PluginProbe
ManageWP Worker / 4.9.36
ManageWP Worker v4.9.36
4.9.38 4.9.37 4.9.36 4.9.35 4.9.34 3.8.7 3.8.8 3.9.0 3.9.1 3.9.10 3.9.11 3.9.12 3.9.13 3.9.14 3.9.15 3.9.16 3.9.17 3.9.18 3.9.19 3.9.2 3.9.20 3.9.21 3.9.22 3.9.23 3.9.24 All 73 releases
worker / src / MWP / Action / IncrementalBackup / ChecksumTables.php

ChecksumTables.php in ManageWP Worker 4.9.36, at src/MWP/Action/IncrementalBackup/ChecksumTables.php

57 lines 2.3 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /*
3 * This file is part of the ManageWP Worker plugin.
4 *
5 * (c) ManageWP LLC <[email protected]>
6 *
7 * For the full copyright and license information, please view the LICENSE
8 * file that was distributed with this source code.
9 */
10
11 class MWP_Action_IncrementalBackup_ChecksumTables extends MWP_Action_IncrementalBackup_Abstract
12 {
13
14 public function execute(array $params = array(), MWP_Worker_Request $request)
15 {
16 // escapeName() validates and escapes each table name. Filter out any
17 // names that fail validation (returns null) to avoid injecting nulls
18 // into the query.
19 $tables = array_filter(array_map(array($this, 'escapeName'), $params['query']));
20
21 if (empty($tables)) {
22 return $this->createResult(array('checksum' => array(), 'db' => $this->container->getWordPressContext()->getConstant('DB_NAME')));
23 }
24
25 $query = implode(',', $tables);
26
27 $wpdb = $this->container->getWordPressContext()->getDb();
28 $results = $wpdb->get_results('CHECKSUM TABLE '.$query, ARRAY_A);
29 $checksum = array();
30
31 foreach ($results as $row) {
32 $checksum[$row['Table']] = $row['Checksum'];
33 }
34
35 return $this->createResult(array('checksum' => $checksum, 'db' => $this->container->getWordPressContext()->getConstant('DB_NAME')));
36 }
37
38 public function escapeName($tableName)
39 {
40 // Validate that the table name contains only characters that are valid
41 // in MySQL identifiers: letters, digits, underscores, and dollar signs.
42 // Dots are intentionally excluded: wrapping "db.table" in a single pair
43 // of backticks produces the literal identifier `db.table` rather than
44 // the qualified `db`.`table` that MySQL expects. Callers always supply
45 // unqualified table names so dot support is not needed.
46 if (!preg_match('/^[a-zA-Z0-9_$]+$/', $tableName)) {
47 return null;
48 }
49
50 // Double any backtick characters within the name as per the MySQL
51 // standard for escaping identifier delimiters. This is defence-in-depth:
52 // the regex above already rejects backticks, but explicit escaping
53 // ensures safety if the validation rule is ever relaxed.
54 return '`' . str_replace('`', '``', $tableName) . '`';
55 }
56 }
57