| 1 |
<?php |
| 2 |
/* |
| 3 |
* This file is part of the ManageWP Worker plugin. |
| 4 |
* |
| 5 |
* (c) ManageWP LLC <[email protected]> |
| 6 |
* |
| 7 |
* For the full copyright and license information, please view the LICENSE |
| 8 |
* file that was distributed with this source code. |
| 9 |
*/ |
| 10 |
|
| 11 |
class MWP_Action_IncrementalBackup_ChecksumTables extends MWP_Action_IncrementalBackup_Abstract |
| 12 |
{ |
| 13 |
|
| 14 |
public function execute(array $params = array(), MWP_Worker_Request $request) |
| 15 |
{ |
| 16 |
// escapeName() validates and escapes each table name. Filter out any |
| 17 |
// names that fail validation (returns null) to avoid injecting nulls |
| 18 |
// into the query. |
| 19 |
$tables = array_filter(array_map(array($this, 'escapeName'), $params['query'])); |
| 20 |
|
| 21 |
if (empty($tables)) { |
| 22 |
return $this->createResult(array('checksum' => array(), 'db' => $this->container->getWordPressContext()->getConstant('DB_NAME'))); |
| 23 |
} |
| 24 |
|
| 25 |
$query = implode(',', $tables); |
| 26 |
|
| 27 |
$wpdb = $this->container->getWordPressContext()->getDb(); |
| 28 |
$results = $wpdb->get_results('CHECKSUM TABLE '.$query, ARRAY_A); |
| 29 |
$checksum = array(); |
| 30 |
|
| 31 |
foreach ($results as $row) { |
| 32 |
$checksum[$row['Table']] = $row['Checksum']; |
| 33 |
} |
| 34 |
|
| 35 |
return $this->createResult(array('checksum' => $checksum, 'db' => $this->container->getWordPressContext()->getConstant('DB_NAME'))); |
| 36 |
} |
| 37 |
|
| 38 |
public function escapeName($tableName) |
| 39 |
{ |
| 40 |
// Validate that the table name contains only characters that are valid |
| 41 |
// in MySQL identifiers: letters, digits, underscores, and dollar signs. |
| 42 |
// Dots are intentionally excluded: wrapping "db.table" in a single pair |
| 43 |
// of backticks produces the literal identifier `db.table` rather than |
| 44 |
// the qualified `db`.`table` that MySQL expects. Callers always supply |
| 45 |
// unqualified table names so dot support is not needed. |
| 46 |
if (!preg_match('/^[a-zA-Z0-9_$]+$/', $tableName)) { |
| 47 |
return null; |
| 48 |
} |
| 49 |
|
| 50 |
// Double any backtick characters within the name as per the MySQL |
| 51 |
// standard for escaping identifier delimiters. This is defence-in-depth: |
| 52 |
// the regex above already rejects backticks, but explicit escaping |
| 53 |
// ensures safety if the validation rule is ever relaxed. |
| 54 |
return '`' . str_replace('`', '``', $tableName) . '`'; |
| 55 |
} |
| 56 |
} |
| 57 |
|