| @@ -105,22 +105,35 @@ | ||
| 105 | 105 | public function search(string $search, array $args = []): array |
| 106 | 106 | { |
| 107 | 107 | $table = esc_sql($this->table); |
| 108 | 108 | $search = sanitize_text_field($search); |
| 109 | - | |
| 109 | + | |
| 110 | 110 | $where = ["type = %s"]; |
| 111 | 111 | $where[] = "(name LIKE %s OR slug LIKE %s OR description LIKE %s)"; |
| 112 | - $searchTerm = '%' . $wpdb->esc_like($search) . '%'; | |
| 112 | + $searchTerm = '%' . $this->wpdb->esc_like($search) . '%'; | |
| 113 | 113 | |
| 114 | - // Add additional where conditions | |
| 114 | + // Build params alongside the WHERE clause (single pass — the previous | |
| 115 | + // version touched $params before it was initialised). | |
| 116 | + $params = [ClassificationTypes::CATEGORY, $searchTerm, $searchTerm, $searchTerm]; | |
| 117 | + | |
| 118 | + // Additional WHERE conditions. Column names are attacker-reachable map | |
| 119 | + // keys, so strip them to [A-Za-z0-9_] (same rule as BaseRepository); | |
| 120 | + // values stay parameterised. | |
| 115 | 121 | if (isset($args['where']) && is_array($args['where'])) { |
| 116 | 122 | foreach ($args['where'] as $field => $value) { |
| 123 | + $column = preg_replace('/[^a-zA-Z0-9_]/', '', (string) $field); | |
| 124 | + if ($column === '') { | |
| 125 | + continue; | |
| 126 | + } | |
| 117 | 127 | if (is_array($value)) { |
| 128 | + if (empty($value)) { | |
| 129 | + continue; | |
| 130 | + } | |
| 118 | 131 | $placeholders = implode(',', array_fill(0, count($value), '%s')); |
| 119 | - $where[] = "{$field} IN ({$placeholders})"; | |
| 120 | - $params = array_merge($params, $value); | |
| 132 | + $where[] = "`{$column}` IN ({$placeholders})"; | |
| 133 | + $params = array_merge($params, array_values($value)); | |
| 121 | 134 | } else { |
| 122 | - $where[] = "{$field} = %s"; | |
| 135 | + $where[] = "`{$column}` = %s"; | |
| 123 | 136 | $params[] = $value; |
| 124 | 137 | } |
| 125 | 138 | } |
| 126 | 139 | } |
| @@ -125,23 +138,42 @@ | ||
| 125 | 138 | } |
| 126 | 139 | } |
| 127 | 140 | |
| 128 | 141 | $whereClause = implode(' AND ', $where); |
| 129 | - $order = isset($args['order']) ? $args['order'] : 'name ASC'; | |
| 130 | - $limit = isset($args['limit']) ? "LIMIT {$args['limit']}" : ''; | |
| 131 | 142 | |
| 132 | - $query = "SELECT * FROM `{$table}` WHERE {$whereClause} ORDER BY {$order} {$limit}"; | |
| 133 | - | |
| 134 | - $params = [ClassificationTypes::CATEGORY, $searchTerm, $searchTerm, $searchTerm]; | |
| 135 | - if (isset($args['where']) && is_array($args['where'])) { | |
| 136 | - foreach ($args['where'] as $field => $value) { | |
| 137 | - if (is_array($value)) { | |
| 138 | - $params = array_merge($params, $value); | |
| 139 | - } else { | |
| 140 | - $params[] = $value; | |
| 143 | + // ORDER BY — was raw interpolation of $args['order']. Sanitize the | |
| 144 | + // column to [A-Za-z0-9_] and whitelist the direction. Default unchanged. | |
| 145 | + $orderBy = 'name'; | |
| 146 | + $orderDir = 'ASC'; | |
| 147 | + if (isset($args['order']) && is_string($args['order']) && $args['order'] !== '') { | |
| 148 | + $parts = preg_split('/\s+/', trim($args['order'])); | |
| 149 | + $col = preg_replace('/[^a-zA-Z0-9_]/', '', (string) ($parts[0] ?? '')); | |
| 150 | + if ($col !== '') { | |
| 151 | + $orderBy = $col; | |
| 152 | + } | |
| 153 | + $dir = strtoupper((string) ($parts[1] ?? 'ASC')); | |
| 154 | + $orderDir = in_array($dir, ['ASC', 'DESC'], true) ? $dir : 'ASC'; | |
| 155 | + } | |
| 156 | + $orderClause = "ORDER BY `{$orderBy}` {$orderDir}"; | |
| 157 | + | |
| 158 | + // LIMIT — was raw interpolation. Cast to int; still support a legacy | |
| 159 | + // "offset, count" string form if any caller passes one. | |
| 160 | + $limitClause = ''; | |
| 161 | + if (isset($args['limit'])) { | |
| 162 | + if (is_string($args['limit']) && strpos($args['limit'], ',') !== false) { | |
| 163 | + [$off, $cnt] = array_map('intval', explode(',', $args['limit'], 2)); | |
| 164 | + if ($cnt > 0) { | |
| 165 | + $limitClause = "LIMIT {$off}, {$cnt}"; | |
| 141 | 166 | } |
| 167 | + } else { | |
| 168 | + $limitVal = (int) $args['limit']; | |
| 169 | + if ($limitVal > 0) { | |
| 170 | + $limitClause = "LIMIT {$limitVal}"; | |
| 171 | + } | |
| 142 | 172 | } |
| 143 | 173 | } |
| 174 | + | |
| 175 | + $query = "SELECT * FROM `{$table}` WHERE {$whereClause} {$orderClause} {$limitClause}"; | |
| 144 | 176 | |
| 145 | 177 | $results = $this->wpdb->get_results($this->wpdb->prepare($query, $params)); |
| 146 | 178 | return $results ?: []; |
| 147 | 179 | } |