PluginProbe
SQL Chart Builder / 3.0.5
SQL Chart Builder v3.0.5
3.0.5 3.0.4 3.0.3 3.0.2 3.0.1 trunk 1.0.2 1.0.3 2.2.2 2.3.0 2.3.1 2.3.2 2.3.3 2.3.4 2.3.5 2.3.6 2.3.7 2.3.7.1 2.3.7.2 2.3.8 3.0.0
sql-chart-builder / functions.php

functions.php in SQL Chart Builder 3.0.5, at functions.php

1,415 lines 61.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 if (!defined('ABSPATH')) {
3 die;
4 }
5 //postinstall function
6 function guaven_sqlcharts_load_defaults()
7 {
8 if (get_option("guaven_sqlcharts_already_installed_2") === false) {
9 update_option("guaven_sqlcharts_already_installed_2", "1");
10 guaven_sqlcharts_install_first_data();
11
12 }
13 }
14
15 function guaven_sqlcharts_install_first_data()
16 {
17 require_once(dirname(__FILE__) . "/initial_data.php");
18 gvn_chart_sample_nonxml_data();
19 }
20
21
22 function guaven_sqlcharts_recommended(){
23 if(!class_exists('WooCommerce'))return;
24 $uid=(int)get_current_user_id();
25 if(isset($_GET["gvnsql_dismiss_recommendation"])){
26 update_option('gvnsql_dismiss_recommendation_'.$uid,1);
27 return;
28 }
29 if(get_option('gvnsql_dismiss_recommendation_'.$uid)!='')return;
30 return '<table class="gf-alert gf-alert-info" style="margin-top:20px">
31 <tbody><tr><td style="width: auto;vertical-align: top;padding: 20px;">
32 <h2>WooCommerce Search Engine – INSTANT, RELEVANT AND SMART Search Box</h2>
33 <h3>Turn your website search into Smart Search which find products by price, SKU, attributes, meta data, categorys, tags etc. </h3>
34 <p>“WooCommerce Search Engine” is a very powerful and easy to use WooCommerce Search Plugin which turns a simple search box of your WooCommerce Store to the powerful multifunctional magic box which helps you to sell more products. The plugin UI is compatible with ALL THEMES.</p>
35 <a target="_blank" style="border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;" class="button button-secondary"
36 href="https://codecanyon.net/item/woocommerce-search-box/15685698">Get the Search Box </a>
37 </td><td style="position:relative">
38 <a href="'.admin_url().'/edit.php?post_type=gvn_schart&gvnsql_dismiss_recommendation=1'.'" style="position: absolute;right: 0;top: -15px;right: -10px;">{svg}
39 </a>
40 <img src="'.plugin_dir_url( __FILE__ ) . 'asset/img/recommended1.jpg" style="max-width: 430px;"></td></tr>
41 </tbody></table>';
42 }
43
44
45
46 function guaven_sqlcharts_my_admin_notice()
47 {
48 global $post;
49
50
51 if(
52 (!empty($_SERVER["REQUEST_URI"]) and strpos(sanitize_text_field(wp_unslash($_SERVER["REQUEST_URI"])),'post_type=gvn_schart')!==false)
53 or
54 (!empty($post) and $post->post_type == 'gvn_schart')
55 ){
56 echo str_replace('{svg}','<svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="11" height="14" viewBox="0 0 11 14">
57 <path d="M10.141 10.328q0 0.312-0.219 0.531l-1.062 1.062q-0.219 0.219-0.531 0.219t-0.531-0.219l-2.297-2.297-2.297 2.297q-0.219 0.219-0.531 0.219t-0.531-0.219l-1.062-1.062q-0.219-0.219-0.219-0.531t0.219-0.531l2.297-2.297-2.297-2.297q-0.219-0.219-0.219-0.531t0.219-0.531l1.062-1.062q0.219-0.219 0.531-0.219t0.531 0.219l2.297 2.297 2.297-2.297q0.219-0.219 0.531-0.219t0.531 0.219l1.062 1.062q0.219 0.219 0.219 0.531t-0.219 0.531l-2.297 2.297 2.297 2.297q0.219 0.219 0.219 0.531z"></path>
58 </svg>',wp_kses_post(guaven_sqlcharts_recommended(),[]));
59 }
60
61
62
63 if (!empty($post) and $post->post_type == 'gvn_schart'):
64 if (!current_user_can('manage_options')) {
65 echo '<br><br>
66 <div class="updated gf-alert gf-alert-danger">Only administrators can manage this page</div>';
67 die();
68 }
69 echo '<div class="updated gf-alert gf-alert-info">';
70 if (empty($_GET["post"]) && strpos(sanitize_text_field(wp_unslash($_SERVER["REQUEST_URI"])), "post-new") === false) {
71 $gf_message = __(
72 'Use <b>Add new</b> button above to create a new SQL report. And click on any existing rule names below to manage them.',
73 'guaven_sqlcharts'
74 );
75 } else {
76 $gf_message = __(
77 '1. Give any name to your report.<br>
78 2. Pick a chart type, build your SQL query with the visual builder (or type it — autocomplete will help), map the X/Y columns and press Publish/Update.<br>
79 3. After update, you will see the shortcode of this chart at the bottom of the page. You can use that shortcode anywhere in your website: in pages, posts, widgets, etc.',
80 'guaven_sqlcharts'
81 );
82 }
83
84 echo '<div style="float:left;max-width:calc(100% - 345px)">';
85 echo wp_kses_post( $gf_message );
86 echo '</div>';
87
88 echo '<div style="float: right;
89 margin-top: 0px;
90 padding-top: 0px;"><a target="_blank" style="text-align:center;border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;"
91 class="button button-secondary" href="https://guaven.com/contact/solution-request/">Get Premium Support </a>
92 <span style="line-height: 30px;padding: 0 5px;">OR</span>
93 <a target="_blank" style="text-align:center;border:0px solid #26b286;border-radius:0px;color:white;font-weight:bold;background: #26b286;"
94 class="button button-secondary" href="https://guaven.com/service/small-thankyou-premium-support-service/">Make a Small Donation</a>
95 </div> </div>';
96 endif;
97 }
98 add_action('admin_notices', 'guaven_sqlcharts_my_admin_notice');
99
100 function guaven_sqlcharts_onboarding_notice(){
101 if((function_exists('wp_doing_ajax') and wp_doing_ajax()) or get_option('guaven_sqlcharts_onboarding_notice_dismissed') == 1)
102 return;
103
104 printf('
105 <div class="guaven-sqlcharts-notice notice notice-success is-dismissible" data-notice="onboarding_notice">
106 <p>Welcome aboard on MySQL Charts!</p>
107 </div>'
108 );
109 }
110 add_action('admin_notices', 'guaven_sqlcharts_onboarding_notice');
111
112 function guaven_sqlcharts_onboarding_notice_dismissed(){
113 check_ajax_referer('notice_dismissed', 'nonce');
114 if (!current_user_can('manage_options')) return;
115
116 if(empty($_POST['type']))return;
117 switch ($_POST['type']){
118 case 'onboarding_notice':
119 update_option('guaven_sqlcharts_onboarding_notice_dismissed', 1);
120 break;
121 }
122 }
123 add_action('wp_ajax_guaven_sqlcharts_onboarding_notice_dismissed', 'guaven_sqlcharts_onboarding_notice_dismissed');
124
125 function guaven_sqlcharts_enqueue_chart()
126 {
127 wp_enqueue_script('guaven_sqlcharts_chartjs', plugins_url('asset/chart.umd.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
128 wp_enqueue_script('guaven_sqlcharts_datepicker', plugins_url('asset/datepicker.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
129 wp_enqueue_script('guaven_sqlcharts_front', plugins_url('asset/front.js', __FILE__),array('jquery','guaven_sqlcharts_chartjs','guaven_sqlcharts_datepicker'),GVNSQLCHARTS_VERSION,false);
130 wp_localize_script('guaven_sqlcharts_front', 'guaven_sqlcharts_notice_dismissed', array(
131 'action' => 'guaven_sqlcharts_onboarding_notice_dismissed',
132 'nonce' => wp_create_nonce('notice_dismissed')
133 ));
134
135 }
136 add_action('wp_enqueue_scripts', 'guaven_sqlcharts_enqueue_chart');
137 add_action('admin_enqueue_scripts', 'guaven_sqlcharts_enqueue_chart');
138
139 function guaven_sqlcharts_enqueue_main_style()
140 {
141 wp_enqueue_style('guaven_sqlcharts_main_style', plugins_url('asset/guaven_sqlcharts.css', __FILE__),array(),GVNSQLCHARTS_VERSION);
142 }
143 add_action('wp_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
144 add_action('admin_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
145
146 // admin-only assets: SQL builder, autocomplete, new metabox UI
147 function guaven_sqlcharts_admin_assets($hook)
148 {
149 if (!in_array($hook, array('post.php', 'post-new.php'))) return;
150 $screen = function_exists('get_current_screen') ? get_current_screen() : null;
151 if (empty($screen->post_type) or $screen->post_type != 'gvn_schart') return;
152 if (!current_user_can('manage_options')) return;
153
154 wp_enqueue_style('guaven_sqlcharts_admin_style', plugins_url('asset/admin.css', __FILE__), array(), GVNSQLCHARTS_VERSION);
155 wp_enqueue_script('guaven_sqlcharts_admin', plugins_url('asset/admin.js', __FILE__), array('jquery'), GVNSQLCHARTS_VERSION, true);
156
157 global $wpdb;
158 $tables = $wpdb->get_col('SHOW TABLES');
159 if (!is_array($tables)) $tables = array();
160 wp_localize_script('guaven_sqlcharts_admin', 'gvnSqlBuilder', array(
161 'ajaxurl' => admin_url('admin-ajax.php'),
162 'nonce' => wp_create_nonce('gvnsql_schema'),
163 'tables' => array_values($tables),
164 'prefix' => $wpdb->prefix,
165 ));
166 }
167 add_action('admin_enqueue_scripts', 'guaven_sqlcharts_admin_assets');
168
169 // returns column names of one table for the live SQL builder/autocomplete
170 function guaven_sqlcharts_ajax_columns()
171 {
172 check_ajax_referer('gvnsql_schema', 'nonce');
173 if (!current_user_can('manage_options')) wp_send_json_error('forbidden', 403);
174 global $wpdb;
175 $table = isset($_POST['table']) ? sanitize_text_field(wp_unslash($_POST['table'])) : '';
176 $tables = $wpdb->get_col('SHOW TABLES');
177 if (!is_array($tables) or !in_array($table, $tables, true)) wp_send_json_error('unknown table', 400);
178 $cols = $wpdb->get_results('SHOW COLUMNS FROM `' . str_replace('`', '', $table) . '`');
179 $out = array();
180 if (is_array($cols)) {
181 foreach ($cols as $col) {
182 $out[] = array('name' => $col->Field, 'type' => $col->Type);
183 }
184 }
185 wp_send_json_success($out);
186 }
187 add_action('wp_ajax_gvnsql_get_columns', 'guaven_sqlcharts_ajax_columns');
188
189
190 function guaven_sqlcharts_isJson($string)
191 {
192 json_decode($string);
193 return (json_last_error() == JSON_ERROR_NONE);
194 }
195
196 add_action('init', 'guaven_sqlcharts_register_post');
197 function guaven_sqlcharts_register_post()
198 {
199 register_post_type('gvn_schart', array(
200 'labels' => array(
201 'name' => __('My SQL Charts','guaven_sqlcharts'),
202 'singular_name' => __('SQL Chart','guaven_sqlcharts'),
203 'menu_name' => __('My SQL Charts','guaven_sqlcharts'),
204 'add_new' => __('Add Chart','guaven_sqlcharts'),
205 'add_new_item' => __('Add New Chart','guaven_sqlcharts'),
206 'edit_item' => __('Edit Chart','guaven_sqlcharts'),
207 'new_item' => __('New Chart','guaven_sqlcharts'),
208 'view_item' => __('View Chart','guaven_sqlcharts'),
209 'view_items' => __('View Charts','guaven_sqlcharts'),
210 'search_items' => __('Search Charts','guaven_sqlcharts'),
211 'not_found' => __('No charts found','guaven_sqlcharts'),
212 'not_found_in_trash' => __('No charts found in Trash','guaven_sqlcharts'),
213 'all_items' => __('All Charts','guaven_sqlcharts'),
214 'archives' => __('Chart Archives','guaven_sqlcharts'),
215 'attributes' => __('Chart Attributes','guaven_sqlcharts'),
216 'insert_into_item' => __('Insert into chart','guaven_sqlcharts'),
217 'uploaded_to_this_item' => __('Uploaded to this chart','guaven_sqlcharts'),
218 'filter_items_list' => __('Filter charts list','guaven_sqlcharts'),
219 'items_list_navigation' => __('Charts list navigation','guaven_sqlcharts'),
220 'items_list' => __('Charts list','guaven_sqlcharts'),
221 'item_published' => __('Chart published.','guaven_sqlcharts'),
222 'item_published_privately' => __('Chart published privately.','guaven_sqlcharts'),
223 'item_reverted_to_draft' => __('Chart reverted to draft.','guaven_sqlcharts'),
224 'item_scheduled' => __('Chart scheduled.','guaven_sqlcharts'),
225 'item_updated' => __('Chart updated.','guaven_sqlcharts'),
226 ),
227
228 'public' => true,
229 'show_in_rest' => false,
230 'menu_icon' => 'dashicons-chart-pie',
231 // Charts execute SQL, so every primitive capability of this post type maps to manage_options.
232 // Contributors/Authors cannot create, edit, publish or delete charts through any WordPress
233 // entry point (admin UI, XML-RPC, REST). Published charts stay viewable on the front end.
234 // Only primitive capabilities are remapped: mapping the meta capabilities edit_post/read_post/
235 // delete_post to manage_options would make WordPress treat manage_options itself as a meta
236 // capability and break that check site-wide.
237 'capability_type' => 'post',
238 'map_meta_cap' => true,
239 'capabilities' => array(
240 'edit_posts' => 'manage_options',
241 'edit_others_posts' => 'manage_options',
242 'edit_published_posts' => 'manage_options',
243 'edit_private_posts' => 'manage_options',
244 'publish_posts' => 'manage_options',
245 'read_private_posts' => 'manage_options',
246 'delete_posts' => 'manage_options',
247 'delete_private_posts' => 'manage_options',
248 'delete_published_posts' => 'manage_options',
249 'delete_others_posts' => 'manage_options',
250 'create_posts' => 'manage_options',
251 ),
252 'supports' => array(
253 'title',
254 'postmeta'
255 ),
256 'register_meta_box_cb' => 'guaven_sqlcharts_metabox_area'
257 ));
258
259 guaven_sqlcharts_load_defaults();
260 }
261
262 // All guaven_sqlcharts_* meta keys are protected: they cannot be written through the Custom Fields box,
263 // XML-RPC or the REST API. The plugin's own save handler (update_post_meta) is not affected.
264 add_filter('is_protected_meta', function ($protected, $meta_key) {
265 return strpos((string) $meta_key, 'guaven_sqlcharts_') === 0 ? true : $protected;
266 }, 10, 2);
267
268 // "Add title" placeholder on the chart edit screen
269 add_filter('enter_title_here', function ($title, $post) {
270 if (!empty($post) and $post->post_type == 'gvn_schart') return __('Chart name', 'guaven_sqlcharts');
271 return $title;
272 }, 10, 2);
273
274 add_action('admin_footer', 'guaven_sqlcharts_admin_front');
275
276
277 function guaven_sqlcharts_admin_front()
278 {
279 global $post;
280 if (!empty($post) and $post->post_type == 'gvn_schart') {
281 ?>
282 <style type="text/css">#normal-sortables{display: none}</style>
283 <?php
284 }
285 }
286
287 // metabox for editor
288 function guaven_sqlcharts_metabox_area()
289 {
290 add_meta_box('guaven_sqlcharts_metabox', 'Chart Builder', 'guaven_sqlcharts_metabox', 'gvn_schart', 'advanced', 'default');
291 }
292
293 function guaven_sqlcharts_metabox()
294 {
295 require_once(dirname(__FILE__) . "/admin_metabox.php");
296 }
297
298 /**
299 * Catalog of all supported chart types: label, group, per-type usage guide and example query.
300 * Used by the admin UI to render the type cards and the contextual guides.
301 */
302 function guaven_sqlcharts_type_catalog()
303 {
304 global $wpdb;
305 $p = $wpdb->posts;
306 $u = $wpdb->users;
307 return array(
308 'pie_l' => array(
309 'label' => 'Pie',
310 'group' => 'Circular',
311 'guide' => 'Best for showing how a total splits into a few parts (shares/percentages). Use one query that returns a label column (X) and a numeric value column (Y). Keep it under ~8 slices for readability.',
312 'example_sql' => "select count(*) postcount, SUBSTR(post_date,1,4) yearnum from $p group by yearnum order by yearnum asc limit 10",
313 'example_x' => 'yearnum', 'example_y' => 'postcount',
314 ),
315 'donut_l' => array(
316 'label' => 'Doughnut',
317 'group' => 'Circular',
318 'guide' => 'Same as Pie but with a hole in the middle — slightly easier to compare slice sizes. One query: label column (X) + numeric column (Y).',
319 'example_sql' => "select count(*) postcount, post_type from $p group by post_type order by postcount desc limit 8",
320 'example_x' => 'post_type', 'example_y' => 'postcount',
321 ),
322 'polar_l' => array(
323 'label' => 'Polar Area',
324 'group' => 'Circular',
325 'guide' => 'Like a pie, but every slice has the same angle and the value controls the radius. Good for cyclic data (months, weekdays). One query: label (X) + numeric value (Y).',
326 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,6,2) monthnum from $p group by monthnum order by monthnum",
327 'example_x' => 'monthnum', 'example_y' => 'postcount',
328 ),
329 'radar_l' => array(
330 'label' => 'Radar',
331 'group' => 'Circular',
332 'guide' => 'Compares one or more series across several categories arranged in a circle. Great for profiles/ratings. Use one query per series, separated with ";".',
333 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,6,2) monthnum from $p where post_type=\"post\" group by monthnum order by monthnum",
334 'example_x' => 'monthnum', 'example_y' => 'postcount',
335 ),
336 'line_l' => array(
337 'label' => 'Line',
338 'group' => 'Line',
339 'guide' => 'The classic choice for trends over time (per day/month/year). X should be an ordered value like a date. Add more queries separated with ";" for comparison lines.',
340 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p group by monthandyear order by monthandyear",
341 'example_x' => 'monthandyear', 'example_y' => 'postcount',
342 ),
343 'area_l' => array(
344 'label' => 'Area',
345 'group' => 'Line',
346 'guide' => 'A line chart with the region under the line filled — emphasizes volume/magnitude of a trend. Works well with 2 queries (";" separated) to compare filled regions.',
347 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p where post_type=\"post\" group by monthandyear order by monthandyear;\nselect count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p where post_type!=\"post\" group by monthandyear order by monthandyear",
348 'example_x' => 'monthandyear', 'example_y' => 'Posts;Other content',
349 ),
350 'steppedline_l' => array(
351 'label' => 'Stepped Line',
352 'group' => 'Line',
353 'guide' => 'Line chart that moves in steps instead of slopes — perfect for values that change at discrete moments (prices, stock level, settings history).',
354 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p group by yearnum order by yearnum",
355 'example_x' => 'yearnum', 'example_y' => 'postcount',
356 ),
357 'bar_l' => array(
358 'label' => 'Bar',
359 'group' => 'Bar',
360 'guide' => 'Compares values across categories with vertical bars. One query: category (X) + numeric value (Y). Multiple ";" separated queries become grouped/stacked bars.',
361 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p group by monthandyear order by monthandyear",
362 'example_x' => 'monthandyear', 'example_y' => 'postcount',
363 ),
364 'horizontalbar_l' => array(
365 'label' => 'Horizontal Bar',
366 'group' => 'Bar',
367 'guide' => 'Bar chart rotated 90° — the best pick when category names are long (user names, product titles).',
368 'example_sql' => "select count(*) as postcount, b.display_name as dname from $p a inner join $u b ON a.post_author=b.ID where a.post_status=\"publish\" group by a.post_author order by postcount desc limit 10",
369 'example_x' => 'dname', 'example_y' => 'postcount',
370 ),
371 'stackedbar_l' => array(
372 'label' => 'Stacked Bar',
373 'group' => 'Bar',
374 'guide' => 'Shows how each category total is composed of parts. Use 2+ queries separated with ";" — each query becomes one segment color of the stack.',
375 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p where post_type=\"post\" group by yearnum order by yearnum;\nselect count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p where post_type!=\"post\" group by yearnum order by yearnum",
376 'example_x' => 'yearnum', 'example_y' => 'Posts;Other content',
377 ),
378 'scatter_l' => array(
379 'label' => 'Scatter',
380 'group' => 'Other',
381 'guide' => 'Plots points on numeric X/Y axes to reveal correlation between two numbers. Both X and Y columns must be numeric (e.g. comment_count vs menu_order).',
382 'example_sql' => "select comment_count ccount, ID from $p where post_status=\"publish\" order by ID limit 100",
383 'example_x' => 'ID', 'example_y' => 'ccount',
384 ),
385 );
386 }
387
388 /**
389 * Maps deprecated Google-Chart era type slugs to their Chart.js equivalents.
390 * Old charts keep working without any manual migration; when the post is re-saved
391 * from the new UI the normalized value is stored automatically.
392 */
393 function guaven_sqlcharts_normalize_type($type)
394 {
395 $map = array(
396 'pie' => 'pie_l',
397 '3dpie' => 'pie_l',
398 'column' => 'bar_l',
399 'bar' => 'horizontalbar_l',
400 'area' => 'area_l',
401 );
402 return isset($map[$type]) ? $map[$type] : $type;
403 }
404
405 function guaven_gutenberg_wrapper($atts){
406 if(isset($atts['sqlcharts_inserted_script'])){
407 global $sqlcharts_inserted_script;
408 $sqlcharts_inserted_script = $atts['sqlcharts_inserted_script'];
409 }
410
411 $post = get_post($atts['chart_id']);
412 if( ! isset($atts['chart_id']) or !isset($post) or $post->post_type != 'gvn_schart'){
413
414 return "Invalid id";
415 }
416
417 return guaven_sqlcharts_local_shortcode(array('id' => $atts['chart_id'])); // temporary explicit value
418 }
419 function guaven_register_gutenberg_blocks()
420 {
421 wp_register_script(
422 'gvn_gutenberg_charts',
423 plugins_url( 'asset/guaven_gutenberg_charts.js', __FILE__ ),
424 array( 'wp-blocks', 'wp-i18n', 'wp-element', 'wp-server-side-render' ),
425 GVNSQLCHARTS_VERSION.'_'.filemtime( plugin_dir_path( __FILE__ ) . 'asset/guaven_gutenberg_charts.js'),
426 false
427 );
428 wp_localize_script('gvn_gutenberg_charts', 'guaven', array(
429 'description' => 'Add My SQL Chart to your post',
430 ));
431
432 register_block_type( 'guaven-sqlcharts/gvn-chart-gutenberg', array(
433 'editor_script' => 'gvn_gutenberg_charts',
434 'render_callback' => 'guaven_gutenberg_wrapper',
435 'attributes' => array(
436 'chart_id' => array(
437 'type' => 'string',
438 'default' => null
439 ),
440 'sqlcharts_inserted_script' => array(
441 'type' => 'number',
442 'default' => null
443 )
444 )
445 ));
446 }
447 add_action('init', 'guaven_register_gutenberg_blocks');
448
449
450
451 function guaven_sqlcharts_save_metabox_area($post_id, $post)
452 {
453 if (!isset($_POST['meta_box_nonce_field']) or !wp_verify_nonce($_POST['meta_box_nonce_field'], 'meta_box_nonce_action')) {
454 return $post->ID;
455 }
456 if ($post->post_type != 'gvn_schart' or !current_user_can('manage_options') or (defined('DOING_AUTOSAVE') and DOING_AUTOSAVE)) {
457 return $post->ID;
458 }
459 $fields = array(
460 "guaven_sqlcharts_chartheight",
461 "guaven_sqlcharts_chartwidth",
462 "guaven_sqlcharts_graphtype",
463 "guaven_sqlcharts_xarg_s",
464 "guaven_sqlcharts_xarg_l",
465 "guaven_sqlcharts_yarg_s",
466 "guaven_sqlcharts_yarg_l",
467 "guaven_sqlcharts_tablepart",
468 "guaven_sqlcharts_variables",
469 "guaven_sqlcharts_formpartrole",
470 "guaven_sqlcharts_formpartbutton",
471 "guaven_sqlcharts_dbhost",
472 "guaven_sqlcharts_dblogin",
473 "guaven_sqlcharts_dbname",
474 "guaven_sqlcharts_colors",
475 "guaven_sqlcharts_begin_with_0_x",
476 "guaven_sqlcharts_begin_with_0_y",
477 "guaven_sqlcharts_round_y_values",
478 "guaven_sqlcharts_legend_position",
479 "guaven_sqlcharts_nostacked",
480 "guaven_sqlcharts_forcetooltips",
481 "guaven_sqlcharts_timeaxis"
482 );
483 foreach ($fields as $key => $value) {
484 if(isset($_POST[$value]))$newval=esc_attr($_POST[$value]);
485 else $newval='';
486
487 update_post_meta($post->ID, $value, $newval);
488 }
489 if(!empty($_POST["guaven_sqlcharts_dbpass"])){
490 $encpass=guaven_sqlcharts_encrypt_decrypt('encrypt',$_POST["guaven_sqlcharts_dbpass"]);
491 update_post_meta($post->ID, 'guaven_sqlcharts_dbpass', ['encrypted',$encpass]);
492 }
493 // Store the SQL as typed. Do not HTML-encode it and do not rewrite quotes:
494 // the editor escapes it on output and the front end decodes entities before running it.
495 $sql_code = isset($_POST['guaven_sqlcharts_code']) ? wp_check_invalid_utf8(wp_unslash($_POST['guaven_sqlcharts_code'])) : '';
496 update_post_meta($post->ID, 'guaven_sqlcharts_code', $sql_code);
497 // Flag that this chart stores raw SQL. Charts without the flag were saved by
498 // versions before 3.0.1, which HTML-encoded the query, and still need decoding.
499 update_post_meta($post->ID, 'guaven_sqlcharts_code_raw', 1);
500 }
501
502 // Returns the stored SQL query exactly as the user typed it.
503 function guaven_sqlcharts_get_code($post_id)
504 {
505 $sql = get_post_meta($post_id, 'guaven_sqlcharts_code', true);
506 if (get_post_meta($post_id, 'guaven_sqlcharts_code_raw', true) != 1) {
507 $sql = html_entity_decode($sql, ENT_QUOTES, 'UTF-8');
508 }
509 return $sql;
510 }
511 add_action('save_post', 'guaven_sqlcharts_save_metabox_area', 1, 2);
512 // save the custom fields
513
514
515
516 // Removes string literals (contents only), backtick identifiers and comments from SQL so keyword checks
517 // see the same code MySQL will execute. "/*!" and "/*+" comments are executable in MySQL and are kept.
518 function guaven_sqlcharts_strip_sql_literals($sql)
519 {
520 $out = ''; $len = strlen($sql); $i = 0;
521 while ($i < $len) {
522 $c = $sql[$i];
523 if ($c === "'" or $c === '"' or $c === '`') {
524 $out .= $c . $c; $i++;
525 while ($i < $len) {
526 if ($sql[$i] === '\\' and $c !== '`') { $i += 2; continue; }
527 if ($sql[$i] === $c) { if ($i + 1 < $len and $sql[$i + 1] === $c) { $i += 2; continue; } $i++; break; }
528 $i++;
529 }
530 continue;
531 }
532 if ($c === '#' or ($c === '-' and substr($sql, $i, 2) === '--' and ($i + 2 >= $len or ctype_space($sql[$i + 2])))) {
533 $nl = strpos($sql, "\n", $i); $i = ($nl === false) ? $len : $nl; continue;
534 }
535 if ($c === '/' and substr($sql, $i, 2) === '/*' and !in_array(substr($sql, $i + 2, 1), array('!', '+'), true)) {
536 $close = strpos($sql, '*/', $i + 2); $i = ($close === false) ? $len : $close + 2; $out .= ' '; continue;
537 }
538 $out .= $c; $i++;
539 }
540 return $out;
541 }
542
543 // Returns 1 when the (fully substituted) SQL must not run, 0 when it is a read-only query.
544 // Called after every {tag}/{argN} replacement so user-supplied values are covered too.
545 function gvn_chart_check_sql_query($sql)
546 {
547 // 1) data-changing statements: checked on the raw text, exactly as in every previous version
548 $write = '/\b(delete|update|insert|replace|drop|truncate|alter|create|rename|grant|revoke|call|handler|load\s+data|load_file|outfile|dumpfile)\b/i';
549 if (preg_match($write, $sql)) return 1;
550
551 // 2) further dangerous statements, matched outside string literals and comments so that ordinary
552 // values such as status = 'reset' keep working
553 $danger = '/\b(prepare|execute|deallocate|lock|unlock|kill|shutdown|flush|reset|purge|install|uninstall|import'
554 . '|set\s+(?:global|session|persist|persist_only|password|@@)|start\s+(?:replica|slave|group_replication)|stop\s+(?:replica|slave)|change\s+(?:master|replication))\b/i';
555 if (preg_match($danger, guaven_sqlcharts_strip_sql_literals($sql))) return 1;
556
557 // 3) every ";"-separated statement must be a read statement. The renderer sends each segment to the
558 // database on its own, so this stops a value from smuggling a second statement behind a ";".
559 foreach (explode(';', $sql) as $segment) {
560 $segment = ltrim(guaven_sqlcharts_strip_sql_literals($segment), " \t\r\n(");
561 if ($segment === '') continue;
562 if (!preg_match('/^(select|with|show|describe|desc|explain)\b/i', $segment)) return 1;
563 }
564 return 0;
565 }
566
567 function guaven_get_labels_and_values($id, $fvs)
568 {
569 $values = array();
570 $labels = array();
571 $xarg_s = get_post_meta($id, 'guaven_sqlcharts_xarg_s', true);
572 $yarg_s = get_post_meta($id, 'guaven_sqlcharts_yarg_s', true);
573 // labels are saved through esc_attr, so "&" is stored as "&amp;"; decode before splitting on ";"
574 // or the entity's own ";" would be taken as a series separator
575 $xarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_xarg_l', true), ENT_QUOTES, 'UTF-8');
576 $yarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_yarg_l', true), ENT_QUOTES, 'UTF-8');
577 foreach ($fvs as $key => $value) {
578 $values[$value->$xarg_s] = $value->$yarg_s;
579 $labels[$value->$xarg_s] = '"' . $value->$xarg_s . '"';
580 }
581 return array(
582 $labels,
583 $values,
584 explode(";", $yarg_l),
585 explode(";", $xarg_l)
586 );
587 }
588
589 function guaven_sqlcharts_print_chart_js($print_data)
590 {
591 extract($print_data);
592 $tip_g = guaven_sqlcharts_normalize_type($tip_g);
593
594 switch ($tip_g) {
595 case 'line_l':
596 guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid);
597 break;
598 case 'area_l':
599 guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'true', $pid);
600 break;
601 case 'steppedline_l':
602 guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid, 'line', true);
603 break;
604 case 'radar_l':
605 guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'radarfill', $pid, 'radar');
606 break;
607 case 'pie_l':
608 guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid);
609 break;
610 case 'donut_l':
611 guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'doughnut');
612 break;
613 case 'polar_l':
614 guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'polarArea');
615 break;
616 case 'bar_l':
617 guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'bar', $pid);
618 break;
619 case 'horizontalbar_l':
620 guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'horizontalBar', $pid);
621 break;
622 case 'stackedbar_l':
623 guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'stackedBar', $pid);
624 break;
625 case 'scatter_l':
626 guaven_sqlcharts_scatterdata($title, $labels, $values, $ylabel, $pid);
627 break;
628 case 'custom':
629 guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid);
630 break;
631 }
632 }
633
634 function guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid){
635 do_action('guaven_sqlcharts_custom',$title, $labels, $values, $ylabel, $pid);
636 }
637
638 function gvn_chart_put_variables($sql,$pid){
639 $sql_initial=$sql;
640
641
642 $default_tag_keys=['{current_user_id}','{current_user_login}','{current_user_email}','{current_user_display_name}'];
643 if(is_user_logged_in( )){
644 $currentuser=wp_get_current_user();
645 $default_tag_values=[$currentuser->ID,$currentuser->user_login,$currentuser->user_email,$currentuser->user_display_name];
646 }
647 else {
648 $default_tag_values='';
649 }
650 $sql_initial=str_replace($default_tag_keys,$default_tag_values,$sql_initial);
651
652 $variables_raw=get_post_meta($pid,'guaven_sqlcharts_variables',true);
653 $variables_arr=explode("|",$variables_raw);
654 foreach($variables_arr as $varfield){
655 $varfield_arr=explode("~",$varfield);
656 if (count($varfield_arr)<3) continue;
657 $varfield_arr=array_map("trim",$varfield_arr);
658 if (!empty($_GET[$varfield_arr[0]])) {
659 // User-supplied input: no () bypass allowed — sanitize strictly
660 $varreplacement = str_replace(';', '', sanitize_text_field(wp_unslash($_GET[$varfield_arr[0]])));
661 if (is_numeric($varreplacement)) {
662 $varreplacement = $varreplacement + 0;
663 } else {
664 $varreplacement = '"' . esc_sql($varreplacement) . '"';
665 }
666 } else {
667 // Admin-configured default value: allow () for SQL functions (e.g. NOW())
668 $varreplacement = $varfield_arr[1];
669 if (!is_numeric($varreplacement) && strpos($varreplacement,'()')===false) {
670 $varreplacement = '"' . esc_sql($varreplacement) . '"';
671 }
672 }
673
674 $sql_initial=str_replace('{'.$varfield_arr[0].'}',$varreplacement,$sql_initial);
675 }
676 return $sql_initial;
677 }
678
679 function gvn_chart_top_form($atts){
680 if (get_post_meta($atts["id"],'guaven_sqlcharts_formpartrole',true)!='' and !is_user_logged_in()) return;
681 $topform='';$dateexists=false;
682 $variables_raw=get_post_meta($atts['id'],'guaven_sqlcharts_variables',true);
683 $variables_raw=explode("|",$variables_raw);
684 foreach ($variables_raw as $vrow){
685 $vrow_arr=explode("~",$vrow);
686 $vrow_arr=array_map("trim",$vrow_arr);
687 if (empty($vrow_arr[3])) continue;
688 $gvalue=!empty($_GET[$vrow_arr[0]])?esc_attr(urldecode($_GET[$vrow_arr[0]])):'';
689 $dvalue=(strpos($vrow_arr[1],'()')===false)?esc_attr($vrow_arr[1]):'';
690 if ($vrow_arr[3]=='date') {
691 $dateexists=true;
692 $topform.= '<span class="gvn-filter-field"><label>'.$vrow_arr[2].'</label> <input class="gws_datepicker" autocomplete="off" type="text"
693 value="'.$gvalue.'"
694 data-toggle="datepicker" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'"></span>
695 ';}
696 else {
697 $topform.= '<span class="gvn-filter-field"><label>'.$vrow_arr[2].'</label> <input autocomplete="off"
698 type="'.$vrow_arr[3].'"
699 value="'.$gvalue.'" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'"></span>
700 ';
701 }
702 }
703 if (!empty($topform)) {
704 $allowed_html = array(
705 'form' => array(
706 'method' => array(),
707 'action' => array(),
708 'class' => array()
709 ),
710 'input' => array(
711 'type' => array(),
712 'value' => array(),
713 'name' => array(),
714 'class' => array(),
715 'data-toggle'=>array(),
716 'placeholder'=>array(),
717 'autocomplete'=>array(),
718 'style'=>[]
719 ),
720 'span' => array('class' => array()),
721 'label' => array(),
722 );
723
724 $submit_button_value = get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true) != ''
725 ? esc_attr(get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true))
726 : 'OK';
727
728 $topform = '<form method="get" action="" class="guaven_sqlcharts_form">' . $topform . '
729 <input type="submit" value="' . $submit_button_value . '"></form>';
730
731 echo wp_kses($topform, $allowed_html);
732 }
733 }
734
735
736 function guaven_sqlcharts_encrypt_decrypt($action, $string)
737 {
738 $output = false;
739 $encrypt_method = "AES-256-CBC";
740 $secret_key = 'GWSCHARTPL2022.2016.';
741 $secret_iv = 'GWSCHARTPL2016.2022';
742 $key = hash('sha256', $secret_key);
743 $iv = substr(hash('sha256', $secret_iv), 0, 16);
744 if ( $action == 'encrypt' ) {
745 $output = openssl_encrypt($string, $encrypt_method, $key, 0, $iv);
746 $output = base64_encode($output);
747 } else if( $action == 'decrypt' ) {
748 $output = openssl_decrypt(base64_decode($string), $encrypt_method, $key, 0, $iv);
749 }
750 return $output;
751 }
752
753 function guaven_sqlcharts_local_shortcode($atts) {
754 if(empty($atts['id']))return 'ID is missing.';
755 $atts['id']=intval($atts['id']);
756 $post_g = get_post($atts['id']);
757 if (!$post_g or $post_g->post_type != 'gvn_schart') return 'Chart not found.';
758 $remote_host=get_post_meta($atts['id'], 'guaven_sqlcharts_dbhost', true);
759 if ($remote_host!=''){
760 $remote_db=get_post_meta($atts['id'], 'guaven_sqlcharts_dbname', true);
761 $remote_login=get_post_meta($atts['id'], 'guaven_sqlcharts_dblogin', true);
762 $remote_pass=get_post_meta($atts['id'], 'guaven_sqlcharts_dbpass', true);
763 if(is_array($remote_pass)){
764 $remote_pass=guaven_sqlcharts_encrypt_decrypt('decrypt',$remote_pass[1]);
765 }
766 $wpdb=new wpdb($remote_login,$remote_pass,$remote_db,$remote_host);
767 }
768 else {
769 global $wpdb;
770 }
771
772 $GLOBALS["guaven_sqlcharts_atts"]=$atts;
773
774 $sql = guaven_sqlcharts_get_code($atts['id']);
775 if(empty($sql))return 'SQL query is missing.';
776
777 // {arg1}..{arg19} come from shortcode attributes: [gvn_schart_2 id="1" arg1="41"].
778 // Substituted directly (not via wpdb::prepare) so the same tag may appear any number of times,
779 // e.g. in every query of a ";"-separated comparison chart. Numbers are inserted as-is, anything
780 // else is escaped and quoted; a tag already wrapped in quotes ('{arg1}') is not double-quoted.
781 // ";" is removed from values because the finished SQL is split on ";" below.
782 for($i=1;$i<20;$i++){
783 $tag = '{arg'.$i.'}';
784 if (strpos($sql, $tag) === false) continue;
785 $replacearg = !empty($atts['arg'.$i]) ? $atts['arg'.$i] : 0;
786 if (is_numeric($replacearg)) $replacearg = $replacearg + 0;
787 else $replacearg = "'" . esc_sql(str_replace(';', '', sanitize_text_field((string) $replacearg))) . "'";
788 $sql = str_replace(array("'".$tag."'", '"'.$tag.'"', $tag), $replacearg, $sql);
789 }
790
791 $sql=gvn_chart_put_variables($sql,$atts['id']);
792 $sql=apply_filters('guaven_sqlcharts_rendered_sql',$sql,$atts);
793
794 // command check on the final SQL, after every shortcode argument and filter value is in place
795 $blacklister_f = gvn_chart_check_sql_query($sql);
796 if ($blacklister_f == 1)return 'You given SQL code contains forbidden commands. Remember that you should only use SELECT queries';
797 $tip_g = guaven_sqlcharts_normalize_type(get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true));
798
799 $sql_split = explode(';', $sql);
800 $labels_and_values = array();
801 $labels = $values = $ylabel = $xlabel = array();
802
803 global $sqlcharts_inserted_script;
804 ob_start();
805 for ($i = 0; $i < count($sql_split); $i++) {
806 if (!empty($sql_split[$i])) {
807
808 $fvs = $wpdb->get_results($sql_split[$i]);
809 if (strpos($_SERVER["REQUEST_URI"],'wp-admin')!==false){
810 $wpdb->show_errors();
811 ob_start();
812 $wpdb->print_error();
813 $printerror = ob_get_clean();
814 if ($printerror != '' and strpos($printerror, "[]") === false){
815 ob_end_clean();
816 return $printerror;
817 }
818 elseif (empty($fvs)){
819 ob_end_clean();
820 return 'Your SQL returnes empty data, please recheck your SQL query above';
821 }
822 }
823
824 if (empty($sqlcharts_inserted_script))
825 $sqlcharts_inserted_script = 1;
826 $labels_and_values[$i] = guaven_get_labels_and_values($atts['id'], $fvs);
827 $labels[$i] = $labels_and_values[$i][0];
828 $values[$i] = $labels_and_values[$i][1];
829 $ylabel[$i] = !empty($labels_and_values[$i][2][$i]) ? $labels_and_values[$i][2][$i] : '';
830 $xlabel[$i] = !empty($labels_and_values[$i][3][$i]) ? $labels_and_values[$i][3][$i] : '';
831 }
832 }
833
834 gvn_chart_top_form($atts);
835
836 // shortcode width/height attributes override the saved defaults
837 $chart_w = !empty($atts['width']) ? $atts['width'] : get_post_meta($atts['id'], 'guaven_sqlcharts_chartwidth', true);
838 $chart_h = !empty($atts['height']) ? $atts['height'] : get_post_meta($atts['id'], 'guaven_sqlcharts_chartheight', true);
839 $wrap_style = '';
840 if ($chart_w != '') $wrap_style .= 'max-width:' . (int) $chart_w . 'px;';
841 if ($chart_h != '') $wrap_style .= 'height:' . (int) $chart_h . 'px;';
842 ?>
843 <div class="gvn-chartwrap"<?php echo $wrap_style != '' ? ' style="' . esc_attr($wrap_style) . '"' : ''; ?>>
844 <canvas
845 id="ct-chart_<?php echo esc_attr($sqlcharts_inserted_script); ?>"
846 class="guaven_chart_canvas"
847 ></canvas>
848 </div>
849
850 <script type="text/javascript" class="gvn_charts_script" async>
851 var ctx = jQuery("#ct-chart_<?php
852 echo esc_attr($sqlcharts_inserted_script);
853 ?>");
854
855 <?php
856 $print_data=apply_filters('guaven_sqlcharts_pre_print_vars',['tip_g'=>$tip_g, 'title'=>$post_g->post_title,
857 'labels'=>$labels, 'values'=>$values, 'ylabel'=>$ylabel, 'pid'=>$atts['id']]);
858 guaven_sqlcharts_print_chart_js($print_data);
859 ?>
860 </script>
861
862 <?php
863 if (!empty($atts["table"])) guaven_sqlcharts_tablepart($post_g->post_title, $labels, $values, $ylabel,$xlabel);
864 $sqlcharts_inserted_script++;
865 $ret=ob_get_clean();
866 $ret=apply_filters( 'guaven_sqlcharts_final_output', $ret, $atts );
867 return $ret;
868 }
869
870 add_shortcode('gvn_schart_2', 'guaven_sqlcharts_local_shortcode');
871
872 // legacy alias: old Google-Chart era posts produced [gvn_schart id=".."] shortcodes
873 if (!shortcode_exists('gvn_schart')) {
874 add_shortcode('gvn_schart', 'guaven_sqlcharts_local_shortcode');
875 }
876
877 // [gvn_schart_2_cached id="1" expire="3600" arg1=".."] – same as gvn_schart_2 but the output is kept in a
878 // transient. All other attributes (argN, width, height, table, params) are passed through, and each
879 // distinct set of attributes gets its own cache entry. Append ?force_sql_cache_reload to the URL to bypass.
880 add_shortcode("gvn_schart_2_cached",function($atts){
881 if(empty($atts["id"]))return;
882 $atts["id"]=intval($atts["id"]);
883 $expire=!empty($atts["expire"])?intval($atts["expire"]):3600;
884 $inner_atts=$atts;
885 unset($inner_atts['expire']);
886 // One cache entry per user (charts may use {current_user_*} tags), per set of shortcode attributes
887 // and per value of every dynamic filter this chart reads from the URL. A visitor can therefore
888 // never be served, or pre-seed, a result computed for someone else or for other filter values.
889 $key_parts = array('atts' => $inner_atts, 'user' => is_user_logged_in() ? get_current_user_id() : 0, 'get' => array());
890 foreach (explode('|', (string) get_post_meta($atts['id'], 'guaven_sqlcharts_variables', true)) as $vrow) {
891 $vname = trim(current(explode('~', $vrow)));
892 if ($vname !== '' and isset($_GET[$vname])) $key_parts['get'][$vname] = sanitize_text_field(wp_unslash($_GET[$vname]));
893 }
894 $key = 'cached_sql_charts_' . $atts["id"] . '_' . md5(serialize($key_parts));
895 $cached=get_transient($key);
896 if(!empty($cached) and !isset($_GET["force_sql_cache_reload"]) )return $cached;
897 $tobecached=guaven_sqlcharts_local_shortcode($inner_atts);
898 set_transient($key, $tobecached,$expire);
899 return $tobecached;
900 });
901
902 // fixed, colorblind-friendly default palette (Tableau 10) used when no custom colors are set
903 function guaven_sqlcharts_default_palette(){
904 return apply_filters('guaven_sqlcharts_default_palette', array(
905 '#4E79A7', '#F28E2B', '#E15759', '#76B7B2', '#59A14F',
906 '#EDC948', '#B07AA1', '#FF9DA7', '#9C755F', '#BAB0AC'
907 ));
908 }
909
910 function guaven_sqlcharts_colors($index, $pid = null){
911 if(!isset($pid)) {
912 global $post;
913 $pid = $post->ID;
914 }
915 $colors=get_post_meta($pid,'guaven_sqlcharts_colors',true);
916 $colors=explode(",",$colors);
917 if (!empty($colors[$index])) return $colors[$index];
918 $palette = guaven_sqlcharts_default_palette();
919 return $palette[$index % count($palette)];
920 }
921
922 // outputs 'maintainAspectRatio:false,' when an explicit height is set, so the
923 // chart fills its sized wrapper instead of keeping the default aspect ratio
924 function guaven_sqlcharts_mar($pid){
925 $atts = isset($GLOBALS["guaven_sqlcharts_atts"]) ? $GLOBALS["guaven_sqlcharts_atts"] : array();
926 $h = !empty($atts['height']) ? $atts['height'] : get_post_meta($pid, 'guaven_sqlcharts_chartheight', true);
927 return $h != '' ? 'maintainAspectRatio: false,' : '';
928 }
929
930 // outputs 'showAllTooltips: true,' when "Value labels" is checked; the values are drawn by the
931 // gvnShowAllValues plugin in asset/front.js (works for every chart type)
932 function guaven_sqlcharts_value_labels($pid){
933 return get_post_meta($pid, 'guaven_sqlcharts_forcetooltips', true) != '' ? 'showAllTooltips: true,' : '';
934 }
935
936 // Chart.js scale title block built from the "X axis label" / "Y axis label" fields.
937 // $which is 'x' or 'y' (the *field* to use, not the scale). The Y label is only used as an axis
938 // title for single-series charts; with several ";"-separated series the legend names them instead.
939 function guaven_sqlcharts_axis_title($pid, $which){
940 $key = $which == 'x' ? 'guaven_sqlcharts_xarg_l' : 'guaven_sqlcharts_yarg_l';
941 $text = trim(html_entity_decode((string) get_post_meta($pid, $key, true), ENT_QUOTES, 'UTF-8'));
942 if ($text === '' or ($which == 'y' and strpos($text, ';') !== false)) return '';
943 return 'title: {display: true, text: ' . wp_json_encode($text) . '},';
944 }
945
946 // "params" shortcode attribute: extra Chart.js dataset options, e.g. params="borderWidth: 3, borderDash: [5,5],".
947 // The text is placed inside the inline <script>, so only a conservative character set is accepted:
948 // no parentheses, semicolons, "=", "<", ">", "/", "\\", "+" or backticks, which rules out executable JavaScript.
949 function guaven_sqlcharts_dataset_params(){
950 $params = isset($GLOBALS["guaven_sqlcharts_atts"]["params"]) ? (string) $GLOBALS["guaven_sqlcharts_atts"]["params"] : '';
951 if ($params === '' or !preg_match('/^[A-Za-z0-9_\s,:.\'"#%\-\[\]{}]+$/', $params)) return '';
952 return $params;
953 }
954
955 // dataset label as a safe JS string literal (labels saved before 3.0.1 may hold HTML entities)
956 function guaven_sqlcharts_js_label($label){
957 return wp_json_encode(html_entity_decode((string) $label, ENT_QUOTES, 'UTF-8'));
958 }
959
960 // Parses an X value for the "time axis" option. Accepts YYYY, YYYY-MM, YYYY-MM-DD, optionally followed
961 // by HH:MM or HH:MM:SS. Returns a UTC timestamp in milliseconds, or false when the value is not a date.
962 function guaven_sqlcharts_parse_date($str){
963 $str = trim((string) $str);
964 if (!preg_match('/^(\d{4})(?:-(\d{1,2})(?:-(\d{1,2})(?:[ T](\d{1,2}):(\d{2})(?::(\d{2}))?)?)?)?$/', $str, $m)) return false;
965 $y = (int) $m[1]; $mo = isset($m[2]) ? (int) $m[2] : 1; $d = isset($m[3]) ? (int) $m[3] : 1;
966 $h = isset($m[4]) ? (int) $m[4] : 0; $mi = isset($m[5]) ? (int) $m[5] : 0; $sec = isset($m[6]) ? (int) $m[6] : 0;
967 if (!checkdate($mo, $d, $y) or $h > 23 or $mi > 59 or $sec > 59) return false;
968 return gmmktime($h, $mi, $sec, $mo, $d, $y) * 1000;
969 }
970
971 // "Scale X axis by date/time" option. Returns, per dataset, a list of "{x:<ms>,y:<value>}" JS point
972 // literals when the option is on and every X value is a date; false otherwise (normal category axis).
973 function guaven_sqlcharts_time_axis_points($pid, $values){
974 if (get_post_meta($pid, 'guaven_sqlcharts_timeaxis', true) != 1) return false;
975 $out = array();
976 $has_point = false;
977 foreach ($values as $key_ak => $series) {
978 $out[$key_ak] = array();
979 foreach ($series as $x => $y) {
980 $ts = guaven_sqlcharts_parse_date($x);
981 if ($ts === false) return false;
982 $out[$key_ak][] = '{x:' . $ts . ',y:' . (is_numeric($y) ? $y + 0 : 'null') . '}';
983 $has_point = true;
984 }
985 }
986 return $has_point ? $out : false;
987 }
988
989 // X scale options for time-axis mode (globals from asset/front.js): gvnSqlChartsTimeTicks replaces the evenly
990 // spaced ticks Chart.js generates on a linear scale with the actual data dates, gvnSqlChartsTimeTick formats them
991 function guaven_sqlcharts_time_axis_scale(){
992 return "type: 'linear', offset: true, afterBuildTicks: gvnSqlChartsTimeTicks, ticks: {callback: gvnSqlChartsTimeTick, maxRotation: 45, autoSkip: true},";
993 }
994 // extra entry for the Chart.js "plugins" object in time-axis mode (tooltip title shown as a date)
995 function guaven_sqlcharts_time_axis_plugins($time_points){
996 return $time_points !== false ? 'tooltip: {callbacks: {title: gvnSqlChartsTimeTooltipTitle}}' : '';
997 }
998
999 function guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, $type = 'bar', $pid = null)
1000 {
1001 $horizontal = ($type == 'horizontalBar');
1002 $forcestack = ($type == 'stackedBar');
1003 $stacked = ($forcestack or get_post_meta($pid, 'guaven_sqlcharts_nostacked', true) != 1) ? 'true' : 'false';
1004 $time_points = $horizontal ? false : guaven_sqlcharts_time_axis_points($pid, $values);
1005 ?>
1006 var data = {
1007 <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?>
1008 datasets: [
1009 <?php
1010 $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
1011 $i=-1;
1012 foreach ($values_new as $key_ak=>$value_ak) {
1013 $i++;
1014 $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak];
1015 ?>
1016 {
1017 <?php
1018 echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1019 ?>
1020 label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>,
1021 backgroundColor: [
1022 <?php
1023 echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0, guaven_sqlcharts_colors($i, $pid)),[]);
1024 ?>
1025 ],
1026 borderColor: [
1027 <?php
1028 echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0.2, guaven_sqlcharts_colors($i, $pid)),[]);
1029 ?>
1030 ],
1031 borderWidth: 1,
1032 <?php if ($time_points !== false) echo 'barThickness: 24,'; // fixed width: on a time axis Chart.js would otherwise size bars from the closest pair of dates ?>
1033 data: [<?php
1034 echo wp_kses(implode(",", $points),[]);
1035 ?>],
1036 },
1037 <?php
1038 }
1039 ?>
1040 ]
1041 };
1042 var options={
1043 responsive: true,
1044 <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1045 <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1046 <?php if ($horizontal) echo "indexAxis: 'y',"; ?>
1047 scales: {
1048 x: {
1049 <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?>
1050 <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'y' : 'x'); ?>
1051 stacked: <?php echo esc_js($stacked); ?>,
1052 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1053 },
1054 y: {
1055 <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'x' : 'y'); ?>
1056 stacked: <?php echo esc_js($stacked); ?>,
1057 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
1058 ticks: {
1059 <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
1060 }
1061 }
1062 }
1063 <?php
1064 guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points));
1065 ?>
1066 };
1067 var myBarChart = new Chart(ctx, {
1068 type: 'bar',
1069 data: data,
1070 options: options
1071 });
1072 <?php
1073 }
1074
1075 function guaven_sqlcharts_merge_labeldata($labels){
1076 if(count($labels)==1){echo wp_kses(implode(",",$labels[0]),[]);return;}
1077 $merged=[];
1078 foreach($labels as $label){
1079 $merged=array_merge($merged,$label);
1080 }
1081 echo wp_kses(implode(",",array_unique($merged)),[]);
1082 }
1083
1084 function guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, $type = 'false', $pid = null, $charttype = 'line', $stepped = false)
1085 {
1086 $time_points = ($charttype == 'radar') ? false : guaven_sqlcharts_time_axis_points($pid, $values);
1087 ?>
1088 var data = {
1089 <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?>
1090 datasets: [
1091 <?php
1092 $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
1093 $dataset_count=count($values_new);
1094 $i=-1;
1095 foreach ($values_new as $key_ak=>$value_ak) {
1096 $i++;
1097 $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak];
1098 if ($type == 'radarfill') $fill = "'origin'";
1099 elseif ($type == 'false') $fill = 'false';
1100 else $fill = ($i == 0 and $dataset_count > 1) ? '"+1"' : '"origin"';
1101 ?>
1102 {
1103 <?php
1104 echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1105 ?>
1106 label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>,
1107 fill: <?php echo wp_kses($fill,[]);
1108 ?>,
1109 tension: 0.1,
1110 <?php if ($stepped) echo 'stepped: true,'; ?>
1111 backgroundColor: <?php
1112 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1113 ?>
1114 borderColor: <?php
1115 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1116 ?>
1117 pointBorderColor: <?php
1118 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1119 ?>
1120 pointHoverBackgroundColor: <?php
1121 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1122 ?>
1123 pointHoverBorderColor: <?php
1124 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1125 ?>
1126 data: [<?php
1127 echo wp_kses_post(implode(",", $points));
1128 ?>],
1129 spanGaps: false,
1130 },
1131 <?php
1132 }
1133 ?>
1134 ]
1135 };
1136 var myLineChart = new Chart(ctx, {
1137 type: '<?php echo esc_attr($charttype); ?>',
1138 data: data,
1139 options: {
1140 responsive: true,
1141 <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1142 <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1143 <?php if ($charttype == 'radar') { ?>
1144 scales: {
1145 r: {
1146 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>
1147 }
1148 }
1149 <?php } else { ?>
1150 scales: {
1151 x: {
1152 display: true,
1153 <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?>
1154 <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?>
1155 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1156 },
1157 y: {
1158 <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?>
1159 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
1160 ticks: {
1161 <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
1162 }
1163 }
1164 }
1165 <?php } ?>
1166 <?php
1167 guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points));
1168 ?>
1169
1170 }
1171 });
1172 <?php
1173 }
1174
1175 function guaven_sqlcharts_scatterdata($title, $labels, $values, $ylabel, $pid = null)
1176 {
1177 ?>
1178 var data = {
1179 datasets: [
1180 <?php
1181 $i=-1;
1182 foreach ($values as $key_ak=>$value_ak) {
1183 $i++;
1184 $points=array();
1185 foreach ($value_ak as $xval=>$yval) {
1186 $x = is_numeric($xval) ? $xval : '"'.esc_js($xval).'"';
1187 $y = is_numeric($yval) ? $yval : '"'.esc_js($yval).'"';
1188 $points[] = '{x:'.$x.',y:'.$y.'}';
1189 }
1190 ?>
1191 {
1192 <?php
1193 echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1194 ?>
1195 label: <?php echo guaven_sqlcharts_js_label(isset($ylabel[$key_ak])?$ylabel[$key_ak]:''); ?>,
1196 backgroundColor: <?php
1197 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1198 ?>
1199 borderColor: <?php
1200 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1201 ?>
1202 data: [<?php echo wp_kses(implode(",", $points),[]); ?>],
1203 },
1204 <?php
1205 }
1206 ?>
1207 ]
1208 };
1209 var myScatterChart = new Chart(ctx, {
1210 type: 'scatter',
1211 data: data,
1212 options: {
1213 responsive: true,
1214 <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1215 <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1216 scales: {
1217 x: {
1218 <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?>
1219 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1220 },
1221 y: {
1222 <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?>
1223 beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
1224 ticks: {
1225 <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
1226 }
1227 }
1228 }
1229 <?php
1230 guaven_sqlcharts_maybe_additional_parameters($pid);
1231 ?>
1232 }
1233 });
1234 <?php
1235 }
1236
1237
1238 function guaven_sqlcharts_maybe_additional_parameters($pid, $extra_plugins = ''){
1239 if(function_exists('guaven_sqlcharts_maybe_additional_parameters_custom')){
1240 wp_kses(guaven_sqlcharts_maybe_additional_parameters_custom($pid),[]);
1241 return;
1242 }
1243 $guaven_sqlcharts_legend_position=get_post_meta($pid, 'guaven_sqlcharts_legend_position', true);
1244 if(in_array($guaven_sqlcharts_legend_position,['top','bottom','left','right'])){
1245 $display='true';$position=$guaven_sqlcharts_legend_position;
1246 }
1247 else {
1248 $display='false';$position='top';
1249 }
1250 echo wp_kses( ",plugins: {legend: {display: ".$display.",position:'".$position."'}".($extra_plugins !== '' ? ','.$extra_plugins : '')."}",[]);
1251 }
1252
1253
1254
1255
1256 function guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, $type = 'pie')
1257 {
1258 ?>
1259 var options={
1260 <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1261 responsive: true
1262 <?php echo get_post_meta($pid,'guaven_sqlcharts_chartheight',true)!=''||!empty($GLOBALS["guaven_sqlcharts_atts"]['height'])?',maintainAspectRatio: false':''; ?>
1263 <?php
1264 guaven_sqlcharts_maybe_additional_parameters($pid);
1265 ?>
1266 };
1267 var data = {
1268 labels: [ <?php guaven_sqlcharts_merge_labeldata($labels);?>],
1269 datasets: [
1270 <?php
1271 for ($i = 0; $i < count($values); $i++) {
1272 ?>
1273 {
1274 <?php
1275 echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1276 ?>
1277 data: [<?php
1278 echo wp_kses(implode(",", $values[$i]),[]);
1279 ?>],
1280 backgroundColor: [
1281 <?php
1282 $ii=0;
1283 foreach($values[$i] as $vci=>$valuecolor){
1284 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 0, -0.1, guaven_sqlcharts_colors($ii, $pid)));
1285 $ii++;
1286 }
1287 ?>
1288 ],
1289 hoverBackgroundColor: [
1290 <?php
1291 $ii=0;
1292 foreach($values[$i] as $vci=>$valuecolor){
1293 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 0, 0.2, guaven_sqlcharts_colors($ii, $pid)));
1294 $ii++;
1295 }
1296 ?>
1297 ]
1298 },
1299 <?php
1300 }
1301 ?>
1302 ]
1303 };
1304 var myPieChart = new Chart(ctx,{
1305 type: '<?php
1306 echo esc_attr($type);
1307 ?>',
1308 data: data,
1309 options: options
1310 });
1311 <?php
1312 }
1313
1314
1315
1316
1317 function guaven_sqlcharts_colorgenerator($count, $indic, $darkness = 0, $initcolor = '255,0,0')
1318 {
1319 if (strpos($initcolor,'#')===0) {
1320 $split = str_split(substr($initcolor,1), 2);
1321 $r = hexdec($split[0]);
1322 $g = hexdec($split[1]);
1323 $b = hexdec($split[2]);
1324 $ret='';
1325 for ($i = 0; $i < $count; $i++) {
1326 $ret .= "'rgba(" . $r . ", " . $g . ", " . $b . ",".($darkness + 0.8 - $indic * $i * 0.8 / ($count)).")',
1327 ";
1328 }
1329 return $ret;
1330 }
1331 $initial_colors = array(
1332 'linebg' => 'red',
1333 'linebr' => 'yellow',
1334 'linebc' => 'green',
1335 'linehbg' => 'white',
1336 'linehbc' => 'black'
1337 );
1338 if (!empty($initial_colors[$count]))
1339 return '"' . $initial_colors[$count] . '",
1340 ';
1341 $ret = '';
1342 for ($i = 0; $i < $count; $i++) {
1343 $ret .= "'rgba(" . $initcolor . "," . ($darkness + 0.8 - $indic * $i * 0.8 / ($count)) . ")',
1344 ";
1345 }
1346 return $ret;
1347 }
1348
1349 function guaven_sqlcharts_tablepart($title, $labels, $values, $ylabel,$xlabel){
1350 $tabledata='';
1351 $fcol=[];$scol=[];
1352 $empty_cell=apply_filters( 'guaven_sqlcharts_table_empty_cell','<td></td>');
1353 $tablein='';
1354 foreach($values as $row=>$valuerow){
1355 foreach ($valuerow as $key => $value) {
1356 $putval=$labels[$row][$key]??'';
1357 $fcol[$key]='<td>'.str_replace('"',"",$putval).'</td>';
1358 $scol[$key][$row]='<td>'.$value.'</td>';
1359 }
1360 foreach($scol as $scolkey=>$scolvalue){
1361 for($i=0;$i<count($values);$i++){
1362 //echo $i;
1363 if(!isset($scolvalue[$i]))$scol[$scolkey][$i]=$empty_cell;;
1364 }
1365 ksort($scol[$scolkey]);
1366 }
1367 }
1368
1369 foreach($fcol as $key=>$value){
1370 $tablein.='<tr>'.$value.implode(" ",$scol[$key]).'</tr>'.PHP_EOL;
1371 }
1372 $tabledata.='<div class="gvn-tablewrap"><table class="gvn-table"><tr><th>'.$xlabel[0].'</th><th>'.implode("</th><th>",$ylabel).'</th></tr>
1373 '.$tablein.'</table></div><br>';
1374
1375 echo wp_kses_post($tabledata);
1376
1377 }
1378
1379 function guaven_sqlcharts_graphtype($post){
1380 if (strpos(get_post_meta($post->ID, 'guaven_sqlcharts_graphtype', true), "_l") !== false)
1381 $postfix = '_2';
1382 else $postfix = '';
1383 return $postfix;
1384 }
1385
1386 add_filter('the_content',function($content){
1387 if(!is_singular('gvn_schart'))return $content;
1388 global $post;
1389 $postfix=guaven_sqlcharts_graphtype($post);
1390 return '[gvn_schart'.$postfix.' id="'.$post->ID.'"'.
1391 (get_post_meta($post->ID,'guaven_sqlcharts_tablepart',true)!=''?' table="1"':'')
1392 .']';
1393 });
1394
1395 function guaven_sqlcharts_key_normalizer($values,$labels,$ylabel){
1396 $normalize_keys=[];
1397 $empty_value=apply_filters( 'guaven_sqlcharts_table_empty_value','');
1398 foreach ($values as $key_ak=>$value_ak) {
1399 $normalize_keys=array_merge($normalize_keys,array_keys($values[$key_ak]));
1400 }
1401 $values_normalized=[];$labels_normalized=[];$ylabel_normalized=[];
1402 foreach($normalize_keys as $normalized_key){
1403 foreach ($values as $key_ak=>$value_ak) {
1404 $values_normalized[$key_ak][$normalized_key]=isset( $values[$key_ak][$normalized_key])? $values[$key_ak][$normalized_key]:"'".$empty_value."'";
1405 $labels_normalized[$key_ak][$normalized_key]=isset( $labels[$key_ak][$normalized_key])? $labels[$key_ak][$normalized_key]:"''";
1406 $ylabel_normalized[$key_ak][$normalized_key]=isset( $ylabel[$key_ak][$normalized_key])? $ylabel[$key_ak][$normalized_key]:"";
1407 }
1408 }
1409 return [$values_normalized,$labels_normalized,$ylabel_normalized];
1410 }
1411
1412
1413 add_filter('guaven_sqlcharts_table_empty_cell',function($str){return '<td>#</td>';});
1414 add_filter('guaven_sqlcharts_table_empty_value',function($str){return 'N/A';});
1415