PluginProbe
Visualizer – Tables & Charts Manager with Built-in AI Generator / 3.11.15
Visualizer – Tables & Charts Manager with Built-in AI Generator v3.11.15
4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.10.1 3.10.10 3.10.11 3.10.12 3.10.13 3.10.14 3.10.15 3.10.2 3.10.3 3.10.4 All 148 releases
visualizer / classes / Visualizer / Source / Query.php

Query.php in Visualizer – Tables & Charts Manager with Built-in AI Generator 3.11.15, at classes/Visualizer/Source/Query.php

306 lines 8.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 // +----------------------------------------------------------------------+
4 // | Copyright 2013 Madpixels (email : visualizer@madpixels.net) |
5 // +----------------------------------------------------------------------+
6 // | This program is free software; you can redistribute it and/or modify |
7 // | it under the terms of the GNU General Public License, version 2, as |
8 // | published by the Free Software Foundation. |
9 // | |
10 // | This program is distributed in the hope that it will be useful, |
11 // | but WITHOUT ANY WARRANTY; without even the implied warranty of |
12 // | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
13 // | GNU General Public License for more details. |
14 // | |
15 // | You should have received a copy of the GNU General Public License |
16 // | along with this program; if not, write to the Free Software |
17 // | Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, |
18 // | MA 02110-1301 USA |
19 // +----------------------------------------------------------------------+
20 // | Author: Eugene Manuilov <eugene@manuilov.org> |
21 // +----------------------------------------------------------------------+
22 /**
23 * Source manager for query builder.
24 *
25 * @category Visualizer
26 * @package Source
27 */
28 class Visualizer_Source_Query extends Visualizer_Source {
29
30 /**
31 * The query.
32 *
33 * @access protected
34 * @var string
35 */
36 protected $_query;
37
38 /**
39 * The chart id.
40 *
41 * @access protected
42 * @var int
43 */
44 protected $_chart_id;
45
46 /**
47 * Any additional parameters (e.g. for connecting to a remote db).
48 *
49 * @access protected
50 * @var array
51 */
52 protected $_params;
53
54 /**
55 * Constructor.
56 *
57 * @access public
58 * @param string $query The query.
59 * @param int $chart_id The chart id.
60 * @param array $params Any additional parameters (e.g. for connecting to a remote db).
61 */
62 public function __construct( $query = null, $chart_id = null, $params = null ) {
63 $this->_query = $this->strip_sql_comments( $query );
64 $this->_chart_id = $chart_id;
65 $this->_params = $params;
66 }
67
68 /**
69 * Strips SQL comments from the query.
70 *
71 * @param string $query The query.
72 *
73 * @return string
74 */
75 private function strip_sql_comments( $query = '' ) {
76 if ( empty( $query ) ) {
77 return $query;
78 }
79
80 // Regex https://regex101.com/r/xd5Vrg/1
81 $sql_comments_regex = '@(--[^\r\n]*)|(\#[^\r\n]*)|(/\*[\w\W]*?(?=\*/)\*/)@ms';
82 return trim( preg_replace( $sql_comments_regex, '', $query ) );
83 }
84
85 /**
86 * Fetches information from source, parses it and builds series and data arrays.
87 *
88 * @param bool $as_html Should the result be fetched as an HTML table or as an object.
89 * @param bool $results_as_numeric_array Should the result be fetched as ARRAY_N instead of ARRAY_A.
90 * @param bool $raw_results Should the result be returned without processing.
91 * @access public
92 * @return boolean TRUE on success, otherwise FALSE.
93 */
94 public function fetch( $as_html = false, $results_as_numeric_array = false, $raw_results = false ) {
95 if ( empty( $this->_query ) ) {
96 return false;
97 }
98
99 // only select queries allowed. must start with SELECT keyword.
100 if ( ! preg_match( '/^(\bselect\b)\s/i', $this->_query ) ) {
101 $this->_error = __( 'Only SELECT queries are allowed', 'visualizer' );
102 return false;
103 }
104
105 // if previous check passed, check for disallowed query parts to prevent subqueries and other harmful queries.
106 $disallow_query_parts = array(
107 'CREATE',
108 'ALTER',
109 'TRUNCATE',
110 'DROP',
111
112 'INSERT',
113 'DELETE',
114 'UPDATE',
115 'REPLACE',
116
117 'RENAME',
118 'COMMIT',
119 'ROLLBACK',
120 'MERGE',
121 'CALL',
122 'EXPLAIN',
123 'LOCK',
124 'GRANT',
125 'REVOKE',
126 'SAVEPOINT',
127 'TRANSACTION',
128 'SET',
129 );
130 $disallow_regex = implode(
131 '|',
132 array_map(
133 function ( $value ) {
134 return '\b' . $value . '\b';
135 }, $disallow_query_parts
136 )
137 );
138
139 if ( preg_match( '/(' . $disallow_regex . ')/i', $this->_query) !== 0 ) {
140 $this->_error = __( 'Only SELECT queries are allowed', 'visualizer' );
141 return false;
142 }
143
144 // impose a limit if no limit clause is provided.
145 if ( strpos( strtolower( $this->_query ), ' limit ' ) === false ) {
146 $this->_query .= ' LIMIT ' . apply_filters( 'visualizer_sql_query_limit', 1000, $this->_chart_id );
147 }
148
149 $this->_query = apply_filters( 'visualizer_db_query', $this->_query, $this->_chart_id, $this->_params );
150
151 $results = array();
152 $headers = array();
153
154 // short circuit results for remote dbs.
155 if ( false !== ( $remote_results = apply_filters( 'visualizer_db_query_execute', false, $this->_query, $as_html, $results_as_numeric_array, $raw_results, $this->_chart_id, $this->_params ) ) ) {
156 $error = $remote_results['error'];
157 if ( empty( $error ) ) {
158 $results = $remote_results['results'];
159 $headers = $remote_results['headers'];
160 }
161
162 $this->_error = $error;
163
164 if ( $raw_results ) {
165 return $results;
166 }
167 }
168
169 if ( ! ( $results && $headers ) ) {
170 global $wpdb;
171 $wpdb->hide_errors();
172 // @codingStandardsIgnoreStart
173 $rows = $wpdb->get_results( $this->_query, $results_as_numeric_array ? ARRAY_N : ARRAY_A );
174 // @codingStandardsIgnoreEnd
175 $wpdb->show_errors();
176
177 if ( $raw_results ) {
178 return $rows;
179 }
180
181 if ( $wpdb->last_error ) {
182 $this->_error = $wpdb->last_error;
183 return [];
184 }
185
186 if ( $rows ) {
187 $results = array();
188 $headers = array();
189 if ( $rows ) {
190 $row_num = 0;
191 foreach ( $rows as $row ) {
192 $result = array();
193 $col_num = 0;
194 foreach ( $row as $k => $v ) {
195 $result[] = $v;
196 if ( 0 === $row_num ) {
197 $headers[] = array( 'type' => $this->get_col_type( $col_num++ ), 'label' => $k );
198 }
199 }
200 $results[] = $result;
201 $row_num++;
202 }
203 }
204
205 $this->_error = $wpdb->last_error;
206 }
207 }
208 // Query log.
209 do_action( 'themeisle_log_event', Visualizer_Plugin::NAME, sprintf( 'Firing query %s to get results %s with error %s', $this->_query, print_r( $rows, true ), print_r( $wpdb->last_error, true ) ), 'debug', __FILE__, __LINE__ );
210
211 if ( $as_html ) {
212 $results = $this->html( $headers, $results );
213 } else {
214 $results = $this->object( $headers, $results );
215 }
216
217 return apply_filters( 'visualizer_db_query_results', $results, $headers, $as_html, $results_as_numeric_array, $raw_results, $this->_query, $this->_chart_id, $this->_params );
218 }
219
220 /**
221 * Get the data type of the column.
222 *
223 * @param int $col_num The column index in the fetched result set.
224 * @access private
225 * @return int
226 */
227 private function get_col_type( $col_num ) {
228 global $wpdb;
229 switch ( $wpdb->get_col_info( 'type', $col_num ) ) {
230 case 0:
231 case 5:
232 case 4:
233 case 9:
234 case 3:
235 case 2:
236 case 246:
237 case 8:
238 // numeric.
239 return 'number';
240 case 10:
241 case 12:
242 case 14:
243 // date.
244 return 'date';
245 }
246 return 'string';
247 }
248
249 /**
250 * Returns the HTML output.
251 *
252 * @param array $headers The headers of the result set.
253 * @param array $results The data of the result set.
254 * @access private
255 * @return string
256 */
257 private function html( $headers, $results ) {
258 return Visualizer_Render_Layout::show( 'db-wizard-results', $headers, $results );
259 }
260
261 /**
262 * Sets the series and data.
263 *
264 * @param array $headers The headers of the result set.
265 * @param array $results The data of the result set.
266 * @access private
267 * @return bool
268 */
269 private function object( $headers, $results ) {
270 $series = array();
271 foreach ( $headers as $header ) {
272 $series[] = $header;
273 }
274 $this->_series = $series;
275
276 $data = array();
277 foreach ( $results as $row ) {
278 $data[] = $this->_normalizeData( $row );
279 }
280 $this->_data = $data;
281 return $this->_data;
282 }
283
284 /**
285 * Returns the final query.
286 *
287 * @access public
288 * @return string
289 */
290 public function get_query() {
291 return $this->_query;
292 }
293
294 /**
295 * Returns source name.
296 *
297 * @since 1.0.0
298 *
299 * @access public
300 * @return string The name of source.
301 */
302 public function getSourceName() {
303 return __CLASS__;
304 }
305 }
306