PluginProbe ʕ •ᴥ•ʔ
WooCommerce / 11.1.0
WooCommerce v11.1.0
11.1.0 11.1.0-rc.2 11.1.0-rc.1 11.1.0-beta.2 11.1.0-beta.1 11.0.1 11.0.0 11.0.0-rc.3 11.0.0-rc.2 11.0.0-rc.1 11.0.0-beta.2 11.0.0-beta.1 10.9.4 10.9.3 10.9.2 10.9.1 10.9.0 10.9.0-rc.1 10.9.0-beta.2 10.9.0-beta.1 10.8.1 10.8.0 10.8.0-rc.1 10.8.0-beta.2 10.8.0-beta.1 7.8.0-beta.1 7.8.0-beta.2 7.8.0-rc.1 7.8.0-rc.2 7.8.1 7.8.2 7.8.3 7.8.4 7.9.0 7.9.0-beta.1 7.9.0-beta.2 7.9.0-rc.2 7.9.0-rc.3 7.9.1 7.9.2 8.0.0 8.0.0-beta.1 8.0.0-beta.2 8.0.0-rc.1 8.0.0-rc.2 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.1.0 8.1.0-beta.1 8.1.0-rc.1 8.1.0-rc.2 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 8.2.0-beta.1 8.2.0-rc.1 8.2.0-rc.2 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.3.0 8.3.0-beta.1 8.3.0-rc.1 8.3.0-rc.2 8.3.1 8.3.2 8.3.3 8.3.4 8.4.0 8.4.0-beta.1 8.4.0-rc.1 8.4.1 8.4.2 8.4.3 8.5.0 8.5.0-beta.1 8.5.0-rc.1 8.5.1 8.5.2 8.5.3 8.5.4 8.5.5 8.6.0 8.6.0-beta.1 8.6.0-rc.1 8.6.1 8.6.2 8.6.3 8.6.4 8.7.0 8.7.0-beta.1 8.7.0-beta.2 8.7.0-rc.1 8.7.1 8.7.2 8.7.3 8.8.0 8.8.0-beta.1 8.8.0-rc.1 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.8.6 8.8.7 8.9.0 8.9.0-beta.1 8.9.0-rc.1 8.9.1 8.9.2 8.9.3 8.9.4 8.9.5 9.0.0 9.0.0-beta.1 9.0.0-beta.2 9.0.0-rc.1 9.0.1 9.0.2 9.0.3 9.0.4 9.1.0 9.1.0-beta.1 9.1.0-rc.1 9.1.1 9.1.2 9.1.3 9.1.4 9.1.5 9.1.6 9.2.0 9.2.0-beta.1 9.2.0-rc.1 9.2.1 9.2.2 9.2.3 9.2.4 9.2.5 9.3.0 9.3.0-beta.1 9.3.0-rc.1 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.3.6 9.4.0 9.4.0-beta.1 9.4.0-beta.2 9.4.0-rc.1 9.4.0-rc.2 9.4.0-rc.3 9.4.0-rc.4 9.4.1 9.4.2 9.4.3 9.4.4 9.4.5 9.5.0 9.5.0-beta.1 9.5.0-beta.2 9.5.0-rc.1 9.5.1 9.5.2 9.5.3 9.5.4 9.6.0 9.6.0-beta.1 9.6.0-beta.2 9.6.0-rc.1 9.6.1 9.6.2 9.6.3 9.6.4 9.7.0 9.7.0-beta.1 9.7.0-rc.1 9.7.1 9.7.2 9.7.3 9.8.0 9.8.0-beta.1 9.8.0-rc.1 9.8.1 9.8.2 9.8.3 9.8.4 9.8.5 9.8.6 9.8.7 9.9.0 9.9.0-beta.1 9.9.0-rc.1 9.9.1 9.9.2 9.9.3 9.9.4 9.9.5 9.9.6 9.9.7 3.7.3 7.1.2 3.8.0 7.2.0 3.8.0-beta.1 7.2.0-beta.1 3.8.0-rc.1 7.2.0-beta.2 3.8.0-rc.2 7.2.0-rc.1 3.8.1 7.2.0-rc.2 3.8.2 7.2.1 3.8.3 7.2.2 3.9.0 7.2.3 3.9.0-beta.1 7.2.4 3.9.0-beta.2 7.3.0 3.9.0-rc.1 7.3.0-beta.1 3.9.0-rc.2 7.3.0-beta.2 3.9.0-rc.3 7.3.0-rc.1 3.9.0-rc.4 7.3.0-rc.2 3.9.1 7.3.1 3.9.2 7.4.0 3.9.3 7.4.0-beta.1 3.9.4 7.4.0-beta.2 3.9.5 7.4.0-rc.1 4.0.0 7.4.0-rc.2 4.0.0-beta.1 7.4.1 4.0.0-rc.1 7.4.2 4.0.0-rc.2 7.5.0 4.0.1 7.5.0-beta.1 4.0.2 7.5.0-beta.2 4.0.3 7.5.0-rc.1 4.0.4 7.5.1 4.1.0 7.5.2 4.1.0-beta.1 7.6.0 4.1.0-beta.2 7.6.0-beta.1 4.1.0-rc.1 7.6.0-beta.2 4.1.0-rc.2 7.6.0-rc.1 4.1.1 7.6.0-rc.2 4.1.2 7.6.0-rc.3 4.1.3 7.6.1 4.1.4 7.6.2 4.2.0 7.7.0 4.2.0-RC.1 7.7.0-beta.1 4.2.0-RC.2 7.7.0-beta.2 4.2.0-beta.1 7.7.0-rc.1 4.2.1 7.7.1 4.2.2 7.7.2 4.2.3 7.7.3 4.2.4 7.8.0 4.2.5 4.3.0 4.3.0-beta.1 4.3.0-rc.1 4.3.0-rc.2 4.3.0-rc.3 4.3.1 4.3.2 4.3.3 4.3.4 4.3.5 4.3.6 4.4.0 4.4.0-beta.1 4.4.0-rc.1 4.4.1 4.4.2 4.4.3 4.4.4 4.5.0 4.5.0-beta.1 4.5.0-rc.1 4.5.0-rc.3 4.5.1 4.5.2 4.5.3 4.5.4 4.5.5 4.6.0 4.6.0-beta.1 4.6.0-rc.1 4.6.1 4.6.2 4.6.3 4.6.4 4.6.5 4.7.0 4.7.0-beta.1 4.7.0-beta.2 4.7.0-rc.1 4.7.1 4.7.1-beta.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.0-beta.1 4.8.0-rc.1 4.8.0-rc.2 4.8.1 4.8.2 4.8.3 4.9.0 4.9.0-beta.1 4.9.0-rc.1 4.9.0-rc.2 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 5.0.0 5.0.0-beta.1 5.0.0-beta.2 5.0.0-rc.1 5.0.0-rc.2 5.0.0-rc.3 5.0.1 5.0.2 5.0.3 5.1.0 5.1.0-beta.1 5.1.0-rc.1 trunk 5.1.1 10.0.0 5.1.2 10.0.0-rc.1 5.1.3 10.0.0-rc.2 5.2.0 10.0.1 5.2.0-beta.1 10.0.2 5.2.0-rc.1 10.0.3 5.2.0-rc.2 10.0.4 5.2.1 10.0.5 5.2.2 10.0.6 5.2.3 10.1.0 5.2.4 10.1.0-rc.1 5.2.5 10.1.0-rc.2 5.3.0 10.1.0-rc.3 5.3.0-beta.1 10.1.0-rc.4 5.3.0-rc.1 10.1.1 5.3.0-rc.2 10.1.2 5.3.1 10.1.3 5.3.2 10.1.4 5.3.3 10.2.0 5.4.0 10.2.0-beta.1 5.4.0-beta.1 10.2.0-beta.2 5.4.0-rc.1 10.2.0-rc.1 5.4.1 10.2.1 5.4.2 10.2.2 5.4.3 10.2.3 5.4.4 10.2.4 5.4.5 10.3.0 5.5.0 10.3.0-beta.1 5.5.0-beta.1 10.3.0-beta.2 5.5.0-rc.1 10.3.0-rc.1 5.5.0-rc.2 10.3.0-rc.2 5.5.1 10.3.1 5.5.2 10.3.2 5.5.3 10.3.3 5.5.4 10.3.4 5.5.5 10.3.5 5.6.0 10.3.6 5.6.0-beta.1 10.3.7 5.6.0-rc.1 10.3.8 5.6.0-rc.2 10.4.0 5.6.1 10.4.0-beta.1 5.6.2 10.4.0-beta.2 5.6.3 10.4.0-rc.1 5.7.0 10.4.1 5.7.0-beta.1 10.4.2 5.7.0-rc.1 10.4.3 5.7.1 10.4.4 5.7.2 10.5.0 5.7.3 10.5.0-beta.1 5.8.0 10.5.0-beta.2 5.8.0-beta.1 10.5.0-rc.1 5.8.0-beta.2 10.5.0-rc.2 5.8.0-rc.1 10.5.0-rc.3 5.8.1 10.5.1 5.8.2 10.5.2 5.9.0 10.5.3 5.9.0-beta.1 10.6.0 5.9.0-rc.1 10.6.0-beta.1 5.9.0-rc.2 10.6.0-beta.2 5.9.1 10.6.0-rc.1 5.9.2 10.6.1 6.0.0 10.6.2 6.0.0-beta.1 10.7.0 6.0.0-rc.1 10.7.0-beta.1 6.0.1 10.7.0-beta.2 6.0.2 10.7.0-rc.1 6.1.0 3.0.0 6.1.0-beta.1 3.0.1 6.1.0-rc.1 3.0.2 6.1.0-rc.2 3.0.3 6.1.1 3.0.4 6.1.2 3.0.5 6.1.3 3.0.6 6.2.0 3.0.7 6.2.0-beta.1 3.0.8 6.2.0-rc.1 3.0.9 6.2.0-rc.2 3.1.0 6.2.1 3.1.1 6.2.2 3.1.2 6.2.3 3.2.0 6.3.0 3.2.1 6.3.0-beta.1 3.2.2 6.3.0-rc.1 3.2.3 6.3.0-rc.2 3.2.4 6.3.1 3.2.5 6.3.2 3.2.6 6.4.0 3.3.0 6.4.0-beta.1 3.3.1 6.4.0-rc.1 3.3.2 6.4.1 3.3.2-rc.1 6.4.2 3.3.3 6.5.0 3.3.4 6.5.0-beta.1 3.3.5 6.5.0-rc.1 3.3.6 6.5.0-rc.2 3.4.0 6.5.1 3.4.0-beta.1 6.5.2 3.4.0-rc.2 6.6.0 3.4.1 6.6.0-beta.1 3.4.2 6.6.0-rc.1 3.4.3 6.6.0-rc.2 3.4.4 6.6.1 3.4.5 6.6.2 3.4.6 6.7.0 3.4.7 6.7.0-beta.1 3.4.8 6.7.0-beta.2 3.5.0 6.7.0-rc.1 3.5.0-beta.1 6.7.1 3.5.0-rc.1 6.8.0 3.5.0-rc.2 6.8.0-beta.1 3.5.1 6.8.0-beta.2 3.5.10 6.8.0-rc.1 3.5.2 6.8.1 3.5.3 6.8.2 3.5.4 6.8.3 3.5.5 6.9.0 3.5.6 6.9.0-beta.1 3.5.7 6.9.0-beta.2 3.5.8 6.9.0-rc.1 3.5.9 6.9.1 3.6.0 6.9.2 3.6.0-beta.1 6.9.3 3.6.0-rc.1 6.9.4 3.6.0-rc.2 6.9.5 3.6.0-rc.3 7.0.0 3.6.1 7.0.0-beta.1 3.6.2 7.0.0-beta.2 3.6.3 7.0.0-beta.3 3.6.4 7.0.0-rc.1 3.6.5 7.0.0-rc.2 3.6.6 7.0.1 3.6.7 7.0.2 3.7.0 7.1.0 3.7.0-beta.1 7.1.0-beta.1 3.7.0-rc.1 7.1.0-beta.2 3.7.0-rc.2 7.1.0-rc.1 3.7.1 7.1.0-rc.2 3.7.2 7.1.1
woocommerce / src / Internal / Api / QueryComplexityRule.php
woocommerce / src / Internal / Api Last commit date
Autogenerated 3 days ago GraphQLEndpointRegistrar.php 2 months ago OpcacheFileExpiry.php 2 months ago QueryCache.php 2 months ago QueryComplexityRule.php 3 days ago QueryDepthRule.php 3 days ago Settings.php 2 months ago StatusResolverFailedException.php 2 months ago
QueryComplexityRule.php
284 lines
1 <?php
2
3 declare(strict_types=1);
4
5 namespace Automattic\WooCommerce\Internal\Api;
6
7 use Automattic\WooCommerce\Vendor\GraphQL\Error\Error;
8 use Automattic\WooCommerce\Vendor\GraphQL\Executor\Values;
9 use Automattic\WooCommerce\Vendor\GraphQL\Language\AST\FieldNode;
10 use Automattic\WooCommerce\Vendor\GraphQL\Language\AST\FragmentSpreadNode;
11 use Automattic\WooCommerce\Vendor\GraphQL\Language\AST\NodeKind;
12 use Automattic\WooCommerce\Vendor\GraphQL\Language\AST\SelectionNode;
13 use Automattic\WooCommerce\Vendor\GraphQL\Language\AST\SelectionSetNode;
14 use Automattic\WooCommerce\Vendor\GraphQL\Type\Definition\Directive;
15 use Automattic\WooCommerce\Vendor\GraphQL\Type\Definition\FieldDefinition;
16 use Automattic\WooCommerce\Vendor\GraphQL\Validator\QueryValidationContext;
17 use Automattic\WooCommerce\Vendor\GraphQL\Validator\Rules\QueryComplexity;
18
19 /**
20 * QueryComplexity validation rule that returns a generic error message when
21 * the complexity is exceeded. Admins can still read both values via debug
22 * mode; see {@see GraphQLController} step 8.
23 *
24 * Unlike the stock webonyx rule, the work done stays proportional to the size
25 * of the document: each named fragment is scored once and the result reused
26 * for every spread, variable values are coerced once instead of once per
27 * directive or complexity callback, field definitions come from the visitor's
28 * TypeInfo instead of being re-collected for every selection set, and scores
29 * saturate at {@see self::COMPLEXITY_CEILING} instead of overflowing.
30 */
31 class QueryComplexityRule extends QueryComplexity {
32 /**
33 * Upper bound for computed complexity scores.
34 *
35 * Far above any configurable limit, so real scores stay exact, while leaving
36 * headroom below PHP_INT_MAX for complexity callbacks to multiply a saturated
37 * child score by a page size without overflowing.
38 */
39 public const COMPLEXITY_CEILING = PHP_INT_MAX >> 10;
40
41 /**
42 * Memoized complexity of each named fragment, keyed by fragment name.
43 *
44 * @var array<string, int>
45 */
46 private array $fragment_complexities = array();
47
48 /**
49 * Names of the fragments whose complexity is currently being computed;
50 * guards against fragment cycles (which the NoFragmentCycles rule reports).
51 *
52 * @var array<string, true>
53 */
54 private array $fragments_in_progress = array();
55
56 /**
57 * Variable values coerced for the current document, or null when not yet computed.
58 *
59 * @var ?array<string, mixed>
60 */
61 private ?array $coerced_variable_values = null;
62
63 /**
64 * Schema definition of every field node in the document, keyed by the
65 * node's spl_object_id(). Populated as the visitor enters each field.
66 *
67 * @var array<int, ?FieldDefinition>
68 */
69 private array $field_definitions = array();
70
71 /**
72 * Reset the per-document state, then replace the stock SELECTION_SET
73 * callback, which re-collects field definitions through every fragment
74 * reachable from each selection set, with recording the definition that
75 * TypeInfo already resolves as the visitor enters each field.
76 *
77 * @param QueryValidationContext $context The validation context.
78 * @return array The visitor definition.
79 */
80 public function getVisitor( QueryValidationContext $context ): array {
81 $this->fragment_complexities = array();
82 $this->fragments_in_progress = array();
83 $this->coerced_variable_values = null;
84 $this->field_definitions = array();
85
86 $visitor = parent::getVisitor( $context );
87 if ( array() === $visitor ) {
88 // The rule is disabled.
89 return $visitor;
90 }
91
92 unset( $visitor[ NodeKind::SELECTION_SET ] );
93 $visitor[ NodeKind::FIELD ] = function ( FieldNode $node ) use ( $context ): void {
94 $this->field_definitions[ spl_object_id( $node ) ] = $context->getFieldDef();
95 };
96
97 return $visitor;
98 }
99
100 /**
101 * Look up the schema definition recorded for a field node.
102 *
103 * @param FieldNode $field The field node.
104 * @return ?FieldDefinition The definition, or null when the field doesn't exist on its parent type.
105 */
106 protected function fieldDefinition( FieldNode $field ): ?FieldDefinition {
107 return $this->field_definitions[ spl_object_id( $field ) ] ?? null;
108 }
109
110 /**
111 * Sum the complexity of a selection set's selections, saturating at
112 * {@see self::COMPLEXITY_CEILING}.
113 *
114 * @param SelectionSetNode $selection_set The selection set to score.
115 * @return int The (possibly saturated) complexity.
116 * @throws \Exception When variable or argument coercion fails.
117 */
118 protected function fieldComplexity( SelectionSetNode $selection_set ): int {
119 $complexity = 0;
120
121 foreach ( $selection_set->selections as $selection ) {
122 $complexity = $this->add_saturating( $complexity, $this->nodeComplexity( $selection ) );
123 }
124
125 return $complexity;
126 }
127
128 /**
129 * Score a single selection. Named fragments are scored once and the result
130 * reused for every spread; everything else is delegated to the stock rule.
131 *
132 * @param SelectionNode $node The selection to score.
133 * @return int The complexity of the selection.
134 * @throws \Exception When variable or argument coercion fails.
135 */
136 protected function nodeComplexity( SelectionNode $node ): int {
137 if ( ! $node instanceof FragmentSpreadNode ) {
138 return parent::nodeComplexity( $node );
139 }
140
141 $fragment = $this->getFragment( $node );
142 if ( is_null( $fragment ) ) {
143 return 0;
144 }
145
146 $name = $fragment->name->value;
147 if ( array_key_exists( $name, $this->fragment_complexities ) ) {
148 return $this->fragment_complexities[ $name ];
149 }
150
151 // A fragment that (transitively) spreads itself has unbounded
152 // complexity. NoFragmentCycles reports the actual error.
153 if ( isset( $this->fragments_in_progress[ $name ] ) ) {
154 return self::COMPLEXITY_CEILING;
155 }
156
157 $this->fragments_in_progress[ $name ] = true;
158 try {
159 $complexity = $this->fieldComplexity( $fragment->selectionSet );
160 } finally {
161 unset( $this->fragments_in_progress[ $name ] );
162 }
163
164 $this->fragment_complexities[ $name ] = $complexity;
165
166 return $complexity;
167 }
168
169 /**
170 * Whether `@include` / `@skip` directives exclude the field from execution.
171 *
172 * Same semantics as the stock rule, but variable values are coerced once
173 * per document (see {@see self::get_coerced_variable_values()}).
174 *
175 * @param FieldNode $node The field node.
176 * @return bool True when the field will not be executed.
177 * @throws \Exception When variable coercion fails.
178 */
179 protected function directiveExcludesField( FieldNode $node ): bool {
180 foreach ( $node->directives as $directive_node ) {
181 $directive_name = $directive_node->name->value;
182
183 if ( Directive::INCLUDE_NAME === $directive_name ) {
184 $include_arguments = Values::getArgumentValues(
185 Directive::includeDirective(),
186 $directive_node,
187 $this->get_coerced_variable_values()
188 );
189 if ( false === $include_arguments['if'] ) {
190 return true;
191 }
192 } elseif ( Directive::SKIP_NAME === $directive_name ) {
193 $skip_arguments = Values::getArgumentValues(
194 Directive::skipDirective(),
195 $directive_node,
196 $this->get_coerced_variable_values()
197 );
198 if ( true === $skip_arguments['if'] ) {
199 return true;
200 }
201 }
202 }
203
204 return false;
205 }
206
207 /**
208 * Build the argument values handed to a field's complexity callback.
209 *
210 * Same semantics as the stock rule, but variable values are coerced once
211 * per document (see {@see self::get_coerced_variable_values()}).
212 *
213 * @param FieldNode $node The field node.
214 * @return array<string, mixed> The coerced argument values.
215 * @throws \Exception When variable or argument coercion fails.
216 */
217 protected function buildFieldArguments( FieldNode $node ): array {
218 $field_definition = $this->fieldDefinition( $node );
219
220 return $field_definition instanceof FieldDefinition
221 ? Values::getArgumentValues( $field_definition, $node, $this->get_coerced_variable_values() )
222 : array();
223 }
224
225 /**
226 * Coerce the document's variable values against their definitions,
227 * once per document.
228 *
229 * @return array<string, mixed> The coerced variable values.
230 * @throws Error When the provided variables don't satisfy their definitions (same error the stock rule throws).
231 */
232 private function get_coerced_variable_values(): array {
233 if ( ! is_null( $this->coerced_variable_values ) ) {
234 return $this->coerced_variable_values;
235 }
236
237 list( $errors, $variable_values ) = Values::getVariableValues(
238 $this->context->getSchema(),
239 $this->variableDefs,
240 $this->getRawVariableValues()
241 );
242
243 if ( ! empty( $errors ) ) {
244 // phpcs:disable WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Not HTML; serialized as JSON by the GraphQL error formatter.
245 throw new Error(
246 implode(
247 "\n\n",
248 array_map( static fn( Error $error ): string => $error->getMessage(), $errors )
249 )
250 );
251 // phpcs:enable WordPress.Security.EscapeOutput.ExceptionNotEscaped
252 }
253
254 $this->coerced_variable_values = $variable_values ?? array();
255
256 return $this->coerced_variable_values;
257 }
258
259 /**
260 * Add two complexity scores, saturating at {@see self::COMPLEXITY_CEILING}.
261 *
262 * @param int $a First score.
263 * @param int $b Second score.
264 * @return int The saturated sum.
265 */
266 private function add_saturating( int $a, int $b ): int {
267 $sum = $a + $b;
268
269 // An int overflow turns the sum into a float, which is also above the ceiling.
270 return $sum > self::COMPLEXITY_CEILING ? self::COMPLEXITY_CEILING : (int) $sum;
271 }
272
273 /**
274 * Override webonyx's default ("Max query complexity should be {max} but
275 * got {count}.").
276 *
277 * @param int $max The configured maximum complexity (unused).
278 * @param int $count The computed query complexity (unused).
279 */
280 public static function maxQueryComplexityErrorMessage( int $max, int $count ): string {
281 return 'Maximum query complexity exceeded.';
282 }
283 }
284