| @@ -110,8 +110,9 @@ | ||
| 110 | 110 | add_action('admin_notices', 'guaven_sqlcharts_onboarding_notice'); |
| 111 | 111 | |
| 112 | 112 | function guaven_sqlcharts_onboarding_notice_dismissed(){ |
| 113 | 113 | check_ajax_referer('notice_dismissed', 'nonce'); |
| 114 | + if (!current_user_can('manage_options')) return; | |
| 114 | 115 | |
| 115 | 116 | if(empty($_POST['type']))return; |
| 116 | 117 | switch ($_POST['type']){ |
| 117 | 118 | case 'onboarding_notice': |
| @@ -224,9 +225,31 @@ | ||
| 224 | 225 | 'item_updated' => __('Chart updated.','guaven_sqlcharts'), |
| 225 | 226 | ), |
| 226 | 227 | |
| 227 | 228 | 'public' => true, |
| 229 | + 'show_in_rest' => false, | |
| 228 | 230 | 'menu_icon' => 'dashicons-chart-pie', |
| 231 | + // Charts execute SQL, so every primitive capability of this post type maps to manage_options. | |
| 232 | + // Contributors/Authors cannot create, edit, publish or delete charts through any WordPress | |
| 233 | + // entry point (admin UI, XML-RPC, REST). Published charts stay viewable on the front end. | |
| 234 | + // Only primitive capabilities are remapped: mapping the meta capabilities edit_post/read_post/ | |
| 235 | + // delete_post to manage_options would make WordPress treat manage_options itself as a meta | |
| 236 | + // capability and break that check site-wide. | |
| 237 | + 'capability_type' => 'post', | |
| 238 | + 'map_meta_cap' => true, | |
| 239 | + 'capabilities' => array( | |
| 240 | + 'edit_posts' => 'manage_options', | |
| 241 | + 'edit_others_posts' => 'manage_options', | |
| 242 | + 'edit_published_posts' => 'manage_options', | |
| 243 | + 'edit_private_posts' => 'manage_options', | |
| 244 | + 'publish_posts' => 'manage_options', | |
| 245 | + 'read_private_posts' => 'manage_options', | |
| 246 | + 'delete_posts' => 'manage_options', | |
| 247 | + 'delete_private_posts' => 'manage_options', | |
| 248 | + 'delete_published_posts' => 'manage_options', | |
| 249 | + 'delete_others_posts' => 'manage_options', | |
| 250 | + 'create_posts' => 'manage_options', | |
| 251 | + ), | |
| 229 | 252 | 'supports' => array( |
| 230 | 253 | 'title', |
| 231 | 254 | 'postmeta' |
| 232 | 255 | ), |
| @@ -235,8 +258,14 @@ | ||
| 235 | 258 | |
| 236 | 259 | guaven_sqlcharts_load_defaults(); |
| 237 | 260 | } |
| 238 | 261 | |
| 262 | +// All guaven_sqlcharts_* meta keys are protected: they cannot be written through the Custom Fields box, | |
| 263 | +// XML-RPC or the REST API. The plugin's own save handler (update_post_meta) is not affected. | |
| 264 | +add_filter('is_protected_meta', function ($protected, $meta_key) { | |
| 265 | + return strpos((string) $meta_key, 'guaven_sqlcharts_') === 0 ? true : $protected; | |
| 266 | +}, 10, 2); | |
| 267 | + | |
| 239 | 268 | // "Add title" placeholder on the chart edit screen |
| 240 | 269 | add_filter('enter_title_here', function ($title, $post) { |
| 241 | 270 | if (!empty($post) and $post->post_type == 'gvn_schart') return __('Chart name', 'guaven_sqlcharts'); |
| 242 | 271 | return $title; |
| @@ -423,8 +452,11 @@ | ||
| 423 | 452 | { |
| 424 | 453 | if (!isset($_POST['meta_box_nonce_field']) or !wp_verify_nonce($_POST['meta_box_nonce_field'], 'meta_box_nonce_action')) { |
| 425 | 454 | return $post->ID; |
| 426 | 455 | } |
| 456 | + if ($post->post_type != 'gvn_schart' or !current_user_can('manage_options') or (defined('DOING_AUTOSAVE') and DOING_AUTOSAVE)) { | |
| 457 | + return $post->ID; | |
| 458 | + } | |
| 427 | 459 | $fields = array( |
| 428 | 460 | "guaven_sqlcharts_chartheight", |
| 429 | 461 | "guaven_sqlcharts_chartwidth", |
| 430 | 462 | "guaven_sqlcharts_graphtype", |
| @@ -444,9 +476,10 @@ | ||
| 444 | 476 | "guaven_sqlcharts_begin_with_0_y", |
| 445 | 477 | "guaven_sqlcharts_round_y_values", |
| 446 | 478 | "guaven_sqlcharts_legend_position", |
| 447 | 479 | "guaven_sqlcharts_nostacked", |
| 448 | - "guaven_sqlcharts_forcetooltips" | |
| 480 | + "guaven_sqlcharts_forcetooltips", | |
| 481 | + "guaven_sqlcharts_timeaxis" | |
| 449 | 482 | ); |
| 450 | 483 | foreach ($fields as $key => $value) { |
| 451 | 484 | if(isset($_POST[$value]))$newval=esc_attr($_POST[$value]); |
| 452 | 485 | else $newval=''; |
| @@ -479,13 +512,57 @@ | ||
| 479 | 512 | // save the custom fields |
| 480 | 513 | |
| 481 | 514 | |
| 482 | 515 | |
| 516 | +// Removes string literals (contents only), backtick identifiers and comments from SQL so keyword checks | |
| 517 | +// see the same code MySQL will execute. "/*!" and "/*+" comments are executable in MySQL and are kept. | |
| 518 | +function guaven_sqlcharts_strip_sql_literals($sql) | |
| 519 | +{ | |
| 520 | + $out = ''; $len = strlen($sql); $i = 0; | |
| 521 | + while ($i < $len) { | |
| 522 | + $c = $sql[$i]; | |
| 523 | + if ($c === "'" or $c === '"' or $c === '`') { | |
| 524 | + $out .= $c . $c; $i++; | |
| 525 | + while ($i < $len) { | |
| 526 | + if ($sql[$i] === '\\' and $c !== '`') { $i += 2; continue; } | |
| 527 | + if ($sql[$i] === $c) { if ($i + 1 < $len and $sql[$i + 1] === $c) { $i += 2; continue; } $i++; break; } | |
| 528 | + $i++; | |
| 529 | + } | |
| 530 | + continue; | |
| 531 | + } | |
| 532 | + if ($c === '#' or ($c === '-' and substr($sql, $i, 2) === '--' and ($i + 2 >= $len or ctype_space($sql[$i + 2])))) { | |
| 533 | + $nl = strpos($sql, "\n", $i); $i = ($nl === false) ? $len : $nl; continue; | |
| 534 | + } | |
| 535 | + if ($c === '/' and substr($sql, $i, 2) === '/*' and !in_array(substr($sql, $i + 2, 1), array('!', '+'), true)) { | |
| 536 | + $close = strpos($sql, '*/', $i + 2); $i = ($close === false) ? $len : $close + 2; $out .= ' '; continue; | |
| 537 | + } | |
| 538 | + $out .= $c; $i++; | |
| 539 | + } | |
| 540 | + return $out; | |
| 541 | +} | |
| 542 | + | |
| 543 | +// Returns 1 when the (fully substituted) SQL must not run, 0 when it is a read-only query. | |
| 544 | +// Called after every {tag}/{argN} replacement so user-supplied values are covered too. | |
| 483 | 545 | function gvn_chart_check_sql_query($sql) |
| 484 | 546 | { |
| 485 | - // case-insensitive, word-boundary check: only read-only SELECT queries are allowed | |
| 486 | - $pattern = '/\b(delete|update|insert|replace|drop|truncate|alter|create|rename|grant|revoke|call|handler|load\s+data|load_file|outfile|dumpfile)\b/i'; | |
| 487 | - return preg_match($pattern, $sql) ? 1 : 0; | |
| 547 | + // 1) data-changing statements: checked on the raw text, exactly as in every previous version | |
| 548 | + $write = '/\b(delete|update|insert|replace|drop|truncate|alter|create|rename|grant|revoke|call|handler|load\s+data|load_file|outfile|dumpfile)\b/i'; | |
| 549 | + if (preg_match($write, $sql)) return 1; | |
| 550 | + | |
| 551 | + // 2) further dangerous statements, matched outside string literals and comments so that ordinary | |
| 552 | + // values such as status = 'reset' keep working | |
| 553 | + $danger = '/\b(prepare|execute|deallocate|lock|unlock|kill|shutdown|flush|reset|purge|install|uninstall|import' | |
| 554 | + . '|set\s+(?:global|session|persist|persist_only|password|@@)|start\s+(?:replica|slave|group_replication)|stop\s+(?:replica|slave)|change\s+(?:master|replication))\b/i'; | |
| 555 | + if (preg_match($danger, guaven_sqlcharts_strip_sql_literals($sql))) return 1; | |
| 556 | + | |
| 557 | + // 3) every ";"-separated statement must be a read statement. The renderer sends each segment to the | |
| 558 | + // database on its own, so this stops a value from smuggling a second statement behind a ";". | |
| 559 | + foreach (explode(';', $sql) as $segment) { | |
| 560 | + $segment = ltrim(guaven_sqlcharts_strip_sql_literals($segment), " \t\r\n("); | |
| 561 | + if ($segment === '') continue; | |
| 562 | + if (!preg_match('/^(select|with|show|describe|desc|explain)\b/i', $segment)) return 1; | |
| 563 | + } | |
| 564 | + return 0; | |
| 488 | 565 | } |
| 489 | 566 | |
| 490 | 567 | function guaven_get_labels_and_values($id, $fvs) |
| 491 | 568 | { |
| @@ -491,11 +568,13 @@ | ||
| 491 | 568 | { |
| 492 | 569 | $values = array(); |
| 493 | 570 | $labels = array(); |
| 494 | 571 | $xarg_s = get_post_meta($id, 'guaven_sqlcharts_xarg_s', true); |
| 495 | - $xarg_l = get_post_meta($id, 'guaven_sqlcharts_xarg_l', true); | |
| 496 | 572 | $yarg_s = get_post_meta($id, 'guaven_sqlcharts_yarg_s', true); |
| 497 | - $yarg_l = get_post_meta($id, 'guaven_sqlcharts_yarg_l', true); | |
| 573 | + // labels are saved through esc_attr, so "&" is stored as "&"; decode before splitting on ";" | |
| 574 | + // or the entity's own ";" would be taken as a series separator | |
| 575 | + $xarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_xarg_l', true), ENT_QUOTES, 'UTF-8'); | |
| 576 | + $yarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_yarg_l', true), ENT_QUOTES, 'UTF-8'); | |
| 498 | 577 | foreach ($fvs as $key => $value) { |
| 499 | 578 | $values[$value->$xarg_s] = $value->$yarg_s; |
| 500 | 579 | $labels[$value->$xarg_s] = '"' . $value->$xarg_s . '"'; |
| 501 | 580 | } |
| @@ -577,9 +656,9 @@ | ||
| 577 | 656 | if (count($varfield_arr)<3) continue; |
| 578 | 657 | $varfield_arr=array_map("trim",$varfield_arr); |
| 579 | 658 | if (!empty($_GET[$varfield_arr[0]])) { |
| 580 | 659 | // User-supplied input: no () bypass allowed — sanitize strictly |
| 581 | - $varreplacement = sanitize_text_field(wp_unslash($_GET[$varfield_arr[0]])); | |
| 660 | + $varreplacement = str_replace(';', '', sanitize_text_field(wp_unslash($_GET[$varfield_arr[0]]))); | |
| 582 | 661 | if (is_numeric($varreplacement)) { |
| 583 | 662 | $varreplacement = $varreplacement + 0; |
| 584 | 663 | } else { |
| 585 | 664 | $varreplacement = '"' . esc_sql($varreplacement) . '"'; |
| @@ -673,8 +752,10 @@ | ||
| 673 | 752 | |
| 674 | 753 | function guaven_sqlcharts_local_shortcode($atts) { |
| 675 | 754 | if(empty($atts['id']))return 'ID is missing.'; |
| 676 | 755 | $atts['id']=intval($atts['id']); |
| 756 | + $post_g = get_post($atts['id']); | |
| 757 | + if (!$post_g or $post_g->post_type != 'gvn_schart') return 'Chart not found.'; | |
| 677 | 758 | $remote_host=get_post_meta($atts['id'], 'guaven_sqlcharts_dbhost', true); |
| 678 | 759 | if ($remote_host!=''){ |
| 679 | 760 | $remote_db=get_post_meta($atts['id'], 'guaven_sqlcharts_dbname', true); |
| 680 | 761 | $remote_login=get_post_meta($atts['id'], 'guaven_sqlcharts_dblogin', true); |
| @@ -691,29 +772,34 @@ | ||
| 691 | 772 | $GLOBALS["guaven_sqlcharts_atts"]=$atts; |
| 692 | 773 | |
| 693 | 774 | $sql = guaven_sqlcharts_get_code($atts['id']); |
| 694 | 775 | if(empty($sql))return 'SQL query is missing.'; |
| 695 | - $sql=gvn_chart_put_variables($sql,$atts['id']); | |
| 696 | 776 | |
| 777 | + // {arg1}..{arg19} come from shortcode attributes: [gvn_schart_2 id="1" arg1="41"]. | |
| 778 | + // Substituted directly (not via wpdb::prepare) so the same tag may appear any number of times, | |
| 779 | + // e.g. in every query of a ";"-separated comparison chart. Numbers are inserted as-is, anything | |
| 780 | + // else is escaped and quoted; a tag already wrapped in quotes ('{arg1}') is not double-quoted. | |
| 781 | + // ";" is removed from values because the finished SQL is split on ";" below. | |
| 782 | + for($i=1;$i<20;$i++){ | |
| 783 | + $tag = '{arg'.$i.'}'; | |
| 784 | + if (strpos($sql, $tag) === false) continue; | |
| 785 | + $replacearg = !empty($atts['arg'.$i]) ? $atts['arg'.$i] : 0; | |
| 786 | + if (is_numeric($replacearg)) $replacearg = $replacearg + 0; | |
| 787 | + else $replacearg = "'" . esc_sql(str_replace(';', '', sanitize_text_field((string) $replacearg))) . "'"; | |
| 788 | + $sql = str_replace(array("'".$tag."'", '"'.$tag.'"', $tag), $replacearg, $sql); | |
| 789 | + } | |
| 697 | 790 | |
| 791 | + $sql=gvn_chart_put_variables($sql,$atts['id']); | |
| 698 | 792 | $sql=apply_filters('guaven_sqlcharts_rendered_sql',$sql,$atts); |
| 699 | 793 | |
| 794 | + // command check on the final SQL, after every shortcode argument and filter value is in place | |
| 700 | 795 | $blacklister_f = gvn_chart_check_sql_query($sql); |
| 701 | 796 | if ($blacklister_f == 1)return 'You given SQL code contains forbidden commands. Remember that you should only use SELECT queries'; |
| 702 | 797 | $tip_g = guaven_sqlcharts_normalize_type(get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true)); |
| 703 | 798 | |
| 704 | - for($i=1;$i<20;$i++){ | |
| 705 | - if(strpos($sql,"{arg".$i."}")!==false){ | |
| 706 | - $replacearg=!empty($atts["arg".$i])?$atts["arg".$i]:0; | |
| 707 | - $sql = str_replace("{arg".$i."}", "%s", $sql); | |
| 708 | - $sql=$wpdb->prepare($sql,$replacearg); | |
| 709 | - } | |
| 710 | - | |
| 711 | - } | |
| 712 | - | |
| 713 | 799 | $sql_split = explode(';', $sql); |
| 714 | 800 | $labels_and_values = array(); |
| 715 | - $post_g = get_post($atts['id']); | |
| 801 | + $labels = $values = $ylabel = $xlabel = array(); | |
| 716 | 802 | |
| 717 | 803 | global $sqlcharts_inserted_script; |
| 718 | 804 | ob_start(); |
| 719 | 805 | for ($i = 0; $i < count($sql_split); $i++) { |
| @@ -787,17 +873,30 @@ | ||
| 787 | 873 | if (!shortcode_exists('gvn_schart')) { |
| 788 | 874 | add_shortcode('gvn_schart', 'guaven_sqlcharts_local_shortcode'); |
| 789 | 875 | } |
| 790 | 876 | |
| 877 | +// [gvn_schart_2_cached id="1" expire="3600" arg1=".."] – same as gvn_schart_2 but the output is kept in a | |
| 878 | +// transient. All other attributes (argN, width, height, table, params) are passed through, and each | |
| 879 | +// distinct set of attributes gets its own cache entry. Append ?force_sql_cache_reload to the URL to bypass. | |
| 791 | 880 | add_shortcode("gvn_schart_2_cached",function($atts){ |
| 792 | 881 | if(empty($atts["id"]))return; |
| 793 | 882 | $atts["id"]=intval($atts["id"]); |
| 794 | - $is_logged_in=is_user_logged_in()?'':'_guest'; | |
| 795 | 883 | $expire=!empty($atts["expire"])?intval($atts["expire"]):3600; |
| 796 | - $cached=get_transient('cached_sql_charts_'.$atts["id"].$is_logged_in); | |
| 884 | + $inner_atts=$atts; | |
| 885 | + unset($inner_atts['expire']); | |
| 886 | + // One cache entry per user (charts may use {current_user_*} tags), per set of shortcode attributes | |
| 887 | + // and per value of every dynamic filter this chart reads from the URL. A visitor can therefore | |
| 888 | + // never be served, or pre-seed, a result computed for someone else or for other filter values. | |
| 889 | + $key_parts = array('atts' => $inner_atts, 'user' => is_user_logged_in() ? get_current_user_id() : 0, 'get' => array()); | |
| 890 | + foreach (explode('|', (string) get_post_meta($atts['id'], 'guaven_sqlcharts_variables', true)) as $vrow) { | |
| 891 | + $vname = trim(current(explode('~', $vrow))); | |
| 892 | + if ($vname !== '' and isset($_GET[$vname])) $key_parts['get'][$vname] = sanitize_text_field(wp_unslash($_GET[$vname])); | |
| 893 | + } | |
| 894 | + $key = 'cached_sql_charts_' . $atts["id"] . '_' . md5(serialize($key_parts)); | |
| 895 | + $cached=get_transient($key); | |
| 797 | 896 | if(!empty($cached) and !isset($_GET["force_sql_cache_reload"]) )return $cached; |
| 798 | - $tobecached=do_shortcode('[gvn_schart_2 id="'.$atts["id"].'"]'); | |
| 799 | - set_transient('cached_sql_charts_'.$atts["id"].$is_logged_in, $tobecached,$expire);//you can change 3600 yourself | |
| 897 | + $tobecached=guaven_sqlcharts_local_shortcode($inner_atts); | |
| 898 | + set_transient($key, $tobecached,$expire); | |
| 800 | 899 | return $tobecached; |
| 801 | 900 | }); |
| 802 | 901 | |
| 803 | 902 | // fixed, colorblind-friendly default palette (Tableau 10) used when no custom colors are set |
| @@ -827,16 +926,85 @@ | ||
| 827 | 926 | $h = !empty($atts['height']) ? $atts['height'] : get_post_meta($pid, 'guaven_sqlcharts_chartheight', true); |
| 828 | 927 | return $h != '' ? 'maintainAspectRatio: false,' : ''; |
| 829 | 928 | } |
| 830 | 929 | |
| 930 | +// outputs 'showAllTooltips: true,' when "Value labels" is checked; the values are drawn by the | |
| 931 | +// gvnShowAllValues plugin in asset/front.js (works for every chart type) | |
| 932 | +function guaven_sqlcharts_value_labels($pid){ | |
| 933 | + return get_post_meta($pid, 'guaven_sqlcharts_forcetooltips', true) != '' ? 'showAllTooltips: true,' : ''; | |
| 934 | +} | |
| 935 | + | |
| 936 | +// Chart.js scale title block built from the "X axis label" / "Y axis label" fields. | |
| 937 | +// $which is 'x' or 'y' (the *field* to use, not the scale). The Y label is only used as an axis | |
| 938 | +// title for single-series charts; with several ";"-separated series the legend names them instead. | |
| 939 | +function guaven_sqlcharts_axis_title($pid, $which){ | |
| 940 | + $key = $which == 'x' ? 'guaven_sqlcharts_xarg_l' : 'guaven_sqlcharts_yarg_l'; | |
| 941 | + $text = trim(html_entity_decode((string) get_post_meta($pid, $key, true), ENT_QUOTES, 'UTF-8')); | |
| 942 | + if ($text === '' or ($which == 'y' and strpos($text, ';') !== false)) return ''; | |
| 943 | + return 'title: {display: true, text: ' . wp_json_encode($text) . '},'; | |
| 944 | +} | |
| 945 | + | |
| 946 | +// "params" shortcode attribute: extra Chart.js dataset options, e.g. params="borderWidth: 3, borderDash: [5,5],". | |
| 947 | +// The text is placed inside the inline <script>, so only a conservative character set is accepted: | |
| 948 | +// no parentheses, semicolons, "=", "<", ">", "/", "\\", "+" or backticks, which rules out executable JavaScript. | |
| 949 | +function guaven_sqlcharts_dataset_params(){ | |
| 950 | + $params = isset($GLOBALS["guaven_sqlcharts_atts"]["params"]) ? (string) $GLOBALS["guaven_sqlcharts_atts"]["params"] : ''; | |
| 951 | + if ($params === '' or !preg_match('/^[A-Za-z0-9_\s,:.\'"#%\-\[\]{}]+$/', $params)) return ''; | |
| 952 | + return $params; | |
| 953 | +} | |
| 954 | + | |
| 955 | +// dataset label as a safe JS string literal (labels saved before 3.0.1 may hold HTML entities) | |
| 956 | +function guaven_sqlcharts_js_label($label){ | |
| 957 | + return wp_json_encode(html_entity_decode((string) $label, ENT_QUOTES, 'UTF-8')); | |
| 958 | +} | |
| 959 | + | |
| 960 | +// Parses an X value for the "time axis" option. Accepts YYYY, YYYY-MM, YYYY-MM-DD, optionally followed | |
| 961 | +// by HH:MM or HH:MM:SS. Returns a UTC timestamp in milliseconds, or false when the value is not a date. | |
| 962 | +function guaven_sqlcharts_parse_date($str){ | |
| 963 | + $str = trim((string) $str); | |
| 964 | + if (!preg_match('/^(\d{4})(?:-(\d{1,2})(?:-(\d{1,2})(?:[ T](\d{1,2}):(\d{2})(?::(\d{2}))?)?)?)?$/', $str, $m)) return false; | |
| 965 | + $y = (int) $m[1]; $mo = isset($m[2]) ? (int) $m[2] : 1; $d = isset($m[3]) ? (int) $m[3] : 1; | |
| 966 | + $h = isset($m[4]) ? (int) $m[4] : 0; $mi = isset($m[5]) ? (int) $m[5] : 0; $sec = isset($m[6]) ? (int) $m[6] : 0; | |
| 967 | + if (!checkdate($mo, $d, $y) or $h > 23 or $mi > 59 or $sec > 59) return false; | |
| 968 | + return gmmktime($h, $mi, $sec, $mo, $d, $y) * 1000; | |
| 969 | +} | |
| 970 | + | |
| 971 | +// "Scale X axis by date/time" option. Returns, per dataset, a list of "{x:<ms>,y:<value>}" JS point | |
| 972 | +// literals when the option is on and every X value is a date; false otherwise (normal category axis). | |
| 973 | +function guaven_sqlcharts_time_axis_points($pid, $values){ | |
| 974 | + if (get_post_meta($pid, 'guaven_sqlcharts_timeaxis', true) != 1) return false; | |
| 975 | + $out = array(); | |
| 976 | + $has_point = false; | |
| 977 | + foreach ($values as $key_ak => $series) { | |
| 978 | + $out[$key_ak] = array(); | |
| 979 | + foreach ($series as $x => $y) { | |
| 980 | + $ts = guaven_sqlcharts_parse_date($x); | |
| 981 | + if ($ts === false) return false; | |
| 982 | + $out[$key_ak][] = '{x:' . $ts . ',y:' . (is_numeric($y) ? $y + 0 : 'null') . '}'; | |
| 983 | + $has_point = true; | |
| 984 | + } | |
| 985 | + } | |
| 986 | + return $has_point ? $out : false; | |
| 987 | +} | |
| 988 | + | |
| 989 | +// X scale options for time-axis mode; gvnSqlChartsTimeTick (asset/front.js) formats the ticks as dates | |
| 990 | +function guaven_sqlcharts_time_axis_scale(){ | |
| 991 | + return "type: 'linear', offset: true, ticks: {callback: gvnSqlChartsTimeTick, maxRotation: 45},"; | |
| 992 | +} | |
| 993 | +// extra entry for the Chart.js "plugins" object in time-axis mode (tooltip title shown as a date) | |
| 994 | +function guaven_sqlcharts_time_axis_plugins($time_points){ | |
| 995 | + return $time_points !== false ? 'tooltip: {callbacks: {title: gvnSqlChartsTimeTooltipTitle}}' : ''; | |
| 996 | +} | |
| 997 | + | |
| 831 | 998 | function guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, $type = 'bar', $pid = null) |
| 832 | 999 | { |
| 833 | 1000 | $horizontal = ($type == 'horizontalBar'); |
| 834 | 1001 | $forcestack = ($type == 'stackedBar'); |
| 835 | 1002 | $stacked = ($forcestack or get_post_meta($pid, 'guaven_sqlcharts_nostacked', true) != 1) ? 'true' : 'false'; |
| 1003 | + $time_points = $horizontal ? false : guaven_sqlcharts_time_axis_points($pid, $values); | |
| 836 | 1004 | ?> |
| 837 | 1005 | var data = { |
| 838 | - labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>], | |
| 1006 | + <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?> | |
| 839 | 1007 | datasets: [ |
| 840 | 1008 | <?php |
| 841 | 1009 | $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0]; |
| 842 | 1010 | $i=-1; |
| @@ -841,32 +1009,29 @@ | ||
| 841 | 1009 | $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0]; |
| 842 | 1010 | $i=-1; |
| 843 | 1011 | foreach ($values_new as $key_ak=>$value_ak) { |
| 844 | 1012 | $i++; |
| 1013 | + $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak]; | |
| 845 | 1014 | ?> |
| 846 | 1015 | { |
| 847 | 1016 | <?php |
| 848 | - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){ | |
| 849 | - //passing chartJS params via the shortcode | |
| 850 | - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]); | |
| 851 | - } | |
| 1017 | + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated) | |
| 852 | 1018 | ?> |
| 853 | - label: "<?php | |
| 854 | - echo wp_kses($ylabel[$key_ak],[]); | |
| 855 | -?>", | |
| 1019 | + label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>, | |
| 856 | 1020 | backgroundColor: [ |
| 857 | 1021 | <?php |
| 858 | - echo wp_kses(guaven_sqlcharts_colorgenerator(count($values_new[$key_ak]), 0, 0, guaven_sqlcharts_colors($i, $pid)),[]); | |
| 1022 | + echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0, guaven_sqlcharts_colors($i, $pid)),[]); | |
| 859 | 1023 | ?> |
| 860 | 1024 | ], |
| 861 | 1025 | borderColor: [ |
| 862 | 1026 | <?php |
| 863 | - echo wp_kses(guaven_sqlcharts_colorgenerator(count($values_new[$key_ak]), 0, 0.2, guaven_sqlcharts_colors($i, $pid)),[]); | |
| 1027 | + echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0.2, guaven_sqlcharts_colors($i, $pid)),[]); | |
| 864 | 1028 | ?> |
| 865 | 1029 | ], |
| 866 | 1030 | borderWidth: 1, |
| 1031 | + <?php if ($time_points !== false) echo 'maxBarThickness: 48,'; ?> | |
| 867 | 1032 | data: [<?php |
| 868 | - echo wp_kses(implode(",", $values_new[$key_ak]),[]); | |
| 1033 | + echo wp_kses(implode(",", $points),[]); | |
| 869 | 1034 | ?>], |
| 870 | 1035 | }, |
| 871 | 1036 | <?php |
| 872 | 1037 | } |
| @@ -875,15 +1040,19 @@ | ||
| 875 | 1040 | }; |
| 876 | 1041 | var options={ |
| 877 | 1042 | responsive: true, |
| 878 | 1043 | <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?> |
| 1044 | + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?> | |
| 879 | 1045 | <?php if ($horizontal) echo "indexAxis: 'y',"; ?> |
| 880 | 1046 | scales: { |
| 881 | 1047 | x: { |
| 1048 | + <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?> | |
| 1049 | + <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'y' : 'x'); ?> | |
| 882 | 1050 | stacked: <?php echo esc_js($stacked); ?>, |
| 883 | 1051 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?> |
| 884 | 1052 | }, |
| 885 | 1053 | y: { |
| 1054 | + <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'x' : 'y'); ?> | |
| 886 | 1055 | stacked: <?php echo esc_js($stacked); ?>, |
| 887 | 1056 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>, |
| 888 | 1057 | ticks: { |
| 889 | 1058 | <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?> |
| @@ -890,9 +1059,9 @@ | ||
| 890 | 1059 | } |
| 891 | 1060 | } |
| 892 | 1061 | } |
| 893 | 1062 | <?php |
| 894 | - guaven_sqlcharts_maybe_additional_parameters($pid); | |
| 1063 | + guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points)); | |
| 895 | 1064 | ?> |
| 896 | 1065 | }; |
| 897 | 1066 | var myBarChart = new Chart(ctx, { |
| 898 | 1067 | type: 'bar', |
| @@ -912,11 +1081,12 @@ | ||
| 912 | 1081 | } |
| 913 | 1082 | |
| 914 | 1083 | function guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, $type = 'false', $pid = null, $charttype = 'line', $stepped = false) |
| 915 | 1084 | { |
| 1085 | + $time_points = ($charttype == 'radar') ? false : guaven_sqlcharts_time_axis_points($pid, $values); | |
| 916 | 1086 | ?> |
| 917 | 1087 | var data = { |
| 918 | - labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>], | |
| 1088 | + <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?> | |
| 919 | 1089 | datasets: [ |
| 920 | 1090 | <?php |
| 921 | 1091 | $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0]; |
| 922 | 1092 | $dataset_count=count($values_new); |
| @@ -922,8 +1092,9 @@ | ||
| 922 | 1092 | $dataset_count=count($values_new); |
| 923 | 1093 | $i=-1; |
| 924 | 1094 | foreach ($values_new as $key_ak=>$value_ak) { |
| 925 | 1095 | $i++; |
| 1096 | + $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak]; | |
| 926 | 1097 | if ($type == 'radarfill') $fill = "'origin'"; |
| 927 | 1098 | elseif ($type == 'false') $fill = 'false'; |
| 928 | 1099 | else $fill = ($i == 0 and $dataset_count > 1) ? '"+1"' : '"origin"'; |
| 929 | 1100 | ?> |
| @@ -928,16 +1099,11 @@ | ||
| 928 | 1099 | else $fill = ($i == 0 and $dataset_count > 1) ? '"+1"' : '"origin"'; |
| 929 | 1100 | ?> |
| 930 | 1101 | { |
| 931 | 1102 | <?php |
| 932 | - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){ | |
| 933 | - //passing chartJS params via the shortcode | |
| 934 | - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]); | |
| 935 | - } | |
| 1103 | + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated) | |
| 936 | 1104 | ?> |
| 937 | - label: "<?php | |
| 938 | - echo esc_attr($ylabel[$key_ak]); | |
| 939 | -?>", | |
| 1105 | + label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>, | |
| 940 | 1106 | fill: <?php echo wp_kses($fill,[]); |
| 941 | 1107 | ?>, |
| 942 | 1108 | tension: 0.1, |
| 943 | 1109 | <?php if ($stepped) echo 'stepped: true,'; ?> |
| @@ -956,9 +1122,9 @@ | ||
| 956 | 1122 | pointHoverBorderColor: <?php |
| 957 | 1123 | echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid))); |
| 958 | 1124 | ?> |
| 959 | 1125 | data: [<?php |
| 960 | - echo wp_kses_post(implode(",", $values_new[$key_ak])); | |
| 1126 | + echo wp_kses_post(implode(",", $points)); | |
| 961 | 1127 | ?>], |
| 962 | 1128 | spanGaps: false, |
| 963 | 1129 | }, |
| 964 | 1130 | <?php |
| @@ -971,8 +1137,9 @@ | ||
| 971 | 1137 | data: data, |
| 972 | 1138 | options: { |
| 973 | 1139 | responsive: true, |
| 974 | 1140 | <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?> |
| 1141 | + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?> | |
| 975 | 1142 | <?php if ($charttype == 'radar') { ?> |
| 976 | 1143 | scales: { |
| 977 | 1144 | r: { |
| 978 | 1145 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?> |
| @@ -981,11 +1148,14 @@ | ||
| 981 | 1148 | <?php } else { ?> |
| 982 | 1149 | scales: { |
| 983 | 1150 | x: { |
| 984 | 1151 | display: true, |
| 1152 | + <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?> | |
| 1153 | + <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?> | |
| 985 | 1154 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?> |
| 986 | 1155 | }, |
| 987 | 1156 | y: { |
| 1157 | + <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?> | |
| 988 | 1158 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>, |
| 989 | 1159 | ticks: { |
| 990 | 1160 | <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?> |
| 991 | 1161 | } |
| @@ -992,9 +1162,9 @@ | ||
| 992 | 1162 | } |
| 993 | 1163 | } |
| 994 | 1164 | <?php } ?> |
| 995 | 1165 | <?php |
| 996 | - guaven_sqlcharts_maybe_additional_parameters($pid); | |
| 1166 | + guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points)); | |
| 997 | 1167 | ?> |
| 998 | 1168 | |
| 999 | 1169 | } |
| 1000 | 1170 | }); |
| @@ -1018,14 +1188,11 @@ | ||
| 1018 | 1188 | } |
| 1019 | 1189 | ?> |
| 1020 | 1190 | { |
| 1021 | 1191 | <?php |
| 1022 | - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){ | |
| 1023 | - //passing chartJS params via the shortcode | |
| 1024 | - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]); | |
| 1025 | - } | |
| 1192 | + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated) | |
| 1026 | 1193 | ?> |
| 1027 | - label: "<?php echo esc_attr(isset($ylabel[$key_ak])?$ylabel[$key_ak]:''); ?>", | |
| 1194 | + label: <?php echo guaven_sqlcharts_js_label(isset($ylabel[$key_ak])?$ylabel[$key_ak]:''); ?>, | |
| 1028 | 1195 | backgroundColor: <?php |
| 1029 | 1196 | echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid))); |
| 1030 | 1197 | ?> |
| 1031 | 1198 | borderColor: <?php |
| @@ -1043,13 +1210,16 @@ | ||
| 1043 | 1210 | data: data, |
| 1044 | 1211 | options: { |
| 1045 | 1212 | responsive: true, |
| 1046 | 1213 | <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?> |
| 1214 | + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?> | |
| 1047 | 1215 | scales: { |
| 1048 | 1216 | x: { |
| 1217 | + <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?> | |
| 1049 | 1218 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?> |
| 1050 | 1219 | }, |
| 1051 | 1220 | y: { |
| 1221 | + <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?> | |
| 1052 | 1222 | beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>, |
| 1053 | 1223 | ticks: { |
| 1054 | 1224 | <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?> |
| 1055 | 1225 | } |
| @@ -1063,9 +1233,9 @@ | ||
| 1063 | 1233 | <?php |
| 1064 | 1234 | } |
| 1065 | 1235 | |
| 1066 | 1236 | |
| 1067 | -function guaven_sqlcharts_maybe_additional_parameters($pid){ | |
| 1237 | +function guaven_sqlcharts_maybe_additional_parameters($pid, $extra_plugins = ''){ | |
| 1068 | 1238 | if(function_exists('guaven_sqlcharts_maybe_additional_parameters_custom')){ |
| 1069 | 1239 | wp_kses(guaven_sqlcharts_maybe_additional_parameters_custom($pid),[]); |
| 1070 | 1240 | return; |
| 1071 | 1241 | } |
| @@ -1075,9 +1245,9 @@ | ||
| 1075 | 1245 | } |
| 1076 | 1246 | else { |
| 1077 | 1247 | $display='false';$position='top'; |
| 1078 | 1248 | } |
| 1079 | - echo wp_kses( ",plugins: {legend: {display: ".$display.",position:'".$position."'}}",[]); | |
| 1249 | + echo wp_kses( ",plugins: {legend: {display: ".$display.",position:'".$position."'}".($extra_plugins !== '' ? ','.$extra_plugins : '')."}",[]); | |
| 1080 | 1250 | } |
| 1081 | 1251 | |
| 1082 | 1252 | |
| 1083 | 1253 | |
| @@ -1085,9 +1255,9 @@ | ||
| 1085 | 1255 | function guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, $type = 'pie') |
| 1086 | 1256 | { |
| 1087 | 1257 | ?> |
| 1088 | 1258 | var options={ |
| 1089 | - <?php if(get_post_meta($pid,'guaven_sqlcharts_forcetooltips',true)!='') echo 'showAllTooltips: true,'.PHP_EOL; ?> | |
| 1259 | + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?> | |
| 1090 | 1260 | responsive: true |
| 1091 | 1261 | <?php echo get_post_meta($pid,'guaven_sqlcharts_chartheight',true)!=''||!empty($GLOBALS["guaven_sqlcharts_atts"]['height'])?',maintainAspectRatio: false':''; ?> |
| 1092 | 1262 | <?php |
| 1093 | 1263 | guaven_sqlcharts_maybe_additional_parameters($pid); |
| @@ -1100,12 +1270,9 @@ | ||
| 1100 | 1270 | for ($i = 0; $i < count($values); $i++) { |
| 1101 | 1271 | ?> |
| 1102 | 1272 | { |
| 1103 | 1273 | <?php |
| 1104 | - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){ | |
| 1105 | - //passing chartJS params via the shortcode | |
| 1106 | - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]); | |
| 1107 | - } | |
| 1274 | + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated) | |
| 1108 | 1275 | ?> |
| 1109 | 1276 | data: [<?php |
| 1110 | 1277 | echo wp_kses(implode(",", $values[$i]),[]); |
| 1111 | 1278 | ?>], |