PluginProbe
SQL Chart Builder / 3.0.6
SQL Chart Builder v3.0.6
3.0.6 3.0.5 3.0.4 3.0.3 3.0.2 3.0.1 trunk 1.0.2 1.0.3 2.2.2 2.3.0 2.3.1 2.3.2 2.3.3 2.3.4 2.3.5 2.3.6 2.3.7 2.3.7.1 2.3.7.2 2.3.8 3.0.0
← All changes | functions.php +679 -199 2.3.7.13.0.6 View file →
@@ -31,9 +31,9 @@
31 31 <tbody><tr><td style="width: auto;vertical-align: top;padding: 20px;">
32 32 <h2>WooCommerce Search Engine – INSTANT, RELEVANT AND SMART Search Box</h2>
33 33 <h3>Turn your website search into Smart Search which find products by price, SKU, attributes, meta data, categorys, tags etc. </h3>
34 34 <p>“WooCommerce Search Engine” is a very powerful and easy to use WooCommerce Search Plugin which turns a simple search box of your WooCommerce Store to the powerful multifunctional magic box which helps you to sell more products. The plugin UI is compatible with ALL THEMES.</p>
35 - <a target="_blank" style="border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;" class="button button-secondary"
35 + <a target="_blank" style="border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;" class="button button-secondary"
36 36 href="https://codecanyon.net/item/woocommerce-search-box/15685698">Get the Search Box </a>
37 37 </td><td style="position:relative">
38 38 <a href="'.admin_url().'/edit.php?post_type=gvn_schart&gvnsql_dismiss_recommendation=1'.'" style="position: absolute;right: 0;top: -15px;right: -10px;">{svg}
39 39 </a>
@@ -47,11 +47,11 @@
47 47 {
48 48 global $post;
49 49
50 50
51 - if(
51 + if(
52 52 (!empty($_SERVER["REQUEST_URI"]) and strpos(sanitize_text_field(wp_unslash($_SERVER["REQUEST_URI"])),'post_type=gvn_schart')!==false)
53 - or
53 + or
54 54 (!empty($post) and $post->post_type == 'gvn_schart')
55 55 ){
56 56 echo str_replace('{svg}','<svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="11" height="14" viewBox="0 0 11 14">
57 57 <path d="M10.141 10.328q0 0.312-0.219 0.531l-1.062 1.062q-0.219 0.219-0.531 0.219t-0.531-0.219l-2.297-2.297-2.297 2.297q-0.219 0.219-0.531 0.219t-0.531-0.219l-1.062-1.062q-0.219-0.219-0.219-0.531t0.219-0.531l2.297-2.297-2.297-2.297q-0.219-0.219-0.219-0.531t0.219-0.531l1.062-1.062q0.219-0.219 0.531-0.219t0.531 0.219l2.297 2.297 2.297-2.297q0.219-0.219 0.531-0.219t0.531 0.219l1.062 1.062q0.219 0.219 0.219 0.531t-0.219 0.531l-2.297 2.297 2.297 2.297q0.219 0.219 0.219 0.531z"></path>
@@ -56,11 +56,11 @@
56 56 echo str_replace('{svg}','<svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="11" height="14" viewBox="0 0 11 14">
57 57 <path d="M10.141 10.328q0 0.312-0.219 0.531l-1.062 1.062q-0.219 0.219-0.531 0.219t-0.531-0.219l-2.297-2.297-2.297 2.297q-0.219 0.219-0.531 0.219t-0.531-0.219l-1.062-1.062q-0.219-0.219-0.219-0.531t0.219-0.531l2.297-2.297-2.297-2.297q-0.219-0.219-0.219-0.531t0.219-0.531l1.062-1.062q0.219-0.219 0.531-0.219t0.531 0.219l2.297 2.297 2.297-2.297q0.219-0.219 0.531-0.219t0.531 0.219l1.062 1.062q0.219 0.219 0.219 0.531t-0.219 0.531l-2.297 2.297 2.297 2.297q0.219 0.219 0.219 0.531z"></path>
58 58 </svg>',wp_kses_post(guaven_sqlcharts_recommended(),[]));
59 59 }
60 -
61 60
62 61
62 +
63 63 if (!empty($post) and $post->post_type == 'gvn_schart'):
64 64 if (!current_user_can('manage_options')) {
65 65 echo '<br><br>
66 66 <div class="updated gf-alert gf-alert-danger">Only administrators can manage this page</div>';
@@ -67,30 +67,30 @@
67 67 die();
68 68 }
69 69 echo '<div class="updated gf-alert gf-alert-info">';
70 70 if (empty($_GET["post"]) && strpos(sanitize_text_field(wp_unslash($_SERVER["REQUEST_URI"])), "post-new") === false) {
71 - $gf_message = __(
71 + $gf_message = __(
72 72 'Use <b>Add new</b> button above to create a new SQL report. And click on any existing rule names below to manage them.',
73 - 'guaven_sqlcharts'
73 + 'guaven_sqlcharts'
74 74 );
75 75 } else {
76 76 $gf_message = __(
77 77 '1. Give any name to your report.<br>
78 - 2. Choose chart type, type SQL query, enter field names, labels, and then press Publish/Update.<br>
79 - 3. After update, you will see the name and the demo of the needed shortcode at the bottom of this admin page. You can use that shortcode anywhere in your website: in pages, posts, widgets, etc.',
78 + 2. Pick a chart type, build your SQL query with the visual builder (or type it — autocomplete will help), map the X/Y columns and press Publish/Update.<br>
79 + 3. After update, you will see the shortcode of this chart at the bottom of the page. You can use that shortcode anywhere in your website: in pages, posts, widgets, etc.',
80 80 'guaven_sqlcharts'
81 81 );
82 82 }
83 -
83 +
84 84 echo '<div style="float:left;max-width:calc(100% - 345px)">';
85 85 echo wp_kses_post( $gf_message );
86 86 echo '</div>';
87 -
87 +
88 88 echo '<div style="float: right;
89 89 margin-top: 0px;
90 90 padding-top: 0px;"><a target="_blank" style="text-align:center;border:0px solid #6200ee;border-radius:0px;color:white;font-weight:bold;background: #6200ee;"
91 91 class="button button-secondary" href="https://guaven.com/contact/solution-request/">Get Premium Support </a>
92 - <span style="line-height: 30px;padding: 0 5px;">OR</span>
92 + <span style="line-height: 30px;padding: 0 5px;">OR</span>
93 93 <a target="_blank" style="text-align:center;border:0px solid #26b286;border-radius:0px;color:white;font-weight:bold;background: #26b286;"
94 94 class="button button-secondary" href="https://guaven.com/service/small-thankyou-premium-support-service/">Make a Small Donation</a>
95 95 </div> </div>';
96 96 endif;
@@ -110,13 +110,14 @@
110 110 add_action('admin_notices', 'guaven_sqlcharts_onboarding_notice');
111 111
112 112 function guaven_sqlcharts_onboarding_notice_dismissed(){
113 113 check_ajax_referer('notice_dismissed', 'nonce');
114 + if (!current_user_can('manage_options')) return;
114 115
115 116 if(empty($_POST['type']))return;
116 117 switch ($_POST['type']){
117 118 case 'onboarding_notice':
118 - update_option('guaven_sqlcharts_onboarding_notice_dismissed', 1);
119 + update_option('guaven_sqlcharts_onboarding_notice_dismissed', 1);
119 120 break;
120 121 }
121 122 }
122 123 add_action('wp_ajax_guaven_sqlcharts_onboarding_notice_dismissed', 'guaven_sqlcharts_onboarding_notice_dismissed');
@@ -121,11 +122,13 @@
121 122 }
122 123 add_action('wp_ajax_guaven_sqlcharts_onboarding_notice_dismissed', 'guaven_sqlcharts_onboarding_notice_dismissed');
123 124
124 125 function guaven_sqlcharts_enqueue_chart()
125 -{
126 - wp_enqueue_script('guaven_sqlcharts_chartjs', plugins_url('asset/bundle.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
127 - wp_localize_script('guaven_sqlcharts_chartjs', 'guaven_sqlcharts_notice_dismissed', array(
126 +{
127 + wp_enqueue_script('guaven_sqlcharts_chartjs', plugins_url('asset/chart.umd.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
128 + wp_enqueue_script('guaven_sqlcharts_datepicker', plugins_url('asset/datepicker.min.js', __FILE__),array('jquery'),GVNSQLCHARTS_VERSION,false);
129 + wp_enqueue_script('guaven_sqlcharts_front', plugins_url('asset/front.js', __FILE__),array('jquery','guaven_sqlcharts_chartjs','guaven_sqlcharts_datepicker'),GVNSQLCHARTS_VERSION,false);
130 + wp_localize_script('guaven_sqlcharts_front', 'guaven_sqlcharts_notice_dismissed', array(
128 131 'action' => 'guaven_sqlcharts_onboarding_notice_dismissed',
129 132 'nonce' => wp_create_nonce('notice_dismissed')
130 133 ));
131 134
@@ -139,9 +142,52 @@
139 142 }
140 143 add_action('wp_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
141 144 add_action('admin_enqueue_scripts', 'guaven_sqlcharts_enqueue_main_style');
142 145
146 +// admin-only assets: SQL builder, autocomplete, new metabox UI
147 +function guaven_sqlcharts_admin_assets($hook)
148 +{
149 + if (!in_array($hook, array('post.php', 'post-new.php'))) return;
150 + $screen = function_exists('get_current_screen') ? get_current_screen() : null;
151 + if (empty($screen->post_type) or $screen->post_type != 'gvn_schart') return;
152 + if (!current_user_can('manage_options')) return;
143 153
154 + wp_enqueue_style('guaven_sqlcharts_admin_style', plugins_url('asset/admin.css', __FILE__), array(), GVNSQLCHARTS_VERSION);
155 + wp_enqueue_script('guaven_sqlcharts_admin', plugins_url('asset/admin.js', __FILE__), array('jquery'), GVNSQLCHARTS_VERSION, true);
156 +
157 + global $wpdb;
158 + $tables = $wpdb->get_col('SHOW TABLES');
159 + if (!is_array($tables)) $tables = array();
160 + wp_localize_script('guaven_sqlcharts_admin', 'gvnSqlBuilder', array(
161 + 'ajaxurl' => admin_url('admin-ajax.php'),
162 + 'nonce' => wp_create_nonce('gvnsql_schema'),
163 + 'tables' => array_values($tables),
164 + 'prefix' => $wpdb->prefix,
165 + ));
166 +}
167 +add_action('admin_enqueue_scripts', 'guaven_sqlcharts_admin_assets');
168 +
169 +// returns column names of one table for the live SQL builder/autocomplete
170 +function guaven_sqlcharts_ajax_columns()
171 +{
172 + check_ajax_referer('gvnsql_schema', 'nonce');
173 + if (!current_user_can('manage_options')) wp_send_json_error('forbidden', 403);
174 + global $wpdb;
175 + $table = isset($_POST['table']) ? sanitize_text_field(wp_unslash($_POST['table'])) : '';
176 + $tables = $wpdb->get_col('SHOW TABLES');
177 + if (!is_array($tables) or !in_array($table, $tables, true)) wp_send_json_error('unknown table', 400);
178 + $cols = $wpdb->get_results('SHOW COLUMNS FROM `' . str_replace('`', '', $table) . '`');
179 + $out = array();
180 + if (is_array($cols)) {
181 + foreach ($cols as $col) {
182 + $out[] = array('name' => $col->Field, 'type' => $col->Type);
183 + }
184 + }
185 + wp_send_json_success($out);
186 +}
187 +add_action('wp_ajax_gvnsql_get_columns', 'guaven_sqlcharts_ajax_columns');
188 +
189 +
144 190 function guaven_sqlcharts_isJson($string)
145 191 {
146 192 json_decode($string);
147 193 return (json_last_error() == JSON_ERROR_NONE);
@@ -149,17 +195,61 @@
149 195
150 196 add_action('init', 'guaven_sqlcharts_register_post');
151 197 function guaven_sqlcharts_register_post()
152 198 {
153 - //register_taxonomy('guaven_update_push_tag', 'termin');
154 199 register_post_type('gvn_schart', array(
155 200 'labels' => array(
156 201 'name' => __('My SQL Charts','guaven_sqlcharts'),
157 - 'singular_name' => __('My SQL chart','guaven_sqlcharts')
202 + 'singular_name' => __('SQL Chart','guaven_sqlcharts'),
203 + 'menu_name' => __('My SQL Charts','guaven_sqlcharts'),
204 + 'add_new' => __('Add Chart','guaven_sqlcharts'),
205 + 'add_new_item' => __('Add New Chart','guaven_sqlcharts'),
206 + 'edit_item' => __('Edit Chart','guaven_sqlcharts'),
207 + 'new_item' => __('New Chart','guaven_sqlcharts'),
208 + 'view_item' => __('View Chart','guaven_sqlcharts'),
209 + 'view_items' => __('View Charts','guaven_sqlcharts'),
210 + 'search_items' => __('Search Charts','guaven_sqlcharts'),
211 + 'not_found' => __('No charts found','guaven_sqlcharts'),
212 + 'not_found_in_trash' => __('No charts found in Trash','guaven_sqlcharts'),
213 + 'all_items' => __('All Charts','guaven_sqlcharts'),
214 + 'archives' => __('Chart Archives','guaven_sqlcharts'),
215 + 'attributes' => __('Chart Attributes','guaven_sqlcharts'),
216 + 'insert_into_item' => __('Insert into chart','guaven_sqlcharts'),
217 + 'uploaded_to_this_item' => __('Uploaded to this chart','guaven_sqlcharts'),
218 + 'filter_items_list' => __('Filter charts list','guaven_sqlcharts'),
219 + 'items_list_navigation' => __('Charts list navigation','guaven_sqlcharts'),
220 + 'items_list' => __('Charts list','guaven_sqlcharts'),
221 + 'item_published' => __('Chart published.','guaven_sqlcharts'),
222 + 'item_published_privately' => __('Chart published privately.','guaven_sqlcharts'),
223 + 'item_reverted_to_draft' => __('Chart reverted to draft.','guaven_sqlcharts'),
224 + 'item_scheduled' => __('Chart scheduled.','guaven_sqlcharts'),
225 + 'item_updated' => __('Chart updated.','guaven_sqlcharts'),
158 226 ),
159 227
160 228 'public' => true,
161 - //'taxonomies' => array('guaven_update_push_tag'),
229 + 'show_in_rest' => false,
230 + 'menu_icon' => 'dashicons-chart-pie',
231 + // Charts execute SQL, so every primitive capability of this post type maps to manage_options.
232 + // Contributors/Authors cannot create, edit, publish or delete charts through any WordPress
233 + // entry point (admin UI, XML-RPC, REST). Published charts stay viewable on the front end.
234 + // Only primitive capabilities are remapped: mapping the meta capabilities edit_post/read_post/
235 + // delete_post to manage_options would make WordPress treat manage_options itself as a meta
236 + // capability and break that check site-wide.
237 + 'capability_type' => 'post',
238 + 'map_meta_cap' => true,
239 + 'capabilities' => array(
240 + 'edit_posts' => 'manage_options',
241 + 'edit_others_posts' => 'manage_options',
242 + 'edit_published_posts' => 'manage_options',
243 + 'edit_private_posts' => 'manage_options',
244 + 'publish_posts' => 'manage_options',
245 + 'read_private_posts' => 'manage_options',
246 + 'delete_posts' => 'manage_options',
247 + 'delete_private_posts' => 'manage_options',
248 + 'delete_published_posts' => 'manage_options',
249 + 'delete_others_posts' => 'manage_options',
250 + 'create_posts' => 'manage_options',
251 + ),
162 252 'supports' => array(
163 253 'title',
164 254 'postmeta'
165 255 ),
@@ -168,8 +258,20 @@
168 258
169 259 guaven_sqlcharts_load_defaults();
170 260 }
171 261
262 +// All guaven_sqlcharts_* meta keys are protected: they cannot be written through the Custom Fields box,
263 +// XML-RPC or the REST API. The plugin's own save handler (update_post_meta) is not affected.
264 +add_filter('is_protected_meta', function ($protected, $meta_key) {
265 + return strpos((string) $meta_key, 'guaven_sqlcharts_') === 0 ? true : $protected;
266 +}, 10, 2);
267 +
268 +// "Add title" placeholder on the chart edit screen
269 +add_filter('enter_title_here', function ($title, $post) {
270 + if (!empty($post) and $post->post_type == 'gvn_schart') return __('Chart name', 'guaven_sqlcharts');
271 + return $title;
272 +}, 10, 2);
273 +
172 274 add_action('admin_footer', 'guaven_sqlcharts_admin_front');
173 275
174 276
175 277 function guaven_sqlcharts_admin_front()
@@ -184,9 +286,9 @@
184 286
185 287 // metabox for editor
186 288 function guaven_sqlcharts_metabox_area()
187 289 {
188 - add_meta_box('guaven_sqlcharts_metabox', 'Configure your graph chart', 'guaven_sqlcharts_metabox', 'gvn_schart', 'advanced', 'default');
290 + add_meta_box('guaven_sqlcharts_metabox', 'Chart Builder', 'guaven_sqlcharts_metabox', 'gvn_schart', 'advanced', 'default');
189 291 }
190 292
191 293 function guaven_sqlcharts_metabox()
192 294 {
@@ -192,25 +294,127 @@
192 294 {
193 295 require_once(dirname(__FILE__) . "/admin_metabox.php");
194 296 }
195 297
298 +/**
299 + * Catalog of all supported chart types: label, group, per-type usage guide and example query.
300 + * Used by the admin UI to render the type cards and the contextual guides.
301 + */
302 +function guaven_sqlcharts_type_catalog()
303 +{
304 + global $wpdb;
305 + $p = $wpdb->posts;
306 + $u = $wpdb->users;
307 + return array(
308 + 'pie_l' => array(
309 + 'label' => 'Pie',
310 + 'group' => 'Circular',
311 + 'guide' => 'Best for showing how a total splits into a few parts (shares/percentages). Use one query that returns a label column (X) and a numeric value column (Y). Keep it under ~8 slices for readability.',
312 + 'example_sql' => "select count(*) postcount, SUBSTR(post_date,1,4) yearnum from $p group by yearnum order by yearnum asc limit 10",
313 + 'example_x' => 'yearnum', 'example_y' => 'postcount',
314 + ),
315 + 'donut_l' => array(
316 + 'label' => 'Doughnut',
317 + 'group' => 'Circular',
318 + 'guide' => 'Same as Pie but with a hole in the middle — slightly easier to compare slice sizes. One query: label column (X) + numeric column (Y).',
319 + 'example_sql' => "select count(*) postcount, post_type from $p group by post_type order by postcount desc limit 8",
320 + 'example_x' => 'post_type', 'example_y' => 'postcount',
321 + ),
322 + 'polar_l' => array(
323 + 'label' => 'Polar Area',
324 + 'group' => 'Circular',
325 + 'guide' => 'Like a pie, but every slice has the same angle and the value controls the radius. Good for cyclic data (months, weekdays). One query: label (X) + numeric value (Y).',
326 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,6,2) monthnum from $p group by monthnum order by monthnum",
327 + 'example_x' => 'monthnum', 'example_y' => 'postcount',
328 + ),
329 + 'radar_l' => array(
330 + 'label' => 'Radar',
331 + 'group' => 'Circular',
332 + 'guide' => 'Compares one or more series across several categories arranged in a circle. Great for profiles/ratings. Use one query per series, separated with ";".',
333 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,6,2) monthnum from $p where post_type=\"post\" group by monthnum order by monthnum",
334 + 'example_x' => 'monthnum', 'example_y' => 'postcount',
335 + ),
336 + 'line_l' => array(
337 + 'label' => 'Line',
338 + 'group' => 'Line',
339 + 'guide' => 'The classic choice for trends over time (per day/month/year). X should be an ordered value like a date. Add more queries separated with ";" for comparison lines.',
340 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p group by monthandyear order by monthandyear",
341 + 'example_x' => 'monthandyear', 'example_y' => 'postcount',
342 + ),
343 + 'area_l' => array(
344 + 'label' => 'Area',
345 + 'group' => 'Line',
346 + 'guide' => 'A line chart with the region under the line filled — emphasizes volume/magnitude of a trend. Works well with 2 queries (";" separated) to compare filled regions.',
347 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p where post_type=\"post\" group by monthandyear order by monthandyear;\nselect count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p where post_type!=\"post\" group by monthandyear order by monthandyear",
348 + 'example_x' => 'monthandyear', 'example_y' => 'Posts;Other content',
349 + ),
350 + 'steppedline_l' => array(
351 + 'label' => 'Stepped Line',
352 + 'group' => 'Line',
353 + 'guide' => 'Line chart that moves in steps instead of slopes — perfect for values that change at discrete moments (prices, stock level, settings history).',
354 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p group by yearnum order by yearnum",
355 + 'example_x' => 'yearnum', 'example_y' => 'postcount',
356 + ),
357 + 'bar_l' => array(
358 + 'label' => 'Bar',
359 + 'group' => 'Bar',
360 + 'guide' => 'Compares values across categories with vertical bars. One query: category (X) + numeric value (Y). Multiple ";" separated queries become grouped/stacked bars.',
361 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,7) monthandyear from $p group by monthandyear order by monthandyear",
362 + 'example_x' => 'monthandyear', 'example_y' => 'postcount',
363 + ),
364 + 'horizontalbar_l' => array(
365 + 'label' => 'Horizontal Bar',
366 + 'group' => 'Bar',
367 + 'guide' => 'Bar chart rotated 90° — the best pick when category names are long (user names, product titles).',
368 + 'example_sql' => "select count(*) as postcount, b.display_name as dname from $p a inner join $u b ON a.post_author=b.ID where a.post_status=\"publish\" group by a.post_author order by postcount desc limit 10",
369 + 'example_x' => 'dname', 'example_y' => 'postcount',
370 + ),
371 + 'stackedbar_l' => array(
372 + 'label' => 'Stacked Bar',
373 + 'group' => 'Bar',
374 + 'guide' => 'Shows how each category total is composed of parts. Use 2+ queries separated with ";" — each query becomes one segment color of the stack.',
375 + 'example_sql' => "select count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p where post_type=\"post\" group by yearnum order by yearnum;\nselect count(*) postcount, SUBSTRING(post_date,1,4) yearnum from $p where post_type!=\"post\" group by yearnum order by yearnum",
376 + 'example_x' => 'yearnum', 'example_y' => 'Posts;Other content',
377 + ),
378 + 'scatter_l' => array(
379 + 'label' => 'Scatter',
380 + 'group' => 'Other',
381 + 'guide' => 'Plots points on numeric X/Y axes to reveal correlation between two numbers. Both X and Y columns must be numeric (e.g. comment_count vs menu_order).',
382 + 'example_sql' => "select comment_count ccount, ID from $p where post_status=\"publish\" order by ID limit 100",
383 + 'example_x' => 'ID', 'example_y' => 'ccount',
384 + ),
385 + );
386 +}
387 +
388 +/**
389 + * Maps deprecated Google-Chart era type slugs to their Chart.js equivalents.
390 + * Old charts keep working without any manual migration; when the post is re-saved
391 + * from the new UI the normalized value is stored automatically.
392 + */
393 +function guaven_sqlcharts_normalize_type($type)
394 +{
395 + $map = array(
396 + 'pie' => 'pie_l',
397 + '3dpie' => 'pie_l',
398 + 'column' => 'bar_l',
399 + 'bar' => 'horizontalbar_l',
400 + 'area' => 'area_l',
401 + );
402 + return isset($map[$type]) ? $map[$type] : $type;
403 +}
404 +
196 405 function guaven_gutenberg_wrapper($atts){
197 406 if(isset($atts['sqlcharts_inserted_script'])){
198 407 global $sqlcharts_inserted_script;
199 408 $sqlcharts_inserted_script = $atts['sqlcharts_inserted_script'];
200 409 }
201 -
202 - // if( isset($_GET["post_id"],$_GET["context"]) and $_GET["context"]=='edit'
203 - // and strpos($_SERVER["REQUEST_URI"],'block-renderer/guaven-sqlcharts/gvn-chart-gutenberg')!==false
204 - // ){
205 - // $atts['chart_id']=$_GET["post_id"];
206 - // }
410 +
207 411 $post = get_post($atts['chart_id']);
208 412 if( ! isset($atts['chart_id']) or !isset($post) or $post->post_type != 'gvn_schart'){
209 -
413 +
210 414 return "Invalid id";
211 415 }
212 -
416 +
213 417 return guaven_sqlcharts_local_shortcode(array('id' => $atts['chart_id'])); // temporary explicit value
214 418 }
215 419 function guaven_register_gutenberg_blocks()
216 420 {
@@ -223,9 +427,9 @@
223 427 );
224 428 wp_localize_script('gvn_gutenberg_charts', 'guaven', array(
225 429 'description' => 'Add My SQL Chart to your post',
226 430 ));
227 -
431 +
228 432 register_block_type( 'guaven-sqlcharts/gvn-chart-gutenberg', array(
229 433 'editor_script' => 'gvn_gutenberg_charts',
230 434 'render_callback' => 'guaven_gutenberg_wrapper',
231 435 'attributes' => array(
@@ -248,8 +452,11 @@
248 452 {
249 453 if (!isset($_POST['meta_box_nonce_field']) or !wp_verify_nonce($_POST['meta_box_nonce_field'], 'meta_box_nonce_action')) {
250 454 return $post->ID;
251 455 }
456 + if ($post->post_type != 'gvn_schart' or !current_user_can('manage_options') or (defined('DOING_AUTOSAVE') and DOING_AUTOSAVE)) {
457 + return $post->ID;
458 + }
252 459 $fields = array(
253 460 "guaven_sqlcharts_chartheight",
254 461 "guaven_sqlcharts_chartwidth",
255 462 "guaven_sqlcharts_graphtype",
@@ -269,9 +476,10 @@
269 476 "guaven_sqlcharts_begin_with_0_y",
270 477 "guaven_sqlcharts_round_y_values",
271 478 "guaven_sqlcharts_legend_position",
272 479 "guaven_sqlcharts_nostacked",
273 - "guaven_sqlcharts_forcetooltips"
480 + "guaven_sqlcharts_forcetooltips",
481 + "guaven_sqlcharts_timeaxis"
274 482 );
275 483 foreach ($fields as $key => $value) {
276 484 if(isset($_POST[$value]))$newval=esc_attr($_POST[$value]);
277 485 else $newval='';
@@ -281,31 +489,80 @@
281 489 if(!empty($_POST["guaven_sqlcharts_dbpass"])){
282 490 $encpass=guaven_sqlcharts_encrypt_decrypt('encrypt',$_POST["guaven_sqlcharts_dbpass"]);
283 491 update_post_meta($post->ID, 'guaven_sqlcharts_dbpass', ['encrypted',$encpass]);
284 492 }
285 - update_post_meta($post->ID, 'guaven_sqlcharts_code', esc_attr(str_replace("'",'"',stripslashes($_POST['guaven_sqlcharts_code']))) );
493 + // Store the SQL as typed. Do not HTML-encode it and do not rewrite quotes:
494 + // the editor escapes it on output and the front end decodes entities before running it.
495 + $sql_code = isset($_POST['guaven_sqlcharts_code']) ? wp_check_invalid_utf8(wp_unslash($_POST['guaven_sqlcharts_code'])) : '';
496 + update_post_meta($post->ID, 'guaven_sqlcharts_code', $sql_code);
497 + // Flag that this chart stores raw SQL. Charts without the flag were saved by
498 + // versions before 3.0.1, which HTML-encoded the query, and still need decoding.
499 + update_post_meta($post->ID, 'guaven_sqlcharts_code_raw', 1);
286 500 }
501 +
502 +// Returns the stored SQL query exactly as the user typed it.
503 +function guaven_sqlcharts_get_code($post_id)
504 +{
505 + $sql = get_post_meta($post_id, 'guaven_sqlcharts_code', true);
506 + if (get_post_meta($post_id, 'guaven_sqlcharts_code_raw', true) != 1) {
507 + $sql = html_entity_decode($sql, ENT_QUOTES, 'UTF-8');
508 + }
509 + return $sql;
510 +}
287 511 add_action('save_post', 'guaven_sqlcharts_save_metabox_area', 1, 2);
288 512 // save the custom fields
289 513
290 514
291 515
516 +// Removes string literals (contents only), backtick identifiers and comments from SQL so keyword checks
517 +// see the same code MySQL will execute. "/*!" and "/*+" comments are executable in MySQL and are kept.
518 +function guaven_sqlcharts_strip_sql_literals($sql)
519 +{
520 + $out = ''; $len = strlen($sql); $i = 0;
521 + while ($i < $len) {
522 + $c = $sql[$i];
523 + if ($c === "'" or $c === '"' or $c === '`') {
524 + $out .= $c . $c; $i++;
525 + while ($i < $len) {
526 + if ($sql[$i] === '\\' and $c !== '`') { $i += 2; continue; }
527 + if ($sql[$i] === $c) { if ($i + 1 < $len and $sql[$i + 1] === $c) { $i += 2; continue; } $i++; break; }
528 + $i++;
529 + }
530 + continue;
531 + }
532 + if ($c === '#' or ($c === '-' and substr($sql, $i, 2) === '--' and ($i + 2 >= $len or ctype_space($sql[$i + 2])))) {
533 + $nl = strpos($sql, "\n", $i); $i = ($nl === false) ? $len : $nl; continue;
534 + }
535 + if ($c === '/' and substr($sql, $i, 2) === '/*' and !in_array(substr($sql, $i + 2, 1), array('!', '+'), true)) {
536 + $close = strpos($sql, '*/', $i + 2); $i = ($close === false) ? $len : $close + 2; $out .= ' '; continue;
537 + }
538 + $out .= $c; $i++;
539 + }
540 + return $out;
541 +}
542 +
543 +// Returns 1 when the (fully substituted) SQL must not run, 0 when it is a read-only query.
544 +// Called after every {tag}/{argN} replacement so user-supplied values are covered too.
292 545 function gvn_chart_check_sql_query($sql)
293 546 {
294 - $blacklister = array(
295 - "delete",
296 - "update",
297 - "insert",
298 - "drop",
299 - "truncate",
300 - "alter"
301 - ); //add all
302 - $blacklister_f = 0;
303 - foreach ($blacklister as $key => $value) {
304 - if (strpos($sql, $value) !== false)
305 - $blacklister_f = 1;
547 + // 1) data-changing statements: checked on the raw text, exactly as in every previous version
548 + $write = '/\b(delete|update|insert|replace|drop|truncate|alter|create|rename|grant|revoke|call|handler|load\s+data|load_file|outfile|dumpfile)\b/i';
549 + if (preg_match($write, $sql)) return 1;
550 +
551 + // 2) further dangerous statements, matched outside string literals and comments so that ordinary
552 + // values such as status = 'reset' keep working
553 + $danger = '/\b(prepare|execute|deallocate|lock|unlock|kill|shutdown|flush|reset|purge|install|uninstall|import'
554 + . '|set\s+(?:global|session|persist|persist_only|password|@@)|start\s+(?:replica|slave|group_replication)|stop\s+(?:replica|slave)|change\s+(?:master|replication))\b/i';
555 + if (preg_match($danger, guaven_sqlcharts_strip_sql_literals($sql))) return 1;
556 +
557 + // 3) every ";"-separated statement must be a read statement. The renderer sends each segment to the
558 + // database on its own, so this stops a value from smuggling a second statement behind a ";".
559 + foreach (explode(';', $sql) as $segment) {
560 + $segment = ltrim(guaven_sqlcharts_strip_sql_literals($segment), " \t\r\n(");
561 + if ($segment === '') continue;
562 + if (!preg_match('/^(select|with|show|describe|desc|explain)\b/i', $segment)) return 1;
306 563 }
307 - return $blacklister_f;
564 + return 0;
308 565 }
309 566
310 567 function guaven_get_labels_and_values($id, $fvs)
311 568 {
@@ -311,19 +568,13 @@
311 568 {
312 569 $values = array();
313 570 $labels = array();
314 571 $xarg_s = get_post_meta($id, 'guaven_sqlcharts_xarg_s', true);
315 - $xarg_l = get_post_meta($id, 'guaven_sqlcharts_xarg_l', true);
316 572 $yarg_s = get_post_meta($id, 'guaven_sqlcharts_yarg_s', true);
317 - $yarg_l = get_post_meta($id, 'guaven_sqlcharts_yarg_l', true);
318 - $chartype = array(
319 - 'line_l' => 'Line',
320 - 'pie_l' => 'Pie',
321 - 'donut_l' => 'Pie',
322 - 'bar_l' => 'Bar',
323 - 'horizontalbar_l' => 'Horizontal Bar',
324 - 'area_l' => 'Line'
325 - );
573 + // labels are saved through esc_attr, so "&" is stored as "&amp;"; decode before splitting on ";"
574 + // or the entity's own ";" would be taken as a series separator
575 + $xarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_xarg_l', true), ENT_QUOTES, 'UTF-8');
576 + $yarg_l = html_entity_decode((string) get_post_meta($id, 'guaven_sqlcharts_yarg_l', true), ENT_QUOTES, 'UTF-8');
326 577 foreach ($fvs as $key => $value) {
327 578 $values[$value->$xarg_s] = $value->$yarg_s;
328 579 $labels[$value->$xarg_s] = '"' . $value->$xarg_s . '"';
329 580 }
@@ -337,29 +588,48 @@
337 588
338 589 function guaven_sqlcharts_print_chart_js($print_data)
339 590 {
340 591 extract($print_data);
592 + $tip_g = guaven_sqlcharts_normalize_type($tip_g);
341 593
342 - if ($tip_g == 'line_l') {
343 - guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid);
594 + switch ($tip_g) {
595 + case 'line_l':
596 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid);
597 + break;
598 + case 'area_l':
599 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'true', $pid);
600 + break;
601 + case 'steppedline_l':
602 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'false', $pid, 'line', true);
603 + break;
604 + case 'radar_l':
605 + guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'radarfill', $pid, 'radar');
606 + break;
607 + case 'pie_l':
608 + guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid);
609 + break;
610 + case 'donut_l':
611 + guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'doughnut');
612 + break;
613 + case 'polar_l':
614 + guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'polarArea');
615 + break;
616 + case 'bar_l':
617 + guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'bar', $pid);
618 + break;
619 + case 'horizontalbar_l':
620 + guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'horizontalBar', $pid);
621 + break;
622 + case 'stackedbar_l':
623 + guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'stackedBar', $pid);
624 + break;
625 + case 'scatter_l':
626 + guaven_sqlcharts_scatterdata($title, $labels, $values, $ylabel, $pid);
627 + break;
628 + case 'custom':
629 + guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid);
630 + break;
344 631 }
345 - if ($tip_g == 'area_l') {
346 - guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, 'true', $pid);
347 - } elseif ($tip_g == 'pie_l') {
348 - guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid);
349 - } elseif ($tip_g == 'donut_l') {
350 - guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'doughnut');
351 - } elseif ($tip_g == 'bar_l') {
352 - guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'bar', $pid);
353 - } elseif ($tip_g == 'horizontalbar_l') {
354 - guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, 'horizontalBar', $pid);
355 - }
356 - elseif($tip_g == 'custom'){
357 - guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid);
358 - }
359 - elseif ($tip_g == 'polar_l') {
360 - guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, 'polarArea');
361 - }
362 632 }
363 633
364 634 function guaven_sqlcharts_custom($title, $labels, $values, $ylabel, $pid){
365 635 do_action('guaven_sqlcharts_custom',$title, $labels, $values, $ylabel, $pid);
@@ -384,10 +654,23 @@
384 654 foreach($variables_arr as $varfield){
385 655 $varfield_arr=explode("~",$varfield);
386 656 if (count($varfield_arr)<3) continue;
387 657 $varfield_arr=array_map("trim",$varfield_arr);
388 - if (!empty($_GET[$varfield_arr[0]])) $varreplacement=$_GET[$varfield_arr[0]]; else $varreplacement=$varfield_arr[1];
389 - if (!is_numeric($varreplacement) and strpos($varreplacement,'()')===false) $varreplacement='"'.$varreplacement.'"';
658 + if (!empty($_GET[$varfield_arr[0]])) {
659 + // User-supplied input: no () bypass allowed — sanitize strictly
660 + $varreplacement = str_replace(';', '', sanitize_text_field(wp_unslash($_GET[$varfield_arr[0]])));
661 + if (is_numeric($varreplacement)) {
662 + $varreplacement = $varreplacement + 0;
663 + } else {
664 + $varreplacement = '"' . esc_sql($varreplacement) . '"';
665 + }
666 + } else {
667 + // Admin-configured default value: allow () for SQL functions (e.g. NOW())
668 + $varreplacement = $varfield_arr[1];
669 + if (!is_numeric($varreplacement) && strpos($varreplacement,'()')===false) {
670 + $varreplacement = '"' . esc_sql($varreplacement) . '"';
671 + }
672 + }
390 673
391 674 $sql_initial=str_replace('{'.$varfield_arr[0].'}',$varreplacement,$sql_initial);
392 675 }
393 676 return $sql_initial;
@@ -394,8 +677,14 @@
394 677 }
395 678
396 679 function gvn_chart_top_form($atts){
397 680 if (get_post_meta($atts["id"],'guaven_sqlcharts_formpartrole',true)!='' and !is_user_logged_in()) return;
681 + // Inside the chart builder's live preview the filter inputs are rendered disabled and without a <form>
682 + // or submit button: the preview sits inside WordPress's own post edit form, nested forms are dropped
683 + // by the browser, and a filter named e.g. "post_type" would otherwise be submitted with the post and
684 + // make WordPress stop with "A post type mismatch has been detected." (chart settings not saved).
685 + $preview = !empty($GLOBALS['guaven_sqlcharts_admin_preview']);
686 + $dis = $preview ? ' disabled' : '';
398 687 $topform='';$dateexists=false;
399 688 $variables_raw=get_post_meta($atts['id'],'guaven_sqlcharts_variables',true);
400 689 $variables_raw=explode("|",$variables_raw);
401 690 foreach ($variables_raw as $vrow){
@@ -405,16 +694,16 @@
405 694 $gvalue=!empty($_GET[$vrow_arr[0]])?esc_attr(urldecode($_GET[$vrow_arr[0]])):'';
406 695 $dvalue=(strpos($vrow_arr[1],'()')===false)?esc_attr($vrow_arr[1]):'';
407 696 if ($vrow_arr[3]=='date') {
408 697 $dateexists=true;
409 - $topform.= $vrow_arr[2].' <input autocomplete="off" style="max-width:210px" type="text"
698 + $topform.= '<span class="gvn-filter-field"><label>'.$vrow_arr[2].'</label> <input class="gws_datepicker" autocomplete="off" type="text"
410 699 value="'.$gvalue.'"
411 - data-toggle="datepicker" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'">
700 + data-toggle="datepicker" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'"'.$dis.'></span>
412 701 ';}
413 702 else {
414 - $topform.= $vrow_arr[2].' <input autocomplete="off" style="max-width:210px;'.($vrow_arr[3]=='number'?'width:100px;':'').'"
703 + $topform.= '<span class="gvn-filter-field"><label>'.$vrow_arr[2].'</label> <input autocomplete="off"
415 704 type="'.$vrow_arr[3].'"
416 - value="'.$gvalue.'" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'">
705 + value="'.$gvalue.'" name="'.$vrow_arr[0].'" placeholder="'.$dvalue.'"'.$dis.'></span>
417 706 ';
418 707 }
419 708 }
420 709 if (!empty($topform)) {
@@ -427,36 +716,43 @@
427 716 'input' => array(
428 717 'type' => array(),
429 718 'value' => array(),
430 719 'name' => array(),
431 - 'class' => array()
720 + 'class' => array(),
721 + 'data-toggle'=>array(),
722 + 'placeholder'=>array(),
723 + 'autocomplete'=>array(),
724 + 'disabled'=>array(),
725 + 'style'=>[]
432 726 ),
433 - 'script' => array(),
727 + 'span' => array('class' => array()),
728 + 'label' => array(),
729 + 'div' => array('class' => array()),
434 730 );
435 -
436 - $submit_button_value = get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true) != ''
437 - ? esc_attr(get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true))
731 +
732 + $submit_button_value = get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true) != ''
733 + ? esc_attr(get_post_meta($atts['id'], 'guaven_sqlcharts_formpartbutton', true))
438 734 : 'OK';
439 -
440 - $topform = '<form method="get" action="" class="guaven_sqlcharts_form">' . $topform . '
735 +
736 + if ($preview) {
737 + $topform = '<div class="guaven_sqlcharts_form">' . $topform . '<input type="submit" value="' . $submit_button_value . '" disabled></div>';
738 + } else {
739 + $topform = '<form method="get" action="" class="guaven_sqlcharts_form">' . $topform . '
441 740 <input type="submit" value="' . $submit_button_value . '"></form>';
442 -
443 - if ($dateexists) {
444 - $topform .= '<script>setTimeout(function(){jQuery(\'[data-toggle="datepicker"]\').datepicker({format: \'yyyy-mm-dd\'});},300);</script>';
445 741 }
446 -
742 +
447 743 echo wp_kses($topform, $allowed_html);
448 744 }
449 745 }
450 746
451 747
452 -function guaven_sqlcharts_encrypt_decrypt($action, $string)
748 +function guaven_sqlcharts_encrypt_decrypt($action, $string)
453 749 {
454 750 $output = false;
455 751 $encrypt_method = "AES-256-CBC";
456 752 $secret_key = 'GWSCHARTPL2022.2016.';
457 753 $secret_iv = 'GWSCHARTPL2016.2022';
458 - $key = hash('sha256', $secret_key);
754 + $key = hash('sha256', $secret_key);
459 755 $iv = substr(hash('sha256', $secret_iv), 0, 16);
460 756 if ( $action == 'encrypt' ) {
461 757 $output = openssl_encrypt($string, $encrypt_method, $key, 0, $iv);
462 758 $output = base64_encode($output);
@@ -467,8 +763,11 @@
467 763 }
468 764
469 765 function guaven_sqlcharts_local_shortcode($atts) {
470 766 if(empty($atts['id']))return 'ID is missing.';
767 + $atts['id']=intval($atts['id']);
768 + $post_g = get_post($atts['id']);
769 + if (!$post_g or $post_g->post_type != 'gvn_schart') return 'Chart not found.';
471 770 $remote_host=get_post_meta($atts['id'], 'guaven_sqlcharts_dbhost', true);
472 771 if ($remote_host!=''){
473 772 $remote_db=get_post_meta($atts['id'], 'guaven_sqlcharts_dbname', true);
474 773 $remote_login=get_post_meta($atts['id'], 'guaven_sqlcharts_dblogin', true);
@@ -483,33 +782,39 @@
483 782 }
484 783
485 784 $GLOBALS["guaven_sqlcharts_atts"]=$atts;
486 785
487 - $sql = html_entity_decode(get_post_meta($atts['id'], 'guaven_sqlcharts_code', true));
786 + $sql = guaven_sqlcharts_get_code($atts['id']);
488 787 if(empty($sql))return 'SQL query is missing.';
489 - $sql=gvn_chart_put_variables($sql,$atts['id']);
490 788
789 + // {arg1}..{arg19} come from shortcode attributes: [gvn_schart_2 id="1" arg1="41"].
790 + // Substituted directly (not via wpdb::prepare) so the same tag may appear any number of times,
791 + // e.g. in every query of a ";"-separated comparison chart. Numbers are inserted as-is, anything
792 + // else is escaped and quoted; a tag already wrapped in quotes ('{arg1}') is not double-quoted.
793 + // ";" is removed from values because the finished SQL is split on ";" below.
794 + for($i=1;$i<20;$i++){
795 + $tag = '{arg'.$i.'}';
796 + if (strpos($sql, $tag) === false) continue;
797 + $replacearg = !empty($atts['arg'.$i]) ? $atts['arg'.$i] : 0;
798 + if (is_numeric($replacearg)) $replacearg = $replacearg + 0;
799 + else $replacearg = "'" . esc_sql(str_replace(';', '', sanitize_text_field((string) $replacearg))) . "'";
800 + $sql = str_replace(array("'".$tag."'", '"'.$tag.'"', $tag), $replacearg, $sql);
801 + }
491 802
803 + $sql=gvn_chart_put_variables($sql,$atts['id']);
492 804 $sql=apply_filters('guaven_sqlcharts_rendered_sql',$sql,$atts);
493 805
806 + // command check on the final SQL, after every shortcode argument and filter value is in place
494 807 $blacklister_f = gvn_chart_check_sql_query($sql);
495 808 if ($blacklister_f == 1)return 'You given SQL code contains forbidden commands. Remember that you should only use SELECT queries';
496 - $tip_g = get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true);
497 -
498 - for($i=1;$i<20;$i++){
499 - if(strpos($sql,"{arg".$i."}")!==false){
500 - $replacearg=!empty($atts["arg".$i])?$atts["arg".$i]:0;
501 - $sql = str_replace("{arg".$i."}", "%s", $sql);
502 - $sql=$wpdb->prepare($sql,$replacearg);
503 - }
809 + $tip_g = guaven_sqlcharts_normalize_type(get_post_meta($atts['id'], 'guaven_sqlcharts_graphtype', true));
504 810
505 - }
506 -
507 811 $sql_split = explode(';', $sql);
508 812 $labels_and_values = array();
509 - $post_g = get_post($atts['id']);
813 + $labels = $values = $ylabel = $xlabel = array();
510 814
511 815 global $sqlcharts_inserted_script;
816 + ob_start();
512 817 for ($i = 0; $i < count($sql_split); $i++) {
513 818 if (!empty($sql_split[$i])) {
514 819
515 820 $fvs = $wpdb->get_results($sql_split[$i]);
@@ -517,16 +822,18 @@
517 822 $wpdb->show_errors();
518 823 ob_start();
519 824 $wpdb->print_error();
520 825 $printerror = ob_get_clean();
521 - if ($printerror != '' and strpos($printerror, "[]") === false)
826 + if ($printerror != '' and strpos($printerror, "[]") === false){
827 + ob_end_clean();
522 828 return $printerror;
523 - elseif (empty($fvs))
829 + }
830 + elseif (empty($fvs)){
831 + ob_end_clean();
524 832 return 'Your SQL returnes empty data, please recheck your SQL query above';
833 + }
525 834 }
526 835
527 - ob_start();
528 -
529 836 if (empty($sqlcharts_inserted_script))
530 837 $sqlcharts_inserted_script = 1;
531 838 $labels_and_values[$i] = guaven_get_labels_and_values($atts['id'], $fvs);
532 839 $labels[$i] = $labels_and_values[$i][0];
@@ -536,14 +843,22 @@
536 843 }
537 844 }
538 845
539 846 gvn_chart_top_form($atts);
847 +
848 + // shortcode width/height attributes override the saved defaults
849 + $chart_w = !empty($atts['width']) ? $atts['width'] : get_post_meta($atts['id'], 'guaven_sqlcharts_chartwidth', true);
850 + $chart_h = !empty($atts['height']) ? $atts['height'] : get_post_meta($atts['id'], 'guaven_sqlcharts_chartheight', true);
851 + $wrap_style = '';
852 + if ($chart_w != '') $wrap_style .= 'max-width:' . (int) $chart_w . 'px;';
853 + if ($chart_h != '') $wrap_style .= 'height:' . (int) $chart_h . 'px;';
540 854 ?>
541 - <canvas
542 - id="ct-chart_<?php echo esc_attr($sqlcharts_inserted_script); ?>"
855 + <div class="gvn-chartwrap"<?php echo $wrap_style != '' ? ' style="' . esc_attr($wrap_style) . '"' : ''; ?>>
856 + <canvas
857 + id="ct-chart_<?php echo esc_attr($sqlcharts_inserted_script); ?>"
543 858 class="guaven_chart_canvas"
544 - style="width: <?php echo esc_attr(get_post_meta($atts['id']), 'guaven_sqlcharts_chartwidth', true); ?>px !important; height: <?php echo esc_attr(get_post_meta($atts['id'], 'guaven_sqlcharts_chartheight', true)); ?>px !important;"
545 859 ></canvas>
860 + </div>
546 861
547 862 <script type="text/javascript" class="gvn_charts_script" async>
548 863 var ctx = jQuery("#ct-chart_<?php
549 864 echo esc_attr($sqlcharts_inserted_script);
@@ -549,9 +864,9 @@
549 864 echo esc_attr($sqlcharts_inserted_script);
550 865 ?>");
551 866
552 867 <?php
553 - $print_data=apply_filters('guaven_sqlcharts_pre_print_vars',['tip_g'=>$tip_g, 'title'=>$post_g->post_title,
868 + $print_data=apply_filters('guaven_sqlcharts_pre_print_vars',['tip_g'=>$tip_g, 'title'=>$post_g->post_title,
554 869 'labels'=>$labels, 'values'=>$values, 'ylabel'=>$ylabel, 'pid'=>$atts['id']]);
555 870 guaven_sqlcharts_print_chart_js($print_data);
556 871 ?>
557 872 </script>
@@ -565,19 +880,46 @@
565 880 }
566 881
567 882 add_shortcode('gvn_schart_2', 'guaven_sqlcharts_local_shortcode');
568 883
884 +// legacy alias: old Google-Chart era posts produced [gvn_schart id=".."] shortcodes
885 +if (!shortcode_exists('gvn_schart')) {
886 + add_shortcode('gvn_schart', 'guaven_sqlcharts_local_shortcode');
887 +}
888 +
889 +// [gvn_schart_2_cached id="1" expire="3600" arg1=".."] – same as gvn_schart_2 but the output is kept in a
890 +// transient. All other attributes (argN, width, height, table, params) are passed through, and each
891 +// distinct set of attributes gets its own cache entry. Append ?force_sql_cache_reload to the URL to bypass.
569 892 add_shortcode("gvn_schart_2_cached",function($atts){
570 893 if(empty($atts["id"]))return;
571 - $is_logged_in=is_user_logged_in()?'':'_guest';
894 + $atts["id"]=intval($atts["id"]);
572 895 $expire=!empty($atts["expire"])?intval($atts["expire"]):3600;
573 - $cached=get_transient('cached_sql_charts_'.$atts["id"].$is_logged_in);
896 + $inner_atts=$atts;
897 + unset($inner_atts['expire']);
898 + // One cache entry per user (charts may use {current_user_*} tags), per set of shortcode attributes
899 + // and per value of every dynamic filter this chart reads from the URL. A visitor can therefore
900 + // never be served, or pre-seed, a result computed for someone else or for other filter values.
901 + $key_parts = array('atts' => $inner_atts, 'user' => is_user_logged_in() ? get_current_user_id() : 0, 'get' => array());
902 + foreach (explode('|', (string) get_post_meta($atts['id'], 'guaven_sqlcharts_variables', true)) as $vrow) {
903 + $vname = trim(current(explode('~', $vrow)));
904 + if ($vname !== '' and isset($_GET[$vname])) $key_parts['get'][$vname] = sanitize_text_field(wp_unslash($_GET[$vname]));
905 + }
906 + $key = 'cached_sql_charts_' . $atts["id"] . '_' . md5(serialize($key_parts));
907 + $cached=get_transient($key);
574 908 if(!empty($cached) and !isset($_GET["force_sql_cache_reload"]) )return $cached;
575 - $tobecached=do_shortcode('[gvn_schart_2 id="'.$atts["id"].'"]');
576 - set_transient('cached_sql_charts_'.$atts["id"].$is_logged_in, $tobecached,$expire);//you can change 3600 yourself
909 + $tobecached=guaven_sqlcharts_local_shortcode($inner_atts);
910 + set_transient($key, $tobecached,$expire);
577 911 return $tobecached;
578 912 });
579 913
914 +// fixed, colorblind-friendly default palette (Tableau 10) used when no custom colors are set
915 +function guaven_sqlcharts_default_palette(){
916 + return apply_filters('guaven_sqlcharts_default_palette', array(
917 + '#4E79A7', '#F28E2B', '#E15759', '#76B7B2', '#59A14F',
918 + '#EDC948', '#B07AA1', '#FF9DA7', '#9C755F', '#BAB0AC'
919 + ));
920 +}
921 +
580 922 function guaven_sqlcharts_colors($index, $pid = null){
581 923 if(!isset($pid)) {
582 924 global $post;
583 925 $pid = $post->ID;
@@ -584,29 +926,98 @@
584 926 }
585 927 $colors=get_post_meta($pid,'guaven_sqlcharts_colors',true);
586 928 $colors=explode(",",$colors);
587 929 if (!empty($colors[$index])) return $colors[$index];
588 - return wp_rand(0, 255) . ',' . wp_rand(0, 255) . ',' . wp_rand(0, 255);
930 + $palette = guaven_sqlcharts_default_palette();
931 + return $palette[$index % count($palette)];
589 932 }
590 933
591 -/* TBD
592 -function guaven_sqlcharts_toshowlegend($pid){
593 - $guaven_sqlcharts_legend_position=get_post_meta($pid, 'guaven_sqlcharts_legend_position', true);
594 - if(in_array($guaven_sqlcharts_legend_position,['top','bottom','left','right'])){
595 - $display='true';$position=$guaven_sqlcharts_legend_position;
934 +// outputs 'maintainAspectRatio:false,' when an explicit height is set, so the
935 +// chart fills its sized wrapper instead of keeping the default aspect ratio
936 +function guaven_sqlcharts_mar($pid){
937 + $atts = isset($GLOBALS["guaven_sqlcharts_atts"]) ? $GLOBALS["guaven_sqlcharts_atts"] : array();
938 + $h = !empty($atts['height']) ? $atts['height'] : get_post_meta($pid, 'guaven_sqlcharts_chartheight', true);
939 + return $h != '' ? 'maintainAspectRatio: false,' : '';
940 +}
941 +
942 +// outputs 'showAllTooltips: true,' when "Value labels" is checked; the values are drawn by the
943 +// gvnShowAllValues plugin in asset/front.js (works for every chart type)
944 +function guaven_sqlcharts_value_labels($pid){
945 + return get_post_meta($pid, 'guaven_sqlcharts_forcetooltips', true) != '' ? 'showAllTooltips: true,' : '';
946 +}
947 +
948 +// Chart.js scale title block built from the "X axis label" / "Y axis label" fields.
949 +// $which is 'x' or 'y' (the *field* to use, not the scale). The Y label is only used as an axis
950 +// title for single-series charts; with several ";"-separated series the legend names them instead.
951 +function guaven_sqlcharts_axis_title($pid, $which){
952 + $key = $which == 'x' ? 'guaven_sqlcharts_xarg_l' : 'guaven_sqlcharts_yarg_l';
953 + $text = trim(html_entity_decode((string) get_post_meta($pid, $key, true), ENT_QUOTES, 'UTF-8'));
954 + if ($text === '' or ($which == 'y' and strpos($text, ';') !== false)) return '';
955 + return 'title: {display: true, text: ' . wp_json_encode($text) . '},';
956 +}
957 +
958 +// "params" shortcode attribute: extra Chart.js dataset options, e.g. params="borderWidth: 3, borderDash: [5,5],".
959 +// The text is placed inside the inline <script>, so only a conservative character set is accepted:
960 +// no parentheses, semicolons, "=", "<", ">", "/", "\\", "+" or backticks, which rules out executable JavaScript.
961 +function guaven_sqlcharts_dataset_params(){
962 + $params = isset($GLOBALS["guaven_sqlcharts_atts"]["params"]) ? (string) $GLOBALS["guaven_sqlcharts_atts"]["params"] : '';
963 + if ($params === '' or !preg_match('/^[A-Za-z0-9_\s,:.\'"#%\-\[\]{}]+$/', $params)) return '';
964 + return $params;
965 +}
966 +
967 +// dataset label as a safe JS string literal (labels saved before 3.0.1 may hold HTML entities)
968 +function guaven_sqlcharts_js_label($label){
969 + return wp_json_encode(html_entity_decode((string) $label, ENT_QUOTES, 'UTF-8'));
970 +}
971 +
972 +// Parses an X value for the "time axis" option. Accepts YYYY, YYYY-MM, YYYY-MM-DD, optionally followed
973 +// by HH:MM or HH:MM:SS. Returns a UTC timestamp in milliseconds, or false when the value is not a date.
974 +function guaven_sqlcharts_parse_date($str){
975 + $str = trim((string) $str);
976 + if (!preg_match('/^(\d{4})(?:-(\d{1,2})(?:-(\d{1,2})(?:[ T](\d{1,2}):(\d{2})(?::(\d{2}))?)?)?)?$/', $str, $m)) return false;
977 + $y = (int) $m[1]; $mo = isset($m[2]) ? (int) $m[2] : 1; $d = isset($m[3]) ? (int) $m[3] : 1;
978 + $h = isset($m[4]) ? (int) $m[4] : 0; $mi = isset($m[5]) ? (int) $m[5] : 0; $sec = isset($m[6]) ? (int) $m[6] : 0;
979 + if (!checkdate($mo, $d, $y) or $h > 23 or $mi > 59 or $sec > 59) return false;
980 + return gmmktime($h, $mi, $sec, $mo, $d, $y) * 1000;
981 +}
982 +
983 +// "Scale X axis by date/time" option. Returns, per dataset, a list of "{x:<ms>,y:<value>}" JS point
984 +// literals when the option is on and every X value is a date; false otherwise (normal category axis).
985 +function guaven_sqlcharts_time_axis_points($pid, $values){
986 + if (get_post_meta($pid, 'guaven_sqlcharts_timeaxis', true) != 1) return false;
987 + $out = array();
988 + $has_point = false;
989 + foreach ($values as $key_ak => $series) {
990 + $out[$key_ak] = array();
991 + foreach ($series as $x => $y) {
992 + $ts = guaven_sqlcharts_parse_date($x);
993 + if ($ts === false) return false;
994 + $out[$key_ak][] = '{x:' . $ts . ',y:' . (is_numeric($y) ? $y + 0 : 'null') . '}';
995 + $has_point = true;
996 + }
596 997 }
597 - else {
598 - $display='false';$position='top';
599 - }
600 - return "legend: {display: ".$display.",position:'".$position."'},";
998 + return $has_point ? $out : false;
601 999 }
602 -*/
603 1000
1001 +// X scale options for time-axis mode (globals from asset/front.js): gvnSqlChartsTimeTicks replaces the evenly
1002 +// spaced ticks Chart.js generates on a linear scale with the actual data dates, gvnSqlChartsTimeTick formats them
1003 +function guaven_sqlcharts_time_axis_scale(){
1004 + return "type: 'linear', offset: true, afterBuildTicks: gvnSqlChartsTimeTicks, ticks: {callback: gvnSqlChartsTimeTick, maxRotation: 45, autoSkip: true},";
1005 +}
1006 +// extra entry for the Chart.js "plugins" object in time-axis mode (tooltip title shown as a date)
1007 +function guaven_sqlcharts_time_axis_plugins($time_points){
1008 + return $time_points !== false ? 'tooltip: {callbacks: {title: gvnSqlChartsTimeTooltipTitle}}' : '';
1009 +}
1010 +
604 1011 function guaven_sqlcharts_bardata($title, $labels, $values, $ylabel, $type = 'bar', $pid = null)
605 1012 {
1013 + $horizontal = ($type == 'horizontalBar');
1014 + $forcestack = ($type == 'stackedBar');
1015 + $stacked = ($forcestack or get_post_meta($pid, 'guaven_sqlcharts_nostacked', true) != 1) ? 'true' : 'false';
1016 + $time_points = $horizontal ? false : guaven_sqlcharts_time_axis_points($pid, $values);
606 1017 ?>
607 1018 var data = {
608 - labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],
1019 + <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?>
609 1020 datasets: [
610 1021 <?php
611 1022 $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
612 1023 $i=-1;
@@ -611,32 +1022,29 @@
611 1022 $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
612 1023 $i=-1;
613 1024 foreach ($values_new as $key_ak=>$value_ak) {
614 1025 $i++;
1026 + $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak];
615 1027 ?>
616 1028 {
617 - <?php
618 - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){
619 - //passing chartJS params via the shortcode
620 - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]);
621 - }
1029 + <?php
1030 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
622 1031 ?>
623 - label: "<?php
624 - echo wp_kses($ylabel[$key_ak],[]);
625 -?>",
1032 + label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>,
626 1033 backgroundColor: [
627 1034 <?php
628 - echo wp_kses(guaven_sqlcharts_colorgenerator(count($values_new[$key_ak]), 0, 0, guaven_sqlcharts_colors($i, $pid)),[]);
1035 + echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0, guaven_sqlcharts_colors($i, $pid)),[]);
629 1036 ?>
630 1037 ],
631 1038 borderColor: [
632 1039 <?php
633 - echo wp_kses(guaven_sqlcharts_colorgenerator(count($values_new[$key_ak]), 0, 0.2, guaven_sqlcharts_colors($i, $pid)),[]);
1040 + echo wp_kses(guaven_sqlcharts_colorgenerator(count($points), 0, 0.2, guaven_sqlcharts_colors($i, $pid)),[]);
634 1041 ?>
635 1042 ],
636 1043 borderWidth: 1,
1044 + <?php if ($time_points !== false) echo 'barThickness: 24,'; // fixed width: on a time axis Chart.js would otherwise size bars from the closest pair of dates ?>
637 1045 data: [<?php
638 - echo wp_kses(implode(",", $values_new[$key_ak]),[]);
1046 + echo wp_kses(implode(",", $points),[]);
639 1047 ?>],
640 1048 },
641 1049 <?php
642 1050 }
@@ -644,31 +1052,33 @@
644 1052 ]
645 1053 };
646 1054 var options={
647 1055 responsive: true,
1056 + <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1057 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1058 + <?php if ($horizontal) echo "indexAxis: 'y',"; ?>
648 1059 scales: {
649 - xAxes: [{
650 - <?php echo (get_post_meta($pid, 'guaven_sqlcharts_nostacked', true) == 1) ? '':'stacked: true,';?>
1060 + x: {
1061 + <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?>
1062 + <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'y' : 'x'); ?>
1063 + stacked: <?php echo esc_js($stacked); ?>,
1064 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1065 + },
1066 + y: {
1067 + <?php echo guaven_sqlcharts_axis_title($pid, $horizontal ? 'x' : 'y'); ?>
1068 + stacked: <?php echo esc_js($stacked); ?>,
1069 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
651 1070 ticks: {
652 - beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
653 - }
654 - }],
655 - yAxes: [{
656 - <?php echo (get_post_meta($pid, 'guaven_sqlcharts_nostacked', true) == 1) ? '':'stacked: true,';?>
657 - ticks: {
658 1071 <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
659 - beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>
660 1072 }
661 - }]
1073 + }
662 1074 }
663 - <?php
664 - guaven_sqlcharts_maybe_additional_parameters($pid);
1075 + <?php
1076 + guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points));
665 1077 ?>
666 1078 };
667 1079 var myBarChart = new Chart(ctx, {
668 - type: '<?php
669 - echo esc_attr($type);
670 -?>',
1080 + type: 'bar',
671 1081 data: data,
672 1082 options: options
673 1083 });
674 1084 <?php
@@ -682,33 +1092,35 @@
682 1092 }
683 1093 echo wp_kses(implode(",",array_unique($merged)),[]);
684 1094 }
685 1095
686 -function guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, $type = 'false', $pid = null)
1096 +function guaven_sqlcharts_linedata($title, $labels, $values, $ylabel, $type = 'false', $pid = null, $charttype = 'line', $stepped = false)
687 1097 {
1098 + $time_points = ($charttype == 'radar') ? false : guaven_sqlcharts_time_axis_points($pid, $values);
688 1099 ?>
689 1100 var data = {
690 - labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],
1101 + <?php if ($time_points === false) { ?>labels: [<?php guaven_sqlcharts_merge_labeldata($labels);?>],<?php } ?>
691 1102 datasets: [
692 - <?php
1103 + <?php
693 1104 $values_new=guaven_sqlcharts_key_normalizer($values,$labels,$ylabel)[0];
1105 + $dataset_count=count($values_new);
694 1106 $i=-1;
695 1107 foreach ($values_new as $key_ak=>$value_ak) {
696 1108 $i++;
1109 + $points = $time_points !== false ? $time_points[$key_ak] : $values_new[$key_ak];
1110 + if ($type == 'radarfill') $fill = "'origin'";
1111 + elseif ($type == 'false') $fill = 'false';
1112 + else $fill = ($i == 0 and $dataset_count > 1) ? '"+1"' : '"origin"';
697 1113 ?>
698 1114 {
699 - <?php
700 - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){
701 - //passing chartJS params via the shortcode
702 - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]);
703 - }
1115 + <?php
1116 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
704 1117 ?>
705 - label: "<?php
706 - echo esc_attr($ylabel[$key_ak]);
707 -?>",
708 - fill: <?php echo $type=="false"? esc_attr($type):($i==0?'"+1"':'"origin"');
1118 + label: <?php echo guaven_sqlcharts_js_label($ylabel[$key_ak]); ?>,
1119 + fill: <?php echo wp_kses($fill,[]);
709 1120 ?>,
710 - lineTension: 0.1,
1121 + tension: 0.1,
1122 + <?php if ($stepped) echo 'stepped: true,'; ?>
711 1123 backgroundColor: <?php
712 1124 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
713 1125 ?>
714 1126 borderColor: <?php
@@ -723,9 +1135,9 @@
723 1135 pointHoverBorderColor: <?php
724 1136 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
725 1137 ?>
726 1138 data: [<?php
727 - echo wp_kses_post(implode(",", $values_new[$key_ak]));
1139 + echo wp_kses_post(implode(",", $points));
728 1140 ?>],
729 1141 spanGaps: false,
730 1142 },
731 1143 <?php
@@ -733,30 +1145,103 @@
733 1145 ?>
734 1146 ]
735 1147 };
736 1148 var myLineChart = new Chart(ctx, {
737 - type: 'line',
1149 + type: '<?php echo esc_attr($charttype); ?>',
738 1150 data: data,
739 1151 options: {
740 1152 responsive: true,
1153 + <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1154 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1155 + <?php if ($charttype == 'radar') { ?>
741 1156 scales: {
742 - xAxes: [{
1157 + r: {
1158 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>
1159 + }
1160 + }
1161 + <?php } else { ?>
1162 + scales: {
1163 + x: {
743 1164 display: true,
1165 + <?php if ($time_points !== false) echo guaven_sqlcharts_time_axis_scale(); ?>
1166 + <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?>
1167 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1168 + },
1169 + y: {
1170 + <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?>
1171 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
744 1172 ticks: {
745 - beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1173 + <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
746 1174 }
747 - }],
748 - yAxes: [{
1175 + }
1176 + }
1177 + <?php } ?>
1178 + <?php
1179 + guaven_sqlcharts_maybe_additional_parameters($pid, guaven_sqlcharts_time_axis_plugins($time_points));
1180 + ?>
1181 +
1182 + }
1183 +});
1184 + <?php
1185 +}
1186 +
1187 +function guaven_sqlcharts_scatterdata($title, $labels, $values, $ylabel, $pid = null)
1188 +{
1189 +?>
1190 +var data = {
1191 + datasets: [
1192 + <?php
1193 + $i=-1;
1194 + foreach ($values as $key_ak=>$value_ak) {
1195 + $i++;
1196 + $points=array();
1197 + foreach ($value_ak as $xval=>$yval) {
1198 + $x = is_numeric($xval) ? $xval : '"'.esc_js($xval).'"';
1199 + $y = is_numeric($yval) ? $yval : '"'.esc_js($yval).'"';
1200 + $points[] = '{x:'.$x.',y:'.$y.'}';
1201 + }
1202 +?>
1203 + {
1204 + <?php
1205 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
1206 + ?>
1207 + label: <?php echo guaven_sqlcharts_js_label(isset($ylabel[$key_ak])?$ylabel[$key_ak]:''); ?>,
1208 + backgroundColor: <?php
1209 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1210 +?>
1211 + borderColor: <?php
1212 + echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 1, 0.2, guaven_sqlcharts_colors($i, $pid)));
1213 +?>
1214 + data: [<?php echo wp_kses(implode(",", $points),[]); ?>],
1215 + },
1216 + <?php
1217 + }
1218 +?>
1219 + ]
1220 +};
1221 +var myScatterChart = new Chart(ctx, {
1222 + type: 'scatter',
1223 + data: data,
1224 + options: {
1225 + responsive: true,
1226 + <?php echo wp_kses(guaven_sqlcharts_mar($pid),[]); ?>
1227 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
1228 + scales: {
1229 + x: {
1230 + <?php echo guaven_sqlcharts_axis_title($pid, 'x'); ?>
1231 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_x', true) == 1) ? 'true':'false'; ?>
1232 + },
1233 + y: {
1234 + <?php echo guaven_sqlcharts_axis_title($pid, 'y'); ?>
1235 + beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>,
749 1236 ticks: {
750 - <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
751 - beginAtZero: <?php echo (get_post_meta($pid, 'guaven_sqlcharts_begin_with_0_y', true) == 1) ? 'true':'false'; ?>
1237 + <?php if(get_post_meta($pid, 'guaven_sqlcharts_round_y_values', true) == 1) echo 'precision: 0,'; ?>
752 1238 }
753 - }]
1239 + }
754 1240 }
755 - <?php
1241 + <?php
756 1242 guaven_sqlcharts_maybe_additional_parameters($pid);
757 1243 ?>
758 -
759 1244 }
760 1245 });
761 1246 <?php
762 1247 }
@@ -761,9 +1246,9 @@
761 1246 <?php
762 1247 }
763 1248
764 1249
765 -function guaven_sqlcharts_maybe_additional_parameters($pid){
1250 +function guaven_sqlcharts_maybe_additional_parameters($pid, $extra_plugins = ''){
766 1251 if(function_exists('guaven_sqlcharts_maybe_additional_parameters_custom')){
767 1252 wp_kses(guaven_sqlcharts_maybe_additional_parameters_custom($pid),[]);
768 1253 return;
769 1254 }
@@ -773,9 +1258,9 @@
773 1258 }
774 1259 else {
775 1260 $display='false';$position='top';
776 1261 }
777 - echo wp_kses( ",legend: {display: ".$display.",position:'".$position."'}",[]);
1262 + echo wp_kses( ",plugins: {legend: {display: ".$display.",position:'".$position."'}".($extra_plugins !== '' ? ','.$extra_plugins : '')."}",[]);
778 1263 }
779 1264
780 1265
781 1266
@@ -781,16 +1266,14 @@
781 1266
782 1267
783 1268 function guaven_sqlcharts_piedata($title, $labels, $values, $ylabel, $pid, $type = 'pie')
784 1269 {
785 - if(get_post_meta($pid,'guaven_sqlcharts_forcetooltips',true)!=''){
786 - echo 'guaven_sqlcharts_show_pie_labels();'.PHP_EOL;
787 - }
788 1270 ?>
789 1271 var options={
790 - showAllTooltips: true,
1272 + <?php echo wp_kses(guaven_sqlcharts_value_labels($pid),[]); ?>
791 1273 responsive: true
792 - <?php
1274 + <?php echo get_post_meta($pid,'guaven_sqlcharts_chartheight',true)!=''||!empty($GLOBALS["guaven_sqlcharts_atts"]['height'])?',maintainAspectRatio: false':''; ?>
1275 + <?php
793 1276 guaven_sqlcharts_maybe_additional_parameters($pid);
794 1277 ?>
795 1278 };
796 1279 var data = {
@@ -799,13 +1282,10 @@
799 1282 <?php
800 1283 for ($i = 0; $i < count($values); $i++) {
801 1284 ?>
802 1285 {
803 - <?php
804 - if(!empty($GLOBALS["guaven_sqlcharts_atts"]["params"])){
805 - //passing chartJS params via the shortcode
806 - echo wp_kses($GLOBALS["guaven_sqlcharts_atts"]["params"],[]);
807 - }
1286 + <?php
1287 + echo guaven_sqlcharts_dataset_params(); // "params" shortcode attribute (validated)
808 1288 ?>
809 1289 data: [<?php
810 1290 echo wp_kses(implode(",", $values[$i]),[]);
811 1291 ?>],
@@ -814,9 +1294,9 @@
814 1294 $ii=0;
815 1295 foreach($values[$i] as $vci=>$valuecolor){
816 1296 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 0, -0.1, guaven_sqlcharts_colors($ii, $pid)));
817 1297 $ii++;
818 - }
1298 + }
819 1299 ?>
820 1300 ],
821 1301 hoverBackgroundColor: [
822 1302 <?php
@@ -823,9 +1303,9 @@
823 1303 $ii=0;
824 1304 foreach($values[$i] as $vci=>$valuecolor){
825 1305 echo wp_kses_post(guaven_sqlcharts_colorgenerator(1, 0, 0.2, guaven_sqlcharts_colors($ii, $pid)));
826 1306 $ii++;
827 - }
1307 + }
828 1308 ?>
829 1309 ]
830 1310 },
831 1311 <?php
@@ -887,9 +1367,9 @@
887 1367 foreach ($valuerow as $key => $value) {
888 1368 $putval=$labels[$row][$key]??'';
889 1369 $fcol[$key]='<td>'.str_replace('"',"",$putval).'</td>';
890 1370 $scol[$key][$row]='<td>'.$value.'</td>';
891 - }
1371 + }
892 1372 foreach($scol as $scolkey=>$scolvalue){
893 1373 for($i=0;$i<count($values);$i++){
894 1374 //echo $i;
895 1375 if(!isset($scolvalue[$i]))$scol[$scolkey][$i]=$empty_cell;;
@@ -895,16 +1375,16 @@
895 1375 if(!isset($scolvalue[$i]))$scol[$scolkey][$i]=$empty_cell;;
896 1376 }
897 1377 ksort($scol[$scolkey]);
898 1378 }
899 - }
900 -
1379 + }
1380 +
901 1381 foreach($fcol as $key=>$value){
902 1382 $tablein.='<tr>'.$value.implode(" ",$scol[$key]).'</tr>'.PHP_EOL;
903 1383 }
904 - $tabledata.='<table><tr><th>'.$xlabel[0].'</th><th>'.implode("</th><th>",$ylabel).'</th></tr>
905 - '.$tablein.'</table><br>';
906 -
1384 + $tabledata.='<div class="gvn-tablewrap"><table class="gvn-table"><tr><th>'.$xlabel[0].'</th><th>'.implode("</th><th>",$ylabel).'</th></tr>
1385 + '.$tablein.'</table></div><br>';
1386 +
907 1387 echo wp_kses_post($tabledata);
908 1388
909 1389 }
910 1390
@@ -942,5 +1422,5 @@
942 1422 }
943 1423
944 1424
945 1425 add_filter('guaven_sqlcharts_table_empty_cell',function($str){return '<td>#</td>';});
946 -add_filter('guaven_sqlcharts_table_empty_value',function($str){return 'N/A';});
1426 +add_filter('guaven_sqlcharts_table_empty_value',function($str){return 'N/A';});