 347 $table = $wpdb->prefix . $table;
393 348 }
394 349
395 - // switch to singular group name
350 + // Switch to singular group name
396 351 $group = rtrim( $group, 's' );
397 352 }
398 353
399 354 /**
@@ -406,9 +361,9 @@
406 361 *
407 362 * @return void
408 363 */
409 364 private static function maybe_remove_prefix( $prefix, &$name ) {
410 - if ( substr( $name, 0, strlen( $prefix ) ) === $prefix ) {
365 + if ( str_starts_with( $name, $prefix ) ) {
411 366 $name = substr( $name, strlen( $prefix ) );
412 367 }
413 368 }
414 369
@@ -423,13 +378,13 @@
423 378 if ( ! is_array( $args ) ) {
424 379 $args = array( 'order_by' => $args );
425 380 }
426 381
427 - if ( ! empty( $order_by ) ) {
382 + if ( $order_by ) {
428 383 $args['order_by'] = $order_by;
429 384 }
430 385
431 - if ( ! empty( $limit ) ) {
386 + if ( $limit ) {
432 387 $args['limit'] = $limit;
433 388 }
434 389
435 390 $temp_args = $args;
@@ -434,8 +389,9 @@
434 389
435 390 $temp_args = $args;
436 391
437 392 foreach ( $temp_args as $k => $v ) {
393 + // phpcs:ignore Universal.Operators.StrictComparisons
438 394 if ( $v == '' ) {
439 395 unset( $args[ $k ] );
440 396 continue;
441 397 }
@@ -441,19 +397,21 @@
441 397 }
442 398
443 399 $db_name = strtoupper( str_replace( '_', ' ', $k ) );
444 400
445 - if ( strpos( $v, $db_name ) === false ) {
401 + if ( ! str_contains( $v, $db_name ) ) {
446 402 $args[ $k ] = $db_name . ' ' . $v;
447 403 }
448 404 }
449 405
450 406 // Make sure LIMIT is the last argument
451 - if ( isset( $args['order_by'] ) && isset( $args['limit'] ) ) {
452 - $temp_limit = $args['limit'];
453 - unset( $args['limit'] );
454 - $args['limit'] = $temp_limit;
407 + if ( ! isset( $args['order_by'] ) || ! isset( $args['limit'] ) ) {
408 + return;
455 409 }
410 +
411 + $temp_limit = $args['limit'];
412 + unset( $args['limit'] );
413 + $args['limit'] = $temp_limit;
456 414 }
457 415
458 416 /**
459 417 * Get the associative array results for the given columns, table, and where query
@@ -469,14 +427,12 @@
469 427 public static function get_associative_array_results( $columns, $table, $where ) {
470 428 $group = '';
471 429 self::get_group_and_table_name( $table, $group );
472 430
473 - $query = self::generate_query_string_from_pieces( $columns, $table, $where );
474 -
431 + $query = self::generate_query_string_from_pieces( $columns, $table, $where );
475 432 $cache_key = str_replace( array( ' ', ',' ), '_', trim( implode( '_', FrmAppHelper::array_flatten( $where ) ) . $columns . '_results_ARRAY_A', ' WHERE' ) );
476 - $results = self::check_cache( $cache_key, $group, $query, 'get_associative_results' );
477 433
478 - return $results;
434 + return self::check_cache( $cache_key, $group, $query, 'get_associative_results' );
479 435 }
480 436
481 437 /**
482 438 * Combine the pieces of a query to form a full, prepared query
@@ -494,15 +450,17 @@
494 450 $query = 'SELECT ' . $columns . ' FROM ' . $table;
495 451
496 452 self::esc_query_args( $args );
497 453
498 - if ( is_array( $where ) || empty( $where ) ) {
499 - self::get_where_clause_and_values( $where );
500 - global $wpdb;
501 - $query = $wpdb->prepare( $query . $where['where'] . ' ' . implode( ' ', $args ), $where['values'] ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
454 + if ( ! is_array( $where ) && $where ) {
455 + return $query;
502 456 }
503 457
504 - return $query;
458 + self::get_where_clause_and_values( $where );
459 + global $wpdb;
460 +
461 + // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
462 + return $wpdb->prepare( $query . $where['where'] . ' ' . implode( ' ', $args ), $where['values'] );
505 463 }
506 464
507 465 /**
508 466 * @since 2.05.07
@@ -518,8 +476,9 @@
518 476 } elseif ( $param === 'limit' ) {
519 477 $args[ $param ] = self::esc_limit( $value );
520 478 }
521 479
480 + // phpcs:ignore Universal.Operators.StrictComparisons
522 481 if ( $args[ $param ] == '' ) {
523 482 unset( $args[ $param ] );
524 483 }
525 484 }
@@ -535,9 +494,8 @@
535 494 * @return string The escaped value
536 495 */
537 496 public static function esc_like( $term ) {
538 497 global $wpdb;
539 -
540 498 return $wpdb->esc_like( $term );
541 499 }
542 500
543 501 /**
@@ -547,9 +505,9 @@
547 505 *
548 506 * @return string
549 507 */
550 508 public static function esc_order( $order_query ) {
551 - if ( empty( $order_query ) ) {
509 + if ( ! $order_query ) {
552 510 return '';
553 511 }
554 512
555 513 // Remove ORDER BY before sanitizing.
@@ -554,18 +512,17 @@
554 512
555 513 // Remove ORDER BY before sanitizing.
556 514 $order_query = strtolower( $order_query );
557 515
558 - if ( strpos( $order_query, 'order by' ) !== false ) {
516 + if ( str_contains( $order_query, 'order by' ) ) {
559 517 $order_query = str_replace( 'order by', '', $order_query );
560 518 }
561 519
562 520 $order_query = explode( ' ', trim( $order_query ) );
521 + $order = trim( reset( $order_query ) );
522 + $safe_order = array( 'count(*)' );
563 523
564 - $order = trim( reset( $order_query ) );
565 - $safe_order = array( 'count(*)' );
566 -
567 - if ( ! in_array( strtolower( $order ), $safe_order ) ) {
524 + if ( ! in_array( strtolower( $order ), $safe_order, true ) ) {
568 525 $order = preg_replace( '/[^a-zA-Z0-9\-\_\.\+]/', '', $order );
569 526 }
570 527
571 528 $order_by = '';
@@ -602,9 +559,9 @@
602 559 *
603 560 * @return string
604 561 */
605 562 public static function esc_limit( $limit ) {
606 - if ( empty( $limit ) ) {
563 + if ( ! $limit ) {
607 564 return '';
608 565 }
609 566
610 567 $limit = trim( str_replace( 'limit ', '', strtolower( $limit ) ) );
@@ -637,9 +594,8 @@
637 594 * @return string
638 595 */
639 596 public static function prepare_array_values( $array, $type = '%s' ) {
640 597 $placeholders = array_fill( 0, count( $array ), $type );
641 -
642 598 return implode( ', ', $placeholders );
643 599 }
644 600
645 601 /**
@@ -650,14 +606,14 @@
650 606 *
651 607 * @return string
652 608 */
653 609 public static function prepend_and_or_where( $starts_with = ' WHERE ', $where = '' ) {
654 - if ( empty( $where ) ) {
610 + if ( ! $where ) {
655 611 $where = '';
656 612 } elseif ( is_array( $where ) ) {
657 - global $wpdb;
658 - self::get_where_clause_and_values( $where, $starts_with );
659 - $where = $wpdb->prepare( $where['where'], $where['values'] ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
613 + global $wpdb;
614 + self::get_where_clause_and_values( $where, $starts_with );
615 + $where = $wpdb->prepare( $where['where'], $where['values'] ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
660 616 } else {
661 617 $where = $starts_with . $where;
662 618 }
663 619
@@ -689,9 +645,9 @@
689 645 if ( empty( $settings['ID'] ) ) {
690 646 unset( $settings['ID'] );
691 647 }
692 648
693 - // delete all caches for this group
649 + // Delete all caches for this group
694 650 self::cache_delete_group( $group );
695 651
696 652 return self::save_json_post( $settings );
697 653 }
@@ -720,9 +676,9 @@
720 676 remove_all_filters( 'content_save_pre' );
721 677
722 678 $post = wp_insert_post( $settings );
723 679
724 - // add the content filters back for views or posts
680 + // Add the content filters back for views or posts
725 681 if ( isset( $filters ) ) {
726 682 $wp_filter['content_save_pre'] = $filters;
727 683 }
728 684
@@ -745,13 +701,13 @@
745 701 public static function check_cache( $cache_key, $group = '', $query = '', $type = 'get_var', $time = 300 ) {
746 702 $found = null;
747 703 $results = wp_cache_get( $cache_key, $group, false, $found );
748 704
749 - if ( ( $found === true && $results !== false ) || empty( $query ) ) {
705 + if ( ( $found === true && $results !== false ) || ! $query ) {
750 706 return $results;
751 707 }
752 708
753 - if ( 'get_posts' == $type ) {
709 + if ( 'get_posts' === $type ) {
754 710 $results = get_posts( $query );
755 711 } elseif ( 'get_associative_results' === $type ) {
756 712 global $wpdb;
757 713 $results = $wpdb->get_results( $query, OBJECT_K ); // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
@@ -775,12 +731,14 @@
775 731 *
776 732 * @return void
777 733 */
778 734 public static function set_cache( $cache_key, $results, $group = '', $time = 300 ) {
779 - if ( ! FrmAppHelper::prevent_caching() ) {
780 - self::add_key_to_group_cache( $cache_key, $group );
781 - wp_cache_set( $cache_key, $results, $group, $time );
735 + if ( FrmAppHelper::prevent_caching() ) {
736 + return;
782 737 }
738 +
739 + self::add_key_to_group_cache( $cache_key, $group );
740 + wp_cache_set( $cache_key, $results, $group, $time );
783 741 }
784 742
785 743 /**
786 744 * Keep track of the keys cached in each group so they can be deleted
@@ -809,9 +767,9 @@
809 767 public static function get_group_cached_keys( $group ) {
810 768 $cached = wp_cache_get( 'cached_keys', $group );
811 769
812 770 if ( ! $cached || ! is_array( $cached ) ) {
813 - $cached = array();
771 + return array();
814 772 }
815 773
816 774 return $cached;
817 775 }
@@ -840,15 +798,17 @@
840 798 */
841 799 public static function cache_delete_group( $group ) {
842 800 $cached_keys = self::get_group_cached_keys( $group );
843 801
844 - if ( ! empty( $cached_keys ) ) {
845 - foreach ( $cached_keys as $key ) {
846 - wp_cache_delete( $key, $group );
847 - }
802 + if ( ! $cached_keys ) {
803 + return;
804 + }
848 805
849 - wp_cache_delete( 'cached_keys', $group );
806 + foreach ( $cached_keys as $key ) {
807 + wp_cache_delete( $key, $group );
850 808 }
809 +
810 + wp_cache_delete( 'cached_keys', $group );
851 811 }
852 812
853 813 /**
854 814 * Checks if a DB column exists.