PluginProbe
SQL Chart Builder / 3.0.4
SQL Chart Builder v3.0.4
3.0.5 3.0.4 3.0.3 3.0.2 3.0.1 trunk 1.0.2 1.0.3 2.2.2 2.3.0 2.3.1 2.3.2 2.3.3 2.3.4 2.3.5 2.3.6 2.3.7 2.3.7.1 2.3.7.2 2.3.8 3.0.0
← All changes | functions.php +1263 -292 1.0.33.0.4 View file →
@@ -1,21 +1,66 @@
1 1 <?php
2 -
2 +if (!defined('ABSPATH')) {
3 + die;
4 +}
3 5 //postinstall function
4 6 function guaven_sqlcharts_load_defaults()
5 7 {
6 - if (get_option("guaven_sqlcharts_already_installed") === false) {
7 - update_option("guaven_sqlcharts_already_installed", "1");
8 + if (get_option("guaven_sqlcharts_already_installed_2") === false) {
9 + update_option("guaven_sqlcharts_already_installed_2", "1");
8 10 guaven_sqlcharts_install_first_data();
11 +
9 12 }
10 13 }
11 14
15 +function guaven_sqlcharts_install_first_data()
16 +{
17 + require_once(dirname(__FILE__) . "/initial_data.php");
18 + gvn_chart_sample_nonxml_data();
19 +}
12 20
13 21
22 +function guaven_sqlcharts_recommended(){
23 + if(!class_exists('WooCommerce'))return;
24 + $uid=(int)get_current_user_id();
25 + if(isset($_GET["gvnsql_dismiss_recommendation"])){
26 + update_option('gvnsql_dismiss_recommendation_'.$uid,1);
27 + return;
28 + }
29 + if(get_option('gvnsql_dismiss_recommendation_'.$uid)!='')return;
30 + return '<table class="gf-alert gf-alert-info" style="margin-top:20px">
31 + <tbody><tr><td style="width: auto;vertical-align: top;padding: 20px;">
32 + <h2>WooCommerce Search Engine – INSTANT, RELEVANT AND SMART Search Box</h2>
33 + <h3>Turn your website search into Smart Search which find products by price, SKU, attributes, meta data, categorys, tags etc. </h3>
34 + <p>“WooCommerce Search Engine” is a very powerful and easy to use WooCommerce Search Plugin which turns a simple search box of your WooCommerce Store to the powerful multifunctional magic box which helps you to sell more products. The plugin UI is compatible with ALL THEMES.</p>
35 + <a target="_blank" style="border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;" class="button button-secondary"
36 + href="https://codecanyon.net/item/woocommerce-search-box/15685698">Get the Search Box </a>
37 + </td><td style="position:relative">
38 + <a href="'.admin_url().'/edit.php?post_type=gvn_schart&gvnsql_dismiss_recommendation=1'.'" style="position: absolute;right: 0;top: -15px;right: -10px;">{svg}
39 + </a>
40 + <img src="'.plugin_dir_url( __FILE__ ) . 'asset/img/recommended1.jpg" style="max-width: 430px;"></td></tr>
41 + </tbody></table>';
42 +}
14 43
44 +
45 +
15 46 function guaven_sqlcharts_my_admin_notice()
16 47 {
17 48 global $post;
49 +
50 +
51 + if(
52 + (!empty($_SERVER["REQUEST_URI"]) and strpos(sanitize_text_field(wp_unslash($_SERVER["REQUEST_URI"])),'post_type=gvn_schart')!==false)
53 + or
54 + (!empty($post) and $post->post_type == 'gvn_schart')
55 + ){
56 + echo str_replace('{svg}','<svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="11" height="14" viewBox="0 0 11 14">
57 + <path d="M10.141 10.328q0 0.312-0.219 0.531l-1.062 1.062q-0.219 0.219-0.531 0.219t-0.531-0.219l-2.297-2.297-2.297 2.297q-0.219 0.219-0.531 0.219t-0.531-0.219l-1.062-1.062q-0.219-0.219-0.219-0.531t0.219-0.531l2.297-2.297-2.297-2.297q-0.219-0.219-0.219-0.531t0.219-0.531l1.062-1.062q0.219-0.219 0.531-0.219t0.531 0.219l2.297 2.297 2.297-2.297q0.219-0.219 0.531-0.219t0.531 0.219l1.062 1.062q0.219 0.219 0.219 0.531t-0.219 0.531l-2.297 2.297 2.297 2.297q0.219 0.219 0.219 0.531z"></path>
58 + </svg>',wp_kses_post(guaven_sqlcharts_recommended(),[]));
59 + }
60 +
61 +
62 +
18 63 if (!empty($post) and $post->post_type == 'gvn_schart'):
19 64 if (!current_user_can('manage_options')) {
20 65 echo '<br><br>
21 66 <div class="updated gf-alert gf-alert-danger">Only administrators can manage this page</div>';
@@ -21,40 +66,128 @@
21 66 <div class="updated gf-alert gf-alert-danger">Only administrators can manage this page</div>';
22 67 die();
23 68 }
24 69 echo '<div class="updated gf-alert gf-alert-info">';
25 - if (empty($_GET["post"]) and strpos($_SERVER["REQUEST_URI"], "post-new") === false):
26 - $gf_message = 'Use <b>Add new</b> button above to create new sql report. And click on any existing rule names below
27 - to manage them. ';
28 - else:
29 - $gf_message = '
30 - 1. Give any name to your report.<br>
31 - 2. Choose chart type, type sql query, enter field names, labels and then press to Publish/Update<br>
32 - 3. After update you will see needed shortcode below. You can use that shortcode anywhere in your website: in pages, posts, widgets etc. <br>
33 - ';
34 -?>
35 - <?php
36 - endif;
37 - _e('<div style="float:left">' . $gf_message . '</div>', 'guaven_sqlcharts');
70 + if (empty($_GET["post"]) && strpos(sanitize_text_field(wp_unslash($_SERVER["REQUEST_URI"])), "post-new") === false) {
71 + $gf_message = __(
72 + 'Use <b>Add new</b> button above to create a new SQL report. And click on any existing rule names below to manage them.',
73 + 'guaven_sqlcharts'
74 + );
75 + } else {
76 + $gf_message = __(
77 + '1. Give any name to your report.<br>
78 + 2. Pick a chart type, build your SQL query with the visual builder (or type it — autocomplete will help), map the X/Y columns and press Publish/Update.<br>
79 + 3. After update, you will see the shortcode of this chart at the bottom of the page. You can use that shortcode anywhere in your website: in pages, posts, widgets, etc.',
80 + 'guaven_sqlcharts'
81 + );
82 + }
83 +
84 + echo '<div style="float:left;max-width:calc(100% - 345px)">';
85 + echo wp_kses_post( $gf_message );
86 + echo '</div>';
87 +
38 88 echo '<div style="float: right;
39 89 margin-top: 0px;
40 - padding-top: 0px;"><a class="button button-secondary" href="http://guaven.com/contact">Contact us for custom reports</a></div> </div>';
90 + padding-top: 0px;"><a target="_blank" style="text-align:center;border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;"
91 + class="button button-secondary" href="https://guaven.com/contact/solution-request/">Get Premium Support </a>
92 + <span style="line-height: 30px;padding: 0 5px;">OR</span>
93 + <a target="_blank" style="text-align:center;border:0px solid #26b286;border-radius:0px;color:white;font-weight:bold;background: #26b286;"
94 + class="button button-secondary" href="https://guaven.com/service/small-thankyou-premium-support-service/">Make a Small Donation</a>
95 + </div> </div>';
41 96 endif;
42 97 }
43 98 add_action('admin_notices', 'guaven_sqlcharts_my_admin_notice');
44 99
100 +function guaven_sqlcharts_onboarding_notice(){
101 + if((function_exists('wp_doing_ajax') and wp_doing_ajax()) or get_option('guaven_sqlcharts_onboarding_notice_dismissed') == 1)
102 + return;
45 103
104 + printf('
105 + <div class="guaven-sqlcharts-notice notice notice-success is-dismissible" data-notice="onboarding_notice">
106 + <p>Welcome aboard on MySQL Charts!</p>
107 + </div>'
108 + );
109 +}
110 +add_action('admin_notices', 'guaven_sqlcharts_onboarding_notice');
46 111
112 +function guaven_sqlcharts_onboarding_notice_dismissed(){
113 + check_ajax_referer('notice_dismissed', 'nonce');
114 + if (!current_user_can('manage_options')) return;
47 115
116 + if(empty($_POST['type']))return;
117 + switch ($_POST['type']){
118 + case 'onboarding_notice':
119 + update_option('guaven_sqlcharts_onboarding_notice_dismissed', 1);
120 + break;
121 + }
122 +}
123 +add_action('wp_ajax_guaven_sqlcharts_onboarding_notice_dismissed', 'guaven_sqlcharts_onboarding_notice_dismissed');
48 124
125 +function guaven_sqlcharts_enqueue_chart()
126 +{
127 + wp_enqueue_script('guaven_sqlcharts_chartjs', plugins_url('asset/chart.umd.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
128 + wp_enqueue_script('guaven_sqlcharts_datepicker', plugins_url('asset/datepicker.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
129 + wp_enqueue_script('guaven_sqlcharts_front', plugins_url('asset/front.js', __FILE__),array('jquery','guaven_sqlcharts_chartjs','guaven_sqlcharts_datepicker'),GVNSQLCHARTS_VERSION,false);
130 + wp_localize_script('guaven_sqlcharts_front', 'guaven_sqlcharts_notice_dismissed', array(
131 + 'action' => 'guaven_sqlcharts_onboarding_notice_dismissed',
132 + 'nonce' => wp_create_nonce('notice_dismissed')
133 + ));
49 134
135 +}
136 +add_action('wp_enqueue_scripts', 'guaven_sqlcharts_enqueue_chart');
137 +add_action('admin_enqueue_scripts', 'guaven_sqlcharts_enqueue_chart');
138 +
50 139 function guaven_sqlcharts_enqueue_main_style()
51 140 {
52 - wp_enqueue_style('guaven_sqlcharts_main_style', plugins_url('guaven_sqlcharts.css', __FILE__));
141 + wp_enqueue_style('guaven_sqlcharts_main_style', plugins_url('asset/guaven_sqlcharts.css', __FILE__),array(),GVNSQLCHARTS_VERSION);
53 142 }
143 +add_action('wp_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
144 +add_action('admin_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
54 145
55 -add_action('admin_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
146 +// admin-only assets: SQL builder, autocomplete, new metabox UI
147 +function guaven_sqlcharts_admin_assets($hook)
148 +{
149 + if (!in_array($hook, array('post.php', 'post-new.php'))) return;
150 + $screen = function_exists('get_current_screen') ? get_current_screen() : null;
151 + if (empty($screen->post_type) or $screen->post_type != 'gvn_schart') return;
152 + if (!current_user_can('manage_options')) return;
56 153
154 + wp_enqueue_style('guaven_sqlcharts_admin_style', plugins_url('asset/admin.css', __FILE__), array(), GVNSQLCHARTS_VERSION);
155 + wp_enqueue_script('guaven_sqlcharts_admin', plugins_url('asset/admin.js', __FILE__), array('jquery'), GVNSQLCHARTS_VERSION, true);
156 +
157 + global $wpdb;
158 + $tables = $wpdb->get_col('SHOW TABLES');
159 + if (!is_array($tables)) $tables = array();
160 + wp_localize_script('guaven_sqlcharts_admin', 'gvnSqlBuilder', array(
161 + 'ajaxurl' => admin_url('admin-ajax.php'),
162 + 'nonce' => wp_create_nonce('gvnsql_schema'),
163 + 'tables' => array_values($tables),
164 + 'prefix' => $wpdb->prefix,
165 + ));
166 +}
167 +add_action('admin_enqueue_scripts', 'guaven_sqlcharts_admin_assets');
168 +
169 +// returns column names of one table for the live SQL builder/autocomplete
170 +function guaven_sqlcharts_ajax_columns()
171 +{
172 + check_ajax_referer('gvnsql_schema', 'nonce');
173 + if (!current_user_can('manage_options')) wp_send_json_error('forbidden', 403);
174 + global $wpdb;
175 + $table = isset($_POST['table']) ? sanitize_text_field(wp_unslash($_POST['table'])) : '';
176 + $tables = $wpdb->get_col('SHOW TABLES');
177 + if (!is_array($tables) or !in_array($table, $tables, true)) wp_send_json_error('unknown table', 400);
178 + $cols = $wpdb->get_results('SHOW COLUMNS FROM `' . str_replace('`', '', $table) . '`');
179 + $out = array();
180 + if (is_array($cols)) {
181 + foreach ($cols as $col) {
182 + $out[] = array('name' => $col->Field, 'type' => $col->Type);
183 + }
184 + }
185 + wp_send_json_success($out);
186 +}
187 +add_action('wp_ajax_gvnsql_get_columns', 'guaven_sqlcharts_ajax_columns');
188 +
189 +
57 190 function guaven_sqlcharts_isJson($string)
58 191 {
59 192 json_decode($string);
60 193 return (json_last_error() == JSON_ERROR_NONE);
@@ -62,17 +195,61 @@
62 195
63 196 add_action('init', 'guaven_sqlcharts_register_post');
64 197 function guaven_sqlcharts_register_post()
65 198 {
66 - //register_taxonomy('guaven_update_push_tag', 'termin');
67 199 register_post_type('gvn_schart', array(
68 200 'labels' => array(
69 - 'name' => __('My SQL Charts'),
70 - 'singular_name' => __('My SQL chart')
201 + 'name' => __('My SQL Charts','guaven_sqlcharts'),
202 + 'singular_name' => __('SQL Chart','guaven_sqlcharts'),
203 + 'menu_name' => __('My SQL Charts','guaven_sqlcharts'),
204 + 'add_new' => __('Add Chart','guaven_sqlcharts'),
205 + 'add_new_item' => __('Add New Chart','guaven_sqlcharts'),
206 + 'edit_item' => __('Edit Chart','guaven_sqlcharts'),
207 + 'new_item' => __('New Chart','guaven_sqlcharts'),
208 + 'view_item' => __('View Chart','guaven_sqlcharts'),
209 + 'view_items' => __('View Charts','guaven_sqlcharts'),
210 + 'search_items' => __('Search Charts','guaven_sqlcharts'),
211 + 'not_found' => __('No charts found','guaven_sqlcharts'),
212 + 'not_found_in_trash' => __('No charts found in Trash','guaven_sqlcharts'),
213 + 'all_items' => __('All Charts','guaven_sqlcharts'),
214 + 'archives' => __('Chart Archives','guaven_sqlcharts'),
215 + 'attributes' => __('Chart Attributes','guaven_sqlcharts'),
216 + 'insert_into_item' => __('Insert into chart','guaven_sqlcharts'),
217 + 'uploaded_to_this_item' => __('Uploaded to this chart','guaven_sqlcharts'),
218 + 'filter_items_list' => __('Filter charts list','guaven_sqlcharts'),
219 + 'items_list_navigation' => __('Charts list navigation','guaven_sqlcharts'),
220 + 'items_list' => __('Charts list','guaven_sqlcharts'),
221 + 'item_published' => __('Chart published.','guaven_sqlcharts'),
222 + 'item_published_privately' => __('Chart published privately.','guaven_sqlcharts'),
223 + 'item_reverted_to_draft' => __('Chart reverted to draft.','guaven_sqlcharts'),
224 + 'item_scheduled' => __('Chart scheduled.','guaven_sqlcharts'),
225 + 'item_updated' => __('Chart updated.','guaven_sqlcharts'),
71 226 ),
72 -
227 +
73 228 'public' => true,
74 - //'taxonomies' => array('guaven_update_push_tag'),
229 + 'show_in_rest' => false,
230 + 'menu_icon' => 'dashicons-chart-pie',
231 + // Charts execute SQL, so every primitive capability of this post type maps to manage_options.
232 + // Contributors/Authors cannot create, edit, publish or delete charts through any WordPress
233 + // entry point (admin UI, XML-RPC, REST). Published charts stay viewable on the front end.
234 + // Only primitive capabilities are remapped: mapping the meta capabilities edit_post/read_post/
235 + // delete_post to manage_options would make WordPress treat manage_options itself as a meta
236 + // capability and break that check site-wide.
237 + 'capability_type' => 'post',
238 + 'map_meta_cap' => true,
239 + 'capabilities' => array(
240 + 'edit_posts' => 'manage_options',
241 + 'edit_others_posts' => 'manage_options',
242 + 'edit_published_posts' => 'manage_options',
243 + 'edit_private_posts' => 'manage_options',
244 + 'publish_posts' => 'manage_options',
245 + 'read_private_posts' => 'manage_options',
246 + 'delete_posts' => 'manage_options',
247 + 'delete_private_posts' => 'manage_options',
248 + 'delete_published_posts' => 'manage_options',
249 + 'delete_others_posts' => 'manage_options',
250 + 'create_posts' => 'manage_options',
251 + ),
75 252 'supports' => array(
76 253 'title',
77 254 'postmeta'
78 255 ),
@@ -77,12 +254,24 @@
77 254 'postmeta'
78 255 ),
79 256 'register_meta_box_cb' => 'guaven_sqlcharts_metabox_area'
80 257 ));
81 -
258 +
82 259 guaven_sqlcharts_load_defaults();
83 260 }
84 261
262 +// All guaven_sqlcharts_* meta keys are protected: they cannot be written through the Custom Fields box,
263 +// XML-RPC or the REST API. The plugin's own save handler (update_post_meta) is not affected.
264 +add_filter('is_protected_meta', function ($protected, $meta_key) {
265 + return strpos((string) $meta_key, 'guaven_sqlcharts_') === 0 ? true : $protected;
266 +}, 10, 2);
267 +
268 +// "Add title" placeholder on the chart edit screen
269 +add_filter('enter_title_here', function ($title, $post) {
270 + if (!empty($post) and $post->post_type == 'gvn_schart') return __('Chart name', 'guaven_sqlcharts');
271 + return $title;
272 +}, 10, 2);
273 +
85 274 add_action('admin_footer', 'guaven_sqlcharts_admin_front');
86 275
87 276
88 277 function guaven_sqlcharts_admin_front()
@@ -97,346 +286,1128 @@
97 286
98 287 // metabox for editor
99 288 function guaven_sqlcharts_metabox_area()
100 289 {
101 - add_meta_box('gvn_schart_metabox', 'Configure your graph chart', 'gvn_schart_metabox', 'gvn_schart', 'advanced', 'default');
290 + add_meta_box('guaven_sqlcharts_metabox', 'Chart Builder', 'guaven_sqlcharts_metabox', 'gvn_schart', 'advanced', 'default');
102 291 }
103 292
104 -function gvn_schart_metabox()
293 +function guaven_sqlcharts_metabox()
105 294 {
106 - global $post;
107 - wp_nonce_field('meta_box_nonce_action', 'meta_box_nonce_field');
108 -
109 -
110 -?>
111 -<h4>Choose your graph</h4>
112 -<p>
113 -<select name="guaven_sqlcharts_graphtype">
114 -<option value="pie" <?php
115 - $guaven_sqlcharts_graphtype = get_post_meta($post->ID, 'guaven_sqlcharts_graphtype', true);
116 - echo ($guaven_sqlcharts_graphtype == 'pie' ? 'selected' : '');
117 -?>>Pie Chart</option>
295 + require_once(dirname(__FILE__) . "/admin_metabox.php");
296 +}
118 297
119 - <option value="3dpie" <?php
120 - echo ($guaven_sqlcharts_graphtype == '3dpie' ? 'selected' : '');
121 -?>>3D Pie Chart</option>
298 +/**
299 + * Catalog of all supported chart types: label, group, per-type usage guide and example query.
300 + * Used by the admin UI to render the type cards and the contextual guides.
301 + */
302 +function guaven_sqlcharts_type_catalog()
303 +{
304 + global $wpdb;
305 + $p = $wpdb->posts;
306 + $u = $wpdb->users;
307 + return array(
308 + 'pie_l' => array(
309 + 'label' => 'Pie',
310 + 'group' => 'Circular',
311 + 'guide' => 'Best for showing how a total splits into a few parts (shares/percentages). Use one query that returns a label column (X) and a numeric value column (Y). Keep it under ~8 slices for readability.',
312 + 'example_sql' => "select count(*) postcount, SUBSTR(post_date,1,4) yearnum from $p group by yearnum order by yearnum asc limit 10",
313 + 'example_x' => 'yearnum', 'example_y' => 'postcount',
314 + ),
315 + 'donut_l' => array(
316 + 'label' => 'Doughnut',
317 + 'group' => 'Circular',
318 + 'guide' => 'Same as Pie but with a hole in the middle — slightly easier to compare slice sizes. One query: label column (X) + numeric column (Y).',
319 + 'example_sql' => "select count(*) postcount, post_type from $p group by post_type order by postcount desc limit 8",
320 + 'example_x' => 'post_type', 'example_y' => 'postcount',
321 + ),
322 + 'polar_l' => array(
323 + 'label' => 'Polar Area',
324 + 'group' => 'Circular',
325 + 'guide' => 'Like a pie, but every slice has the same angle and the value controls the radius. Good for cyclic data (months, weekdays). One query: label (X) + numeric value (Y).',
326 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,6,2) monthnum from $p group by monthnum order by monthnum",
327 + 'example_x' => 'monthnum', 'example_y' => 'postcount',
328 + ),
329 + 'radar_l' => array(
330 + 'label' => 'Radar',
331 + 'group' => 'Circular',
332 + 'guide' => 'Compares one or more series across several categories arranged in a circle. Great for profiles/ratings. Use one query per series, separated with ";".',
333 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,6,2) monthnum from $p where post_type=\"post\" group by monthnum order by monthnum",
334 + 'example_x' => 'monthnum', 'example_y' => 'postcount',
335 + ),
336 + 'line_l' => array(
337 + 'label' => 'Line',
338 + 'group' => 'Line',
339 + 'guide' => 'The classic choice for trends over time (per day/month/year). X should be an ordered value like a date. Add more queries separated with ";" for comparison lines.',
340 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p group by monthandyear order by monthandyear",
341 + 'example_x' => 'monthandyear', 'example_y' => 'postcount',
342 + ),
343 + 'area_l' => array(
344 + 'label' => 'Area',
345 + 'group' => 'Line',
346 + 'guide' => 'A line chart with the region under the line filled — emphasizes volume/magnitude of a trend. Works well with 2 queries (";" separated) to compare filled regions.',
347 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p where post_type=\"post\" group by monthandyear order by monthandyear;\nselect count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p where post_type!=\"post\" group by monthandyear order by monthandyear",
348 + 'example_x' => 'monthandyear', 'example_y' => 'Posts;Other content',
349 + ),
350 + 'steppedline_l' => array(
351 + 'label' => 'Stepped Line',
352 + 'group' => 'Line',
353 + 'guide' => 'Line chart that moves in steps instead of slopes — perfect for values that change at discrete moments (prices, stock level, settings history).',
354 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p group by yearnum order by yearnum",
355 + 'example_x' => 'yearnum', 'example_y' => 'postcount',
356 + ),
357 + 'bar_l' => array(
358 + 'label' => 'Bar',
359 + 'group' => 'Bar',
360 + 'guide' => 'Compares values across categories with vertical bars. One query: category (X) + numeric value (Y). Multiple ";" separated queries become grouped/stacked bars.',
361 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p group by monthandyear order by monthandyear",
362 + 'example_x' => 'monthandyear', 'example_y' => 'postcount',
363 + ),
364 + 'horizontalbar_l' => array(
365 + 'label' => 'Horizontal Bar',
366 + 'group' => 'Bar',
367 + 'guide' => 'Bar chart rotated 90° — the best pick when category names are long (user names, product titles).',
368 + 'example_sql' => "select count(*) as postcount, b.display_name as dname from $p a inner join $u b ON a.post_author=b.ID where a.post_status=\"publish\" group by a.post_author order by postcount desc limit 10",
369 + 'example_x' => 'dname', 'example_y' => 'postcount',
370 + ),
371 + 'stackedbar_l' => array(
372 + 'label' => 'Stacked Bar',
373 + 'group' => 'Bar',
374 + 'guide' => 'Shows how each category total is composed of parts. Use 2+ queries separated with ";" — each query becomes one segment color of the stack.',
375 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p where post_type=\"post\" group by yearnum order by yearnum;\nselect count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p where post_type!=\"post\" group by yearnum order by yearnum",
376 + 'example_x' => 'yearnum', 'example_y' => 'Posts;Other content',
377 + ),
378 + 'scatter_l' => array(
379 + 'label' => 'Scatter',
380 + 'group' => 'Other',
381 + 'guide' => 'Plots points on numeric X/Y axes to reveal correlation between two numbers. Both X and Y columns must be numeric (e.g. comment_count vs menu_order).',
382 + 'example_sql' => "select comment_count ccount, ID from $p where post_status=\"publish\" order by ID limit 100",
383 + 'example_x' => 'ID', 'example_y' => 'ccount',
384 + ),
385 + );
386 +}
122 387
123 -<option value="column" <?php
124 - echo ($guaven_sqlcharts_graphtype == 'column' ? 'selected' : '');
125 -?>>Column Chart</option>
388 +/**
389 + * Maps deprecated Google-Chart era type slugs to their Chart.js equivalents.
390 + * Old charts keep working without any manual migration; when the post is re-saved
391 + * from the new UI the normalized value is stored automatically.
392 + */
393 +function guaven_sqlcharts_normalize_type($type)
394 +{
395 + $map = array(
396 + 'pie' => 'pie_l',
397 + '3dpie' => 'pie_l',
398 + 'column' => 'bar_l',
399 + 'bar' => 'horizontalbar_l',
400 + 'area' => 'area_l',
401 + );
402 + return isset($map[$type]) ? $map[$type] : $type;
403 +}
126 404
127 -<option value="bar" <?php
128 - echo ($guaven_sqlcharts_graphtype == 'bar' ? 'selected' : '');
129 -?>>Bar Chart</option>
405 +function guaven_gutenberg_wrapper($atts){
406 + if(isset($atts['sqlcharts_inserted_script'])){
407 + global $sqlcharts_inserted_script;
408 + $sqlcharts_inserted_script = $atts['sqlcharts_inserted_script'];
409 + }
130 410
131 - <option value="area" <?php
132 - echo ($guaven_sqlcharts_graphtype == 'area' ? 'selected' : '');
133 -?>>Area Chart</option>
134 -
411 + $post = get_post($atts['chart_id']);
412 + if( ! isset($atts['chart_id']) or !isset($post) or $post->post_type != 'gvn_schart'){
135 413
136 -</select>
137 -</p>
138 -<hr>
414 + return "Invalid id";
415 + }
139 416
417 + return guaven_sqlcharts_local_shortcode(array('id' => $atts['chart_id'])); // temporary explicit value
418 +}
419 +function guaven_register_gutenberg_blocks()
420 +{
421 + wp_register_script(
422 + 'gvn_gutenberg_charts',
423 + plugins_url( 'asset/guaven_gutenberg_charts.js', __FILE__ ),
424 + array( 'wp-blocks', 'wp-i18n', 'wp-element', 'wp-server-side-render' ),
425 + GVNSQLCHARTS_VERSION.'_'.filemtime( plugin_dir_path( __FILE__ ) . 'asset/guaven_gutenberg_charts.js'),
426 + false
427 + );
428 + wp_localize_script('gvn_gutenberg_charts', 'guaven', array(
429 + 'description' => 'Add My SQL Chart to your post',
430 + ));
140 431
432 + register_block_type( 'guaven-sqlcharts/gvn-chart-gutenberg', array(
433 + 'editor_script' => 'gvn_gutenberg_charts',
434 + 'render_callback' => 'guaven_gutenberg_wrapper',
435 + 'attributes' => array(
436 + 'chart_id' => array(
437 + 'type' => 'string',
438 + 'default' => null
439 + ),
440 + 'sqlcharts_inserted_script' => array(
441 + 'type' => 'number',
442 + 'default' => null
443 + )
444 + )
445 + ));
446 +}
447 +add_action('init', 'guaven_register_gutenberg_blocks');
141 448
142 449
143 -<h4>Your SQL code </h4>
144 -<span>(Use double " " quotes instead of single ' ' ones)</span>
145 -<p>
146 -<textarea name="guaven_sqlcharts_code" id="guaven_sqlcharts_code" style="width:100%" rows="6"><?php
147 - echo (get_post_meta($post->ID, 'guaven_sqlcharts_code', true) != '' ? get_post_meta($post->ID, 'guaven_sqlcharts_code', true) : '');
148 -?>
149 -</textarea>
150 -</p>
151 -<p style="text-align: right;">Need help with custom SQL reports? <a href="http://guaven.com/contact">Contact us.</a></p>
152 -<hr>
153 450
451 +function guaven_sqlcharts_save_metabox_area($post_id, $post)
452 +{
453 + if (!isset($_POST['meta_box_nonce_field']) or !wp_verify_nonce($_POST['meta_box_nonce_field'], 'meta_box_nonce_action')) {
454 + return $post->ID;
455 + }
456 + if ($post->post_type != 'gvn_schart' or !current_user_can('manage_options') or (defined('DOING_AUTOSAVE') and DOING_AUTOSAVE)) {
457 + return $post->ID;
458 + }
459 + $fields = array(
460 + "guaven_sqlcharts_chartheight",
461 + "guaven_sqlcharts_chartwidth",
462 + "guaven_sqlcharts_graphtype",
463 + "guaven_sqlcharts_xarg_s",
464 + "guaven_sqlcharts_xarg_l",
465 + "guaven_sqlcharts_yarg_s",
466 + "guaven_sqlcharts_yarg_l",
467 + "guaven_sqlcharts_tablepart",
468 + "guaven_sqlcharts_variables",
469 + "guaven_sqlcharts_formpartrole",
470 + "guaven_sqlcharts_formpartbutton",
471 + "guaven_sqlcharts_dbhost",
472 + "guaven_sqlcharts_dblogin",
473 + "guaven_sqlcharts_dbname",
474 + "guaven_sqlcharts_colors",
475 + "guaven_sqlcharts_begin_with_0_x",
476 + "guaven_sqlcharts_begin_with_0_y",
477 + "guaven_sqlcharts_round_y_values",
478 + "guaven_sqlcharts_legend_position",
479 + "guaven_sqlcharts_nostacked",
480 + "guaven_sqlcharts_forcetooltips",
481 + "guaven_sqlcharts_timeaxis"
482 + );
483 + foreach ($fields as $key => $value) {
484 + if(isset($_POST[$value]))$newval=esc_attr($_POST[$value]);
485 + else $newval='';
154 486
487 + update_post_meta($post->ID, $value, $newval);
488 + }
489 + if(!empty($_POST["guaven_sqlcharts_dbpass"])){
490 + $encpass=guaven_sqlcharts_encrypt_decrypt('encrypt',$_POST["guaven_sqlcharts_dbpass"]);
491 + update_post_meta($post->ID, 'guaven_sqlcharts_dbpass', ['encrypted',$encpass]);
492 + }
493 + // Store the SQL as typed. Do not HTML-encode it and do not rewrite quotes:
494 + // the editor escapes it on output and the front end decodes entities before running it.
495 + $sql_code = isset($_POST['guaven_sqlcharts_code']) ? wp_check_invalid_utf8(wp_unslash($_POST['guaven_sqlcharts_code'])) : '';
496 + update_post_meta($post->ID, 'guaven_sqlcharts_code', $sql_code);
497 + // Flag that this chart stores raw SQL. Charts without the flag were saved by
498 + // versions before 3.0.1, which HTML-encoded the query, and still need decoding.
499 + update_post_meta($post->ID, 'guaven_sqlcharts_code_raw', 1);
500 +}
155 501
502 +// Returns the stored SQL query exactly as the user typed it.
503 +function guaven_sqlcharts_get_code($post_id)
504 +{
505 + $sql = get_post_meta($post_id, 'guaven_sqlcharts_code', true);
506 + if (get_post_meta($post_id, 'guaven_sqlcharts_code_raw', true) != 1) {
507 + $sql = html_entity_decode($sql, ENT_QUOTES, 'UTF-8');
508 + }
509 + return $sql;
510 +}
511 +add_action('save_post', 'guaven_sqlcharts_save_metabox_area', 1, 2);
512 +// save the custom fields
156 513
157 -<h4>Arguments</h4>
158 -<p>
159 -Label for Y axis: <br><input type="text" name="guaven_sqlcharts_xarg_l" id="guaven_sqlcharts_xarg_l" value="<?php
160 - echo get_post_meta($post->ID, 'guaven_sqlcharts_xarg_l', true);
161 -?>"></p>
162 - <p>
163 -SQL field name of Y axis (Write corresponding SQL field name here, which has a number value. f.e. post_count):
164 -<br>
165 -<input type="text" name="guaven_sqlcharts_xarg_s" id="guaven_sqlcharts_xarg_s" value="<?php
166 - echo get_post_meta($post->ID, 'guaven_sqlcharts_xarg_s', true);
167 -?>">
168 -</p>
169 514
170 -<p>
171 -Label for X axis: <br><input type="text" name="guaven_sqlcharts_yarg_l" id="guaven_sqlcharts_yarg_l" value="<?php
172 - echo get_post_meta($post->ID, 'guaven_sqlcharts_yarg_l', true);
173 -?>"></p><p>
174 -SQL field name of X axis (Write corresponding SQL field name here, which usually has a string value. f.e. display_name):
175 -<br>
176 -<input type="text" name="guaven_sqlcharts_yarg_s" id="guaven_sqlcharts_yarg_s" value="<?php
177 - echo get_post_meta($post->ID, 'guaven_sqlcharts_yarg_s', true);
178 -?>">
179 -</p>
180 515
181 -<hr>
516 +// Removes string literals (contents only), backtick identifiers and comments from SQL so keyword checks
517 +// see the same code MySQL will execute. "/*!" and "/*+" comments are executable in MySQL and are kept.
518 +function guaven_sqlcharts_strip_sql_literals($sql)
519 +{
520 + $out = ''; $len = strlen($sql); $i = 0;
521 + while ($i < $len) {
522 + $c = $sql[$i];
523 + if ($c === "'" or $c === '"' or $c === '`') {
524 + $out .= $c . $c; $i++;
525 + while ($i < $len) {
526 + if ($sql[$i] === '\\' and $c !== '`') { $i += 2; continue; }
527 + if ($sql[$i] === $c) { if ($i + 1 < $len and $sql[$i + 1] === $c) { $i += 2; continue; } $i++; break; }
528 + $i++;
529 + }
530 + continue;
531 + }
532 + if ($c === '#' or ($c === '-' and substr($sql, $i, 2) === '--' and ($i + 2 >= $len or ctype_space($sql[$i + 2])))) {
533 + $nl = strpos($sql, "\n", $i); $i = ($nl === false) ? $len : $nl; continue;
534 + }
535 + if ($c === '/' and substr($sql, $i, 2) === '/*' and !in_array(substr($sql, $i + 2, 1), array('!', '+'), true)) {
536 + $close = strpos($sql, '*/', $i + 2); $i = ($close === false) ? $len : $close + 2; $out .= ' '; continue;
537 + }
538 + $out .= $c; $i++;
539 + }
540 + return $out;
541 +}
182 542
543 +// Returns 1 when the (fully substituted) SQL must not run, 0 when it is a read-only query.
544 +// Called after every {tag}/{argN} replacement so user-supplied values are covered too.
545 +function gvn_chart_check_sql_query($sql)
546 +{
547 + // 1) data-changing statements: checked on the raw text, exactly as in every previous version
548 + $write = '/\b(delete|update|insert|replace|drop|truncate|alter|create|rename|grant|revoke|call|handler|load\s+data|load_file|outfile|dumpfile)\b/i';
549 + if (preg_match($write, $sql)) return 1;
183 550
184 -<h4>Width and height (with px. don't type px itself, just numbers)</h4>
185 -<p>
551 + // 2) further dangerous statements, matched outside string literals and comments so that ordinary
552 + // values such as status = 'reset' keep working
553 + $danger = '/\b(prepare|execute|deallocate|lock|unlock|kill|shutdown|flush|reset|purge|install|uninstall|import'
554 + . '|set\s+(?:global|session|persist|persist_only|password|@@)|start\s+(?:replica|slave|group_replication)|stop\s+(?:replica|slave)|change\s+(?:master|replication))\b/i';
555 + if (preg_match($danger, guaven_sqlcharts_strip_sql_literals($sql))) return 1;
186 556
187 -<input type="number" name="guaven_sqlcharts_chartwidth" id="guaven_sqlcharts_chartwidth" value="<?php
188 - echo get_post_meta($post->ID, 'guaven_sqlcharts_chartwidth', true);
189 -?>">
557 + // 3) every ";"-separated statement must be a read statement. The renderer sends each segment to the
558 + // database on its own, so this stops a value from smuggling a second statement behind a ";".
559 + foreach (explode(';', $sql) as $segment) {
560 + $segment = ltrim(guaven_sqlcharts_strip_sql_literals($segment), " \t\r\n(");
561 + if ($segment === '') continue;
562 + if (!preg_match('/^(select|with|show|describe|desc|explain)\b/i', $segment)) return 1;
563 + }
564 + return 0;
565 +}
190 566
191 -<input type="number" name="guaven_sqlcharts_chartheight" id="guaven_sqlcharts_chartheight" value="<?php
192 - echo get_post_meta($post->ID, 'guaven_sqlcharts_chartheight', true);
193 -?>">
194 -</p>
567 +function guaven_get_labels_and_values($id, $fvs)
568 +{
569 + $values = array();
570 + $labels = array();
571 + $xarg_s = get_post_meta($id, 'guaven_sqlcharts_xarg_s', true);
572 + $yarg_s = get_post_meta($id, 'guaven_sqlcharts_yarg_s', true);
573 + // labels are saved through esc_attr, so "&" is stored as "&amp;"; decode before splitting on ";"
574 + // or the entity's own ";" would be taken as a series separator
575 + $xarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_xarg_l', true), ENT_QUOTES, 'UTF-8');
576 + $yarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_yarg_l', true), ENT_QUOTES, 'UTF-8');
577 + foreach ($fvs as $key => $value) {
578 + $values[$value->$xarg_s] = $value->$yarg_s;
579 + $labels[$value->$xarg_s] = '"' . $value->$xarg_s . '"';
580 + }
581 + return array(
582 + $labels,
583 + $values,
584 + explode(";", $yarg_l),
585 + explode(";", $xarg_l)
586 + );
587 +}
195 588
196 -<hr>
589 +function guaven_sqlcharts_print_chart_js($print_data)
590 +{
591 + extract($print_data);
592 + $tip_g = guaven_sqlcharts_normalize_type($tip_g);
197 593
594 + switch ($tip_g) {
595 + case 'line_l':
596 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid);
597 + break;
598 + case 'area_l':
599 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'true', $pid);
600 + break;
601 + case 'steppedline_l':
602 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid, 'line', true);
603 + break;
604 + case 'radar_l':
605 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'radarfill', $pid, 'radar');
606 + break;
607 + case 'pie_l':
608 + guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid);
609 + break;
610 + case 'donut_l':
611 + guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'doughnut');
612 + break;
613 + case 'polar_l':
614 + guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'polarArea');
615 + break;
616 + case 'bar_l':
617 + guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'bar', $pid);
618 + break;
619 + case 'horizontalbar_l':
620 + guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'horizontalBar', $pid);
621 + break;
622 + case 'stackedbar_l':
623 + guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'stackedBar', $pid);
624 + break;
625 + case 'scatter_l':
626 + guaven_sqlcharts_scatterdata($title, $labels, $values, $ylabel, $pid);
627 + break;
628 + case 'custom':
629 + guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid);
630 + break;
631 + }
632 +}
198 633
634 +function guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid){
635 + do_action('guaven_sqlcharts_custom',$title, $labels, $values, $ylabel, $pid);
636 +}
199 637
638 +function gvn_chart_put_variables($sql,$pid){
639 + $sql_initial=$sql;
200 640
201 -<?php
202 - if (get_post_meta($post->ID, 'guaven_sqlcharts_graphtype', true) != '') {
203 -?>
204 -<div class="gf-alert-success gf-alert">
205 -<h4>
206 -Text shortcode: [gvn_schart id="<?php
207 - echo $post->ID;
208 -?>"]
209 -<br>
210 -<br>
211 -PHP shorcode: &lt;?php echo do_shortcode(' [gvn_schart id="<?php
212 - echo $post->ID;
213 -?>"]'); ?&gt;
214 -</h4>
215 -<p>Note: Shortcodes supports width and height attributes. F.e. [gvn_schart id="1" width="500" height="400"]. If no attributes, default width, height (which you enter in this page above) will be used.
216 -</div>
217 -<h4>Demo</h4>
218 -<?php
219 - echo do_shortcode(' [gvn_schart id="' . $post->ID . '"]');
220 -
641 +
642 + $default_tag_keys=['{current_user_id}','{current_user_login}','{current_user_email}','{current_user_display_name}'];
643 + if(is_user_logged_in( )){
644 + $currentuser=wp_get_current_user();
645 + $default_tag_values=[$currentuser->ID,$currentuser->user_login,$currentuser->user_email,$currentuser->user_display_name];
646 + }
647 + else {
648 + $default_tag_values='';
649 + }
650 + $sql_initial=str_replace($default_tag_keys,$default_tag_values,$sql_initial);
651 +
652 + $variables_raw=get_post_meta($pid,'guaven_sqlcharts_variables',true);
653 + $variables_arr=explode("|",$variables_raw);
654 + foreach($variables_arr as $varfield){
655 + $varfield_arr=explode("~",$varfield);
656 + if (count($varfield_arr)<3) continue;
657 + $varfield_arr=array_map("trim",$varfield_arr);
658 + if (!empty($_GET[$varfield_arr[0]])) {
659 + // User-supplied input: no () bypass allowed — sanitize strictly
660 + $varreplacement = str_replace(';', '', sanitize_text_field(wp_unslash($_GET[$varfield_arr[0]])));
661 + if (is_numeric($varreplacement)) {
662 + $varreplacement = $varreplacement + 0;
663 + } else {
664 + $varreplacement = '"' . esc_sql($varreplacement) . '"';
665 + }
666 + } else {
667 + // Admin-configured default value: allow () for SQL functions (e.g. NOW())
668 + $varreplacement = $varfield_arr[1];
669 + if (!is_numeric($varreplacement) && strpos($varreplacement,'()')===false) {
670 + $varreplacement = '"' . esc_sql($varreplacement) . '"';
671 + }
221 672 }
222 -
673 +
674 + $sql_initial=str_replace('{'.$varfield_arr[0].'}',$varreplacement,$sql_initial);
675 + }
676 + return $sql_initial;
223 677 }
224 678
679 +function gvn_chart_top_form($atts){
680 + if (get_post_meta($atts["id"],'guaven_sqlcharts_formpartrole',true)!='' and !is_user_logged_in()) return;
681 + $topform='';$dateexists=false;
682 + $variables_raw=get_post_meta($atts['id'],'guaven_sqlcharts_variables',true);
683 + $variables_raw=explode("|",$variables_raw);
684 + foreach ($variables_raw as $vrow){
685 + $vrow_arr=explode("~",$vrow);
686 + $vrow_arr=array_map("trim",$vrow_arr);
687 + if (empty($vrow_arr[3])) continue;
688 + $gvalue=!empty($_GET[$vrow_arr[0]])?esc_attr(urldecode($_GET[$vrow_arr[0]])):'';
689 + $dvalue=(strpos($vrow_arr[1],'()')===false)?esc_attr($vrow_arr[1]):'';
690 + if ($vrow_arr[3]=='date') {
691 + $dateexists=true;
692 + $topform.= '<span class="gvn-filter-field"><label>'.$vrow_arr[2].'</label> <input class="gws_datepicker" autocomplete="off" type="text"
693 + value="'.$gvalue.'"
694 + data-toggle="datepicker" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'"></span>
695 + ';}
696 + else {
697 + $topform.= '<span class="gvn-filter-field"><label>'.$vrow_arr[2].'</label> <input autocomplete="off"
698 + type="'.$vrow_arr[3].'"
699 + value="'.$gvalue.'" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'"></span>
700 + ';
701 + }
702 + }
703 + if (!empty($topform)) {
704 + $allowed_html = array(
705 + 'form' => array(
706 + 'method' => array(),
707 + 'action' => array(),
708 + 'class' => array()
709 + ),
710 + 'input' => array(
711 + 'type' => array(),
712 + 'value' => array(),
713 + 'name' => array(),
714 + 'class' => array(),
715 + 'data-toggle'=>array(),
716 + 'placeholder'=>array(),
717 + 'autocomplete'=>array(),
718 + 'style'=>[]
719 + ),
720 + 'span' => array('class' => array()),
721 + 'label' => array(),
722 + );
225 723
724 + $submit_button_value = get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true) != ''
725 + ? esc_attr(get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true))
726 + : 'OK';
226 727
227 -function gvn_schart_save_metabox_area($post_id, $post)
728 + $topform = '<form method="get" action="" class="guaven_sqlcharts_form">' . $topform . '
729 + <input type="submit" value="' . $submit_button_value . '"></form>';
730 +
731 + echo wp_kses($topform, $allowed_html);
732 + }
733 +}
734 +
735 +
736 +function guaven_sqlcharts_encrypt_decrypt($action, $string)
228 737 {
229 -
230 - if (!isset($_POST['meta_box_nonce_field']) or !wp_verify_nonce($_POST['meta_box_nonce_field'], 'meta_box_nonce_action')) {
231 - return $post->ID;
738 + $output = false;
739 + $encrypt_method = "AES-256-CBC";
740 + $secret_key = 'GWSCHARTPL2022.2016.';
741 + $secret_iv = 'GWSCHARTPL2016.2022';
742 + $key = hash('sha256', $secret_key);
743 + $iv = substr(hash('sha256', $secret_iv), 0, 16);
744 + if ( $action == 'encrypt' ) {
745 + $output = openssl_encrypt($string, $encrypt_method, $key, 0, $iv);
746 + $output = base64_encode($output);
747 + } else if( $action == 'decrypt' ) {
748 + $output = openssl_decrypt(base64_decode($string), $encrypt_method, $key, 0, $iv);
232 749 }
233 - $fields = array(
234 - "guaven_sqlcharts_chartheight",
235 - "guaven_sqlcharts_chartwidth",
236 - "guaven_sqlcharts_graphtype",
237 - "guaven_sqlcharts_code",
238 - "guaven_sqlcharts_xarg_s",
239 - "guaven_sqlcharts_xarg_l",
240 - "guaven_sqlcharts_yarg_s",
241 - "guaven_sqlcharts_yarg_l"
242 - );
243 - foreach ($fields as $key => $value) {
244 - update_post_meta($post->ID, $value, esc_attr($_POST[$value]));
750 + return $output;
751 +}
752 +
753 +function guaven_sqlcharts_local_shortcode($atts) {
754 + if(empty($atts['id']))return 'ID is missing.';
755 + $atts['id']=intval($atts['id']);
756 + $post_g = get_post($atts['id']);
757 + if (!$post_g or $post_g->post_type != 'gvn_schart') return 'Chart not found.';
758 + $remote_host=get_post_meta($atts['id'], 'guaven_sqlcharts_dbhost', true);
759 + if ($remote_host!=''){
760 + $remote_db=get_post_meta($atts['id'], 'guaven_sqlcharts_dbname', true);
761 + $remote_login=get_post_meta($atts['id'], 'guaven_sqlcharts_dblogin', true);
762 + $remote_pass=get_post_meta($atts['id'], 'guaven_sqlcharts_dbpass', true);
763 + if(is_array($remote_pass)){
764 + $remote_pass=guaven_sqlcharts_encrypt_decrypt('decrypt',$remote_pass[1]);
765 + }
766 + $wpdb=new wpdb($remote_login,$remote_pass,$remote_db,$remote_host);
245 767 }
768 + else {
769 + global $wpdb;
770 + }
771 +
772 + $GLOBALS["guaven_sqlcharts_atts"]=$atts;
773 +
774 + $sql = guaven_sqlcharts_get_code($atts['id']);
775 + if(empty($sql))return 'SQL query is missing.';
776 +
777 + // {arg1}..{arg19} come from shortcode attributes: [gvn_schart_2 id="1" arg1="41"].
778 + // Substituted directly (not via wpdb::prepare) so the same tag may appear any number of times,
779 + // e.g. in every query of a ";"-separated comparison chart. Numbers are inserted as-is, anything
780 + // else is escaped and quoted; a tag already wrapped in quotes ('{arg1}') is not double-quoted.
781 + // ";" is removed from values because the finished SQL is split on ";" below.
782 + for($i=1;$i<20;$i++){
783 + $tag = '{arg'.$i.'}';
784 + if (strpos($sql, $tag) === false) continue;
785 + $replacearg = !empty($atts['arg'.$i]) ? $atts['arg'.$i] : 0;
786 + if (is_numeric($replacearg)) $replacearg = $replacearg + 0;
787 + else $replacearg = "'" . esc_sql(str_replace(';', '', sanitize_text_field((string) $replacearg))) . "'";
788 + $sql = str_replace(array("'".$tag."'", '"'.$tag.'"', $tag), $replacearg, $sql);
789 + }
790 +
791 + $sql=gvn_chart_put_variables($sql,$atts['id']);
792 + $sql=apply_filters('guaven_sqlcharts_rendered_sql',$sql,$atts);
793 +
794 + // command check on the final SQL, after every shortcode argument and filter value is in place
795 + $blacklister_f = gvn_chart_check_sql_query($sql);
796 + if ($blacklister_f == 1)return 'You given SQL code contains forbidden commands. Remember that you should only use SELECT queries';
797 + $tip_g = guaven_sqlcharts_normalize_type(get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true));
798 +
799 + $sql_split = explode(';', $sql);
800 + $labels_and_values = array();
801 + $labels = $values = $ylabel = $xlabel = array();
802 +
803 + global $sqlcharts_inserted_script;
804 + ob_start();
805 + for ($i = 0; $i < count($sql_split); $i++) {
806 + if (!empty($sql_split[$i])) {
807 +
808 + $fvs = $wpdb->get_results($sql_split[$i]);
809 + if (strpos($_SERVER["REQUEST_URI"],'wp-admin')!==false){
810 + $wpdb->show_errors();
811 + ob_start();
812 + $wpdb->print_error();
813 + $printerror = ob_get_clean();
814 + if ($printerror != '' and strpos($printerror, "[]") === false){
815 + ob_end_clean();
816 + return $printerror;
817 + }
818 + elseif (empty($fvs)){
819 + ob_end_clean();
820 + return 'Your SQL returnes empty data, please recheck your SQL query above';
821 + }
822 + }
823 +
824 + if (empty($sqlcharts_inserted_script))
825 + $sqlcharts_inserted_script = 1;
826 + $labels_and_values[$i] = guaven_get_labels_and_values($atts['id'], $fvs);
827 + $labels[$i] = $labels_and_values[$i][0];
828 + $values[$i] = $labels_and_values[$i][1];
829 + $ylabel[$i] = !empty($labels_and_values[$i][2][$i]) ? $labels_and_values[$i][2][$i] : '';
830 + $xlabel[$i] = !empty($labels_and_values[$i][3][$i]) ? $labels_and_values[$i][3][$i] : '';
831 + }
832 + }
833 +
834 + gvn_chart_top_form($atts);
835 +
836 + // shortcode width/height attributes override the saved defaults
837 + $chart_w = !empty($atts['width']) ? $atts['width'] : get_post_meta($atts['id'], 'guaven_sqlcharts_chartwidth', true);
838 + $chart_h = !empty($atts['height']) ? $atts['height'] : get_post_meta($atts['id'], 'guaven_sqlcharts_chartheight', true);
839 + $wrap_style = '';
840 + if ($chart_w != '') $wrap_style .= 'max-width:' . (int) $chart_w . 'px;';
841 + if ($chart_h != '') $wrap_style .= 'height:' . (int) $chart_h . 'px;';
842 + ?>
843 + <div class="gvn-chartwrap"<?php echo $wrap_style != '' ? ' style="' . esc_attr($wrap_style) . '"' : ''; ?>>
844 + <canvas
845 + id="ct-chart_<?php echo esc_attr($sqlcharts_inserted_script); ?>"
846 + class="guaven_chart_canvas"
847 + ></canvas>
848 + </div>
849 +
850 + <script type="text/javascript" class="gvn_charts_script" async>
851 + var ctx = jQuery("#ct-chart_<?php
852 + echo esc_attr($sqlcharts_inserted_script);
853 + ?>");
854 +
855 + <?php
856 + $print_data=apply_filters('guaven_sqlcharts_pre_print_vars',['tip_g'=>$tip_g, 'title'=>$post_g->post_title,
857 + 'labels'=>$labels, 'values'=>$values, 'ylabel'=>$ylabel, 'pid'=>$atts['id']]);
858 + guaven_sqlcharts_print_chart_js($print_data);
859 + ?>
860 + </script>
861 +
862 + <?php
863 + if (!empty($atts["table"])) guaven_sqlcharts_tablepart($post_g->post_title, $labels, $values, $ylabel,$xlabel);
864 + $sqlcharts_inserted_script++;
865 + $ret=ob_get_clean();
866 + $ret=apply_filters( 'guaven_sqlcharts_final_output', $ret, $atts );
867 + return $ret;
246 868 }
247 -add_action('save_post', 'gvn_schart_save_metabox_area', 1, 2);
248 -// save the custom fields
249 869
870 +add_shortcode('gvn_schart_2', 'guaven_sqlcharts_local_shortcode');
250 871
872 +// legacy alias: old Google-Chart era posts produced [gvn_schart id=".."] shortcodes
873 +if (!shortcode_exists('gvn_schart')) {
874 + add_shortcode('gvn_schart', 'guaven_sqlcharts_local_shortcode');
875 +}
251 876
877 +// [gvn_schart_2_cached id="1" expire="3600" arg1=".."] – same as gvn_schart_2 but the output is kept in a
878 +// transient. All other attributes (argN, width, height, table, params) are passed through, and each
879 +// distinct set of attributes gets its own cache entry. Append ?force_sql_cache_reload to the URL to bypass.
880 +add_shortcode("gvn_schart_2_cached",function($atts){
881 + if(empty($atts["id"]))return;
882 + $atts["id"]=intval($atts["id"]);
883 + $expire=!empty($atts["expire"])?intval($atts["expire"]):3600;
884 + $inner_atts=$atts;
885 + unset($inner_atts['expire']);
886 + // One cache entry per user (charts may use {current_user_*} tags), per set of shortcode attributes
887 + // and per value of every dynamic filter this chart reads from the URL. A visitor can therefore
888 + // never be served, or pre-seed, a result computed for someone else or for other filter values.
889 + $key_parts = array('atts' => $inner_atts, 'user' => is_user_logged_in() ? get_current_user_id() : 0, 'get' => array());
890 + foreach (explode('|', (string) get_post_meta($atts['id'], 'guaven_sqlcharts_variables', true)) as $vrow) {
891 + $vname = trim(current(explode('~', $vrow)));
892 + if ($vname !== '' and isset($_GET[$vname])) $key_parts['get'][$vname] = sanitize_text_field(wp_unslash($_GET[$vname]));
893 + }
894 + $key = 'cached_sql_charts_' . $atts["id"] . '_' . md5(serialize($key_parts));
895 + $cached=get_transient($key);
896 + if(!empty($cached) and !isset($_GET["force_sql_cache_reload"]) )return $cached;
897 + $tobecached=guaven_sqlcharts_local_shortcode($inner_atts);
898 + set_transient($key, $tobecached,$expire);
899 + return $tobecached;
900 +});
252 901
253 -function gvn_schart_libloads($type, $step)
254 -{
255 - $stty = array(
256 - 'bar' => array(
257 - 'packages' => "'corechart', 'bar'",
258 - 'charts' => "BarChart"
259 - ),
260 - 'column' => array(
261 - 'packages' => "'corechart', 'bar'",
262 - 'charts' => "ColumnChart"
263 - ),
264 - 'area' => array(
265 - 'packages' => "'corechart'",
266 - 'charts' => "AreaChart"
267 - ),
268 - 'pie' => array(
269 - 'packages' => "'corechart'",
270 - 'charts' => "PieChart"
271 - ),
272 - '3dpie' => array(
273 - 'packages' => "'corechart'",
274 - 'charts' => "PieChart"
275 - )
276 - );
277 -
278 - return $stty[$type][$step];
902 +// fixed, colorblind-friendly default palette (Tableau 10) used when no custom colors are set
903 +function guaven_sqlcharts_default_palette(){
904 + return apply_filters('guaven_sqlcharts_default_palette', array(
905 + '#4E79A7', '#F28E2B', '#E15759', '#76B7B2', '#59A14F',
906 + '#EDC948', '#B07AA1', '#FF9DA7', '#9C755F', '#BAB0AC'
907 + ));
279 908 }
280 909
910 +function guaven_sqlcharts_colors($index, $pid = null){
911 + if(!isset($pid)) {
912 + global $post;
913 + $pid = $post->ID;
914 + }
915 + $colors=get_post_meta($pid,'guaven_sqlcharts_colors',true);
916 + $colors=explode(",",$colors);
917 + if (!empty($colors[$index])) return $colors[$index];
918 + $palette = guaven_sqlcharts_default_palette();
919 + return $palette[$index % count($palette)];
920 +}
281 921
922 +// outputs 'maintainAspectRatio:false,' when an explicit height is set, so the
923 +// chart fills its sized wrapper instead of keeping the default aspect ratio
924 +function guaven_sqlcharts_mar($pid){
925 + $atts = isset($GLOBALS["guaven_sqlcharts_atts"]) ? $GLOBALS["guaven_sqlcharts_atts"] : array();
926 + $h = !empty($atts['height']) ? $atts['height'] : get_post_meta($pid, 'guaven_sqlcharts_chartheight', true);
927 + return $h != '' ? 'maintainAspectRatio: false,' : '';
928 +}
282 929
930 +// outputs 'showAllTooltips: true,' when "Value labels" is checked; the values are drawn by the
931 +// gvnShowAllValues plugin in asset/front.js (works for every chart type)
932 +function guaven_sqlcharts_value_labels($pid){
933 + return get_post_meta($pid, 'guaven_sqlcharts_forcetooltips', true) != '' ? 'showAllTooltips: true,' : '';
934 +}
283 935
936 +// Chart.js scale title block built from the "X axis label" / "Y axis label" fields.
937 +// $which is 'x' or 'y' (the *field* to use, not the scale). The Y label is only used as an axis
938 +// title for single-series charts; with several ";"-separated series the legend names them instead.
939 +function guaven_sqlcharts_axis_title($pid, $which){
940 + $key = $which == 'x' ? 'guaven_sqlcharts_xarg_l' : 'guaven_sqlcharts_yarg_l';
941 + $text = trim(html_entity_decode((string) get_post_meta($pid, $key, true), ENT_QUOTES, 'UTF-8'));
942 + if ($text === '' or ($which == 'y' and strpos($text, ';') !== false)) return '';
943 + return 'title: {display: true, text: ' . wp_json_encode($text) . '},';
944 +}
284 945
946 +// "params" shortcode attribute: extra Chart.js dataset options, e.g. params="borderWidth: 3, borderDash: [5,5],".
947 +// The text is placed inside the inline <script>, so only a conservative character set is accepted:
948 +// no parentheses, semicolons, "=", "<", ">", "/", "\\", "+" or backticks, which rules out executable JavaScript.
949 +function guaven_sqlcharts_dataset_params(){
950 + $params = isset($GLOBALS["guaven_sqlcharts_atts"]["params"]) ? (string) $GLOBALS["guaven_sqlcharts_atts"]["params"] : '';
951 + if ($params === '' or !preg_match('/^[A-Za-z0-9_\s,:.\'"#%\-\[\]{}]+$/', $params)) return '';
952 + return $params;
953 +}
285 954
286 -function gvn_schart_shortcode($atts)
955 +// dataset label as a safe JS string literal (labels saved before 3.0.1 may hold HTML entities)
956 +function guaven_sqlcharts_js_label($label){
957 + return wp_json_encode(html_entity_decode((string) $label, ENT_QUOTES, 'UTF-8'));
958 +}
959 +
960 +// Parses an X value for the "time axis" option. Accepts YYYY, YYYY-MM, YYYY-MM-DD, optionally followed
961 +// by HH:MM or HH:MM:SS. Returns a UTC timestamp in milliseconds, or false when the value is not a date.
962 +function guaven_sqlcharts_parse_date($str){
963 + $str = trim((string) $str);
964 + if (!preg_match('/^(\d{4})(?:-(\d{1,2})(?:-(\d{1,2})(?:[ T](\d{1,2}):(\d{2})(?::(\d{2}))?)?)?)?$/', $str, $m)) return false;
965 + $y = (int) $m[1]; $mo = isset($m[2]) ? (int) $m[2] : 1; $d = isset($m[3]) ? (int) $m[3] : 1;
966 + $h = isset($m[4]) ? (int) $m[4] : 0; $mi = isset($m[5]) ? (int) $m[5] : 0; $sec = isset($m[6]) ? (int) $m[6] : 0;
967 + if (!checkdate($mo, $d, $y) or $h > 23 or $mi > 59 or $sec > 59) return false;
968 + return gmmktime($h, $mi, $sec, $mo, $d, $y) * 1000;
969 +}
970 +
971 +// "Scale X axis by date/time" option. Returns, per dataset, a list of "{x:<ms>,y:<value>}" JS point
972 +// literals when the option is on and every X value is a date; false otherwise (normal category axis).
973 +function guaven_sqlcharts_time_axis_points($pid, $values){
974 + if (get_post_meta($pid, 'guaven_sqlcharts_timeaxis', true) != 1) return false;
975 + $out = array();
976 + $has_point = false;
977 + foreach ($values as $key_ak => $series) {
978 + $out[$key_ak] = array();
979 + foreach ($series as $x => $y) {
980 + $ts = guaven_sqlcharts_parse_date($x);
981 + if ($ts === false) return false;
982 + $out[$key_ak][] = '{x:' . $ts . ',y:' . (is_numeric($y) ? $y + 0 : 'null') . '}';
983 + $has_point = true;
984 + }
985 + }
986 + return $has_point ? $out : false;
987 +}
988 +
989 +// X scale options for time-axis mode; gvnSqlChartsTimeTick (asset/front.js) formats the ticks as dates
990 +function guaven_sqlcharts_time_axis_scale(){
991 + return "type: 'linear', offset: true, ticks: {callback: gvnSqlChartsTimeTick, maxRotation: 45},";
992 +}
993 +// extra entry for the Chart.js "plugins" object in time-axis mode (tooltip title shown as a date)
994 +function guaven_sqlcharts_time_axis_plugins($time_points){
995 + return $time_points !== false ? 'tooltip: {callbacks: {title: gvnSqlChartsTimeTooltipTitle}}' : '';
996 +}
997 +
998 +function guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, $type = 'bar', $pid = null)
287 999 {
288 -
289 -
290 - global $wpdb;
291 - $sql = html_entity_decode(get_post_meta($atts['id'], 'guaven_sqlcharts_code', true));
292 -
293 -
294 - $blacklister = array(
295 - "delete",
296 - "update",
297 - "insert",
298 - "drop",
299 - "truncate"
300 - ); //add all
301 - $blacklister_f = 0;
302 - foreach ($blacklister as $key => $value) {
303 - if (strpos($sql, $value) !== false)
304 - $blacklister_f = 1;
1000 + $horizontal = ($type == 'horizontalBar');
1001 + $forcestack = ($type == 'stackedBar');
1002 + $stacked = ($forcestack or get_post_meta($pid, 'guaven_sqlcharts_nostacked', true) != 1) ? 'true' : 'false';
1003 + $time_points = $horizontal ? false : guaven_sqlcharts_time_axis_points($pid, $values);
1004 +?>
1005 + var data = {
1006 + <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?>
1007 + datasets: [
1008 + <?php
1009 + $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
1010 + $i=-1;
1011 + foreach ($values_new as $key_ak=>$value_ak) {
1012 + $i++;
1013 + $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak];
1014 +?>
1015 + {
1016 + <?php
1017 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1018 + ?>
1019 + label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>,
1020 + backgroundColor: [
1021 + <?php
1022 + echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0, guaven_sqlcharts_colors($i, $pid)),[]);
1023 +?>
1024 + ],
1025 + borderColor: [
1026 + <?php
1027 + echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0.2, guaven_sqlcharts_colors($i, $pid)),[]);
1028 +?>
1029 + ],
1030 + borderWidth: 1,
1031 + <?php if ($time_points !== false) echo 'maxBarThickness: 48,'; ?>
1032 + data: [<?php
1033 + echo wp_kses(implode(",", $points),[]);
1034 +?>],
1035 + },
1036 + <?php
305 1037 }
306 -
307 - if ($blacklister_f == 1)
308 - return 'You given SQL code contains forbidden commands. Remember that you should only use SELECT queries';
309 -
310 - $fvs = $wpdb->get_results($sql);
311 -
312 - $wpdb->show_errors();
313 - ob_start();
314 - $wpdb->print_error();
315 - $printerror = ob_get_clean();
316 -
317 - if ($printerror != '' and strpos($printerror, "[]") === false)
318 - return $printerror;
319 - elseif (empty($fvs))
320 - return 'Your SQL returnes empty date, please recheck your SQL query above';
321 - else {
322 - ob_start();
323 1038 ?>
324 -<script type="text/javascript" src="https://www.gstatic.com/charts/loader.js"></script>
325 -
326 - <script type="text/javascript">;
327 - google.charts.load('current', {'packages':[<?php
328 - $tip_g = get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true);
329 -
330 - echo gvn_schart_libloads($tip_g, 'packages');
331 -?>]});
332 - google.charts.setOnLoadCallback(drawChart);
333 - function drawChart() {
1039 + ]
1040 +};
1041 +var options={
1042 + responsive: true,
1043 + <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1044 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1045 + <?php if ($horizontal) echo "indexAxis: 'y',"; ?>
1046 + scales: {
1047 + x: {
1048 + <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?>
1049 + <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'y' : 'x'); ?>
1050 + stacked: <?php echo esc_js($stacked); ?>,
1051 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1052 + },
1053 + y: {
1054 + <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'x' : 'y'); ?>
1055 + stacked: <?php echo esc_js($stacked); ?>,
1056 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
1057 + ticks: {
1058 + <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
1059 + }
1060 + }
1061 + }
334 1062 <?php
335 - $html_temp = '';
336 -
337 - $post_g = get_post($atts['id']);
338 - $xarg_s = get_post_meta($atts['id'], 'guaven_sqlcharts_xarg_s', true);
339 - $xarg_l = get_post_meta($atts['id'], 'guaven_sqlcharts_xarg_l', true);
340 - $yarg_s = get_post_meta($atts['id'], 'guaven_sqlcharts_yarg_s', true);
341 - $yarg_l = get_post_meta($atts['id'], 'guaven_sqlcharts_yarg_l', true);
342 -
343 - $graph_width = get_post_meta($atts['id'], 'guaven_sqlcharts_chartwidth', true);
344 - $graph_height = get_post_meta($atts['id'], 'guaven_sqlcharts_chartheight', true);
345 -
346 - if (!empty($atts["width"])) {
347 - $graph_width = intval($atts['width']);
1063 + guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points));
1064 + ?>
1065 +};
1066 +var myBarChart = new Chart(ctx, {
1067 + type: 'bar',
1068 + data: data,
1069 + options: options
1070 +});
1071 + <?php
1072 +}
1073 +
1074 +function guaven_sqlcharts_merge_labeldata($labels){
1075 + if(count($labels)==1){echo wp_kses(implode(",",$labels[0]),[]);return;}
1076 + $merged=[];
1077 + foreach($labels as $label){
1078 + $merged=array_merge($merged,$label);
1079 + }
1080 + echo wp_kses(implode(",",array_unique($merged)),[]);
1081 +}
1082 +
1083 +function guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, $type = 'false', $pid = null, $charttype = 'line', $stepped = false)
1084 +{
1085 + $time_points = ($charttype == 'radar') ? false : guaven_sqlcharts_time_axis_points($pid, $values);
1086 +?>
1087 +var data = {
1088 + <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?>
1089 + datasets: [
1090 + <?php
1091 + $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
1092 + $dataset_count=count($values_new);
1093 + $i=-1;
1094 + foreach ($values_new as $key_ak=>$value_ak) {
1095 + $i++;
1096 + $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak];
1097 + if ($type == 'radarfill') $fill = "'origin'";
1098 + elseif ($type == 'false') $fill = 'false';
1099 + else $fill = ($i == 0 and $dataset_count > 1) ? '"+1"' : '"origin"';
1100 +?>
1101 + {
1102 + <?php
1103 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1104 + ?>
1105 + label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>,
1106 + fill: <?php echo wp_kses($fill,[]);
1107 +?>,
1108 + tension: 0.1,
1109 + <?php if ($stepped) echo 'stepped: true,'; ?>
1110 + backgroundColor: <?php
1111 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1112 +?>
1113 + borderColor: <?php
1114 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1115 +?>
1116 + pointBorderColor: <?php
1117 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1118 +?>
1119 + pointHoverBackgroundColor: <?php
1120 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1121 +?>
1122 + pointHoverBorderColor: <?php
1123 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1124 +?>
1125 + data: [<?php
1126 + echo wp_kses_post(implode(",", $points));
1127 +?>],
1128 + spanGaps: false,
1129 + },
1130 + <?php
1131 + }
1132 +?>
1133 + ]
1134 +};
1135 +var myLineChart = new Chart(ctx, {
1136 + type: '<?php echo esc_attr($charttype); ?>',
1137 + data: data,
1138 + options: {
1139 + responsive: true,
1140 + <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1141 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1142 + <?php if ($charttype == 'radar') { ?>
1143 + scales: {
1144 + r: {
1145 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>
1146 + }
348 1147 }
349 - if (!empty($atts["height"])) {
350 - $graph_height = intval($atts['height']);
1148 + <?php } else { ?>
1149 + scales: {
1150 + x: {
1151 + display: true,
1152 + <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?>
1153 + <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?>
1154 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1155 + },
1156 + y: {
1157 + <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?>
1158 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
1159 + ticks: {
1160 + <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
1161 + }
1162 + }
351 1163 }
352 -
353 - foreach ($fvs as $fv) {
354 - $html_temp .= "['{$fv->$yarg_s}', {$fv->$xarg_s}, '#b87333'],";
355 -
1164 + <?php } ?>
1165 + <?php
1166 + guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points));
1167 + ?>
1168 +
1169 + }
1170 +});
1171 + <?php
1172 +}
1173 +
1174 +function guaven_sqlcharts_scatterdata($title, $labels, $values, $ylabel, $pid = null)
1175 +{
1176 +?>
1177 +var data = {
1178 + datasets: [
1179 + <?php
1180 + $i=-1;
1181 + foreach ($values as $key_ak=>$value_ak) {
1182 + $i++;
1183 + $points=array();
1184 + foreach ($value_ak as $xval=>$yval) {
1185 + $x = is_numeric($xval) ? $xval : '"'.esc_js($xval).'"';
1186 + $y = is_numeric($yval) ? $yval : '"'.esc_js($yval).'"';
1187 + $points[] = '{x:'.$x.',y:'.$y.'}';
356 1188 }
357 -
358 1189 ?>
359 - var data = google.visualization.arrayToDataTable([
360 - ['<?php
361 - echo $yarg_l;
362 -?>', '<?php
363 - echo $xarg_l;
364 -?>', { role: 'style' }],
1190 + {
1191 + <?php
1192 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1193 + ?>
1194 + label: <?php echo guaven_sqlcharts_js_label(isset($ylabel[$key_ak])?$ylabel[$key_ak]:''); ?>,
1195 + backgroundColor: <?php
1196 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1197 +?>
1198 + borderColor: <?php
1199 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1200 +?>
1201 + data: [<?php echo wp_kses(implode(",", $points),[]); ?>],
1202 + },
365 1203 <?php
366 - echo $html_temp;
1204 + }
367 1205 ?>
368 - ]);
1206 + ]
1207 +};
1208 +var myScatterChart = new Chart(ctx, {
1209 + type: 'scatter',
1210 + data: data,
1211 + options: {
1212 + responsive: true,
1213 + <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1214 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1215 + scales: {
1216 + x: {
1217 + <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?>
1218 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1219 + },
1220 + y: {
1221 + <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?>
1222 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
1223 + ticks: {
1224 + <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
1225 + }
1226 + }
1227 + }
1228 + <?php
1229 + guaven_sqlcharts_maybe_additional_parameters($pid);
1230 + ?>
1231 + }
1232 +});
1233 + <?php
1234 +}
369 1235
370 - var options = {
371 - <?php
372 - echo $tip_g == '3dpie' ? "is3D: true," : '';
373 -?>
374 - chart: {
375 - title: '<?php
376 - echo $post_g->post_title;
377 -?>',
378 - }
379 - };
380 1236
381 -var chart = new google.visualization.<?php
382 - echo gvn_schart_libloads(get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true), 'charts');
383 -?>(document.getElementById('columnchart_material'));
384 - chart.draw(data, options);
385 - }
1237 +function guaven_sqlcharts_maybe_additional_parameters($pid, $extra_plugins = ''){
1238 + if(function_exists('guaven_sqlcharts_maybe_additional_parameters_custom')){
1239 + wp_kses(guaven_sqlcharts_maybe_additional_parameters_custom($pid),[]);
1240 + return;
1241 + }
1242 + $guaven_sqlcharts_legend_position=get_post_meta($pid, 'guaven_sqlcharts_legend_position', true);
1243 + if(in_array($guaven_sqlcharts_legend_position,['top','bottom','left','right'])){
1244 + $display='true';$position=$guaven_sqlcharts_legend_position;
1245 + }
1246 + else {
1247 + $display='false';$position='top';
1248 + }
1249 + echo wp_kses( ",plugins: {legend: {display: ".$display.",position:'".$position."'}".($extra_plugins !== '' ? ','.$extra_plugins : '')."}",[]);
1250 +}
386 1251
387 - </script>
388 1252
389 -<div id="columnchart_material" style="width:<?php
390 - echo $graph_width > 0 ? intval($graph_width) : '500';
391 -?>px;
392 -height: <?php
393 - echo $graph_height > 0 ? intval($graph_height) : '400';
394 -?>px"></div>
1253 +
1254 +
1255 +function guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, $type = 'pie')
1256 +{
1257 +?>
1258 + var options={
1259 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1260 + responsive: true
1261 + <?php echo get_post_meta($pid,'guaven_sqlcharts_chartheight',true)!=''||!empty($GLOBALS["guaven_sqlcharts_atts"]['height'])?',maintainAspectRatio: false':''; ?>
1262 + <?php
1263 + guaven_sqlcharts_maybe_additional_parameters($pid);
1264 + ?>
1265 + };
1266 + var data = {
1267 + labels: [ <?php guaven_sqlcharts_merge_labeldata($labels);?>],
1268 + datasets: [
1269 + <?php
1270 + for ($i = 0; $i < count($values); $i++) {
1271 +?>
1272 + {
1273 + <?php
1274 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1275 + ?>
1276 + data: [<?php
1277 + echo wp_kses(implode(",", $values[$i]),[]);
1278 +?>],
1279 + backgroundColor: [
1280 + <?php
1281 + $ii=0;
1282 + foreach($values[$i] as $vci=>$valuecolor){
1283 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 0, -0.1, guaven_sqlcharts_colors($ii, $pid)));
1284 + $ii++;
1285 + }
1286 +?>
1287 + ],
1288 + hoverBackgroundColor: [
1289 + <?php
1290 + $ii=0;
1291 + foreach($values[$i] as $vci=>$valuecolor){
1292 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 0, 0.2, guaven_sqlcharts_colors($ii, $pid)));
1293 + $ii++;
1294 + }
1295 +?>
1296 + ]
1297 + },
395 1298 <?php
396 - return ob_get_clean();
397 1299 }
1300 +?>
1301 + ]
1302 +};
1303 +var myPieChart = new Chart(ctx,{
1304 + type: '<?php
1305 + echo esc_attr($type);
1306 +?>',
1307 + data: data,
1308 + options: options
1309 +});
1310 + <?php
398 1311 }
399 -add_shortcode('gvn_schart', 'gvn_schart_shortcode');
400 1312
401 1313
402 1314
403 1315
404 -function gvn_schart_wp_tags()
1316 +function guaven_sqlcharts_colorgenerator($count, $indic, $darkness = 0, $initcolor = '255,0,0')
405 1317 {
406 - $tags = get_tags(array(
407 - "order" => "DESC",
408 - "orderby" => "count",
409 - "number" => 10
410 - ));
411 - $html = '';
412 - $itag = 0;
413 - $html60 = '';
414 - foreach ($tags as $tag) {
415 - $itag++;
416 - $html_temp .= "['{$tag->name}', {$tag->count}, '#b87333'],";
1318 + if (strpos($initcolor,'#')===0) {
1319 + $split = str_split(substr($initcolor,1), 2);
1320 + $r = hexdec($split[0]);
1321 + $g = hexdec($split[1]);
1322 + $b = hexdec($split[2]);
1323 + $ret='';
1324 + for ($i = 0; $i < $count; $i++) {
1325 + $ret .= "'rgba(" . $r . ", " . $g . ", " . $b . ",".($darkness + 0.8 - $indic * $i * 0.8 / ($count)).")',
1326 + ";
1327 + }
1328 + return $ret;
1329 + }
1330 + $initial_colors = array(
1331 + 'linebg' => 'red',
1332 + 'linebr' => 'yellow',
1333 + 'linebc' => 'green',
1334 + 'linehbg' => 'white',
1335 + 'linehbc' => 'black'
1336 + );
1337 + if (!empty($initial_colors[$count]))
1338 + return '"' . $initial_colors[$count] . '",
1339 + ';
1340 + $ret = '';
1341 + for ($i = 0; $i < $count; $i++) {
1342 + $ret .= "'rgba(" . $initcolor . "," . ($darkness + 0.8 - $indic * $i * 0.8 / ($count)) . ")',
1343 + ";
417 1344 }
418 -?>
419 - var data = google.visualization.arrayToDataTable([
420 - ['Element', 'Density', { role: 'style' }],
421 - <?php
422 - echo $html_temp;
423 -?>
424 - ]);
1345 + return $ret;
1346 +}
425 1347
426 - var options = {
427 - chart: {
428 - title: 'Company Performance',
429 - subtitle: 'Sales, Expenses, and Profit: 2014-2017',
430 - }
431 - };
432 -<?php
433 - return $html_temp;
1348 +function guaven_sqlcharts_tablepart($title, $labels, $values, $ylabel,$xlabel){
1349 + $tabledata='';
1350 + $fcol=[];$scol=[];
1351 + $empty_cell=apply_filters( 'guaven_sqlcharts_table_empty_cell','<td></td>');
1352 + $tablein='';
1353 + foreach($values as $row=>$valuerow){
1354 + foreach ($valuerow as $key => $value) {
1355 + $putval=$labels[$row][$key]??'';
1356 + $fcol[$key]='<td>'.str_replace('"',"",$putval).'</td>';
1357 + $scol[$key][$row]='<td>'.$value.'</td>';
1358 + }
1359 + foreach($scol as $scolkey=>$scolvalue){
1360 + for($i=0;$i<count($values);$i++){
1361 + //echo $i;
1362 + if(!isset($scolvalue[$i]))$scol[$scolkey][$i]=$empty_cell;;
1363 + }
1364 + ksort($scol[$scolkey]);
1365 + }
1366 + }
1367 +
1368 + foreach($fcol as $key=>$value){
1369 + $tablein.='<tr>'.$value.implode(" ",$scol[$key]).'</tr>'.PHP_EOL;
1370 + }
1371 + $tabledata.='<div class="gvn-tablewrap"><table class="gvn-table"><tr><th>'.$xlabel[0].'</th><th>'.implode("</th><th>",$ylabel).'</th></tr>
1372 + '.$tablein.'</table></div><br>';
1373 +
1374 + echo wp_kses_post($tabledata);
1375 +
434 1376 }
435 1377
1378 +function guaven_sqlcharts_graphtype($post){
1379 + if (strpos(get_post_meta($post->ID, 'guaven_sqlcharts_graphtype', true), "_l") !== false)
1380 + $postfix = '_2';
1381 + else $postfix = '';
1382 + return $postfix;
1383 +}
436 1384
437 -function guaven_sqlcharts_install_first_data()
438 -{
439 -
440 - require_once(dirname(__FILE__) . "/initial_data.php");
441 - gvn_chart_sample_nonxml_data();
1385 +add_filter('the_content',function($content){
1386 + if(!is_singular('gvn_schart'))return $content;
1387 + global $post;
1388 + $postfix=guaven_sqlcharts_graphtype($post);
1389 + return '[gvn_schart'.$postfix.' id="'.$post->ID.'"'.
1390 + (get_post_meta($post->ID,'guaven_sqlcharts_tablepart',true)!=''?' table="1"':'')
1391 + .']';
1392 +});
1393 +
1394 +function guaven_sqlcharts_key_normalizer($values,$labels,$ylabel){
1395 + $normalize_keys=[];
1396 + $empty_value=apply_filters( 'guaven_sqlcharts_table_empty_value','');
1397 + foreach ($values as $key_ak=>$value_ak) {
1398 + $normalize_keys=array_merge($normalize_keys,array_keys($values[$key_ak]));
1399 + }
1400 + $values_normalized=[];$labels_normalized=[];$ylabel_normalized=[];
1401 + foreach($normalize_keys as $normalized_key){
1402 + foreach ($values as $key_ak=>$value_ak) {
1403 + $values_normalized[$key_ak][$normalized_key]=isset( $values[$key_ak][$normalized_key])? $values[$key_ak][$normalized_key]:"'".$empty_value."'";
1404 + $labels_normalized[$key_ak][$normalized_key]=isset( $labels[$key_ak][$normalized_key])? $labels[$key_ak][$normalized_key]:"''";
1405 + $ylabel_normalized[$key_ak][$normalized_key]=isset( $ylabel[$key_ak][$normalized_key])? $ylabel[$key_ak][$normalized_key]:"";
1406 + }
1407 + }
1408 + return [$values_normalized,$labels_normalized,$ylabel_normalized];
442 1409 }
1410 +
1411 +
1412 +add_filter('guaven_sqlcharts_table_empty_cell',function($str){return '<td>#</td>';});
1413 +add_filter('guaven_sqlcharts_table_empty_value',function($str){return 'N/A';});