PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Repositories/CustomerRepository.php +39 -3 3.0.8 → 3.0.16 View file →
@@ -241,13 +241,43 @@
241 241 ['id' => $customerId],
242 242 null,
243 243 ['%d']
244 244 );
245 -
245 +
246 246 return $result !== false;
247 247 }
248 248
249 249 /**
250 + * Link a WordPress user to a customer, ONLY when the customer has none yet.
251 + *
252 + * Deliberately narrow: the WHERE clause requires the current user_id to be
253 + * NULL/0, so this can add a login link but can never reassign or overwrite an
254 + * existing one — a customer's login is never silently switched to a different
255 + * account. Returns true only when a row was actually linked.
256 + */
257 + public function linkUserIfUnlinked(int $customerId, int $userId): bool
258 + {
259 + global $wpdb;
260 +
261 + if ($customerId <= 0 || $userId <= 0) {
262 + return false;
263 + }
264 +
265 + $table = $this->getTableName();
266 +
267 + $result = $wpdb->query($wpdb->prepare(
268 + "UPDATE `{$table}`
269 + SET user_id = %d, updated_at = %s
270 + WHERE id = %d AND (user_id IS NULL OR user_id = 0)",
271 + $userId,
272 + current_time('mysql'),
273 + $customerId
274 + ));
275 +
276 + return $result > 0;
277 + }
278 +
279 + /**
250 280 * Update customer from admin form
251 281 *
252 282 * This is used by the CustomerService::updateCustomer method when saving
253 283 * changes from the admin Edit Customer screen.
@@ -600,11 +630,17 @@
600 630 }
601 631
602 632 $whereClause = implode(' AND ', $where);
603 633
604 - // Count total
634 + // Count total. With no status/search filters the WHERE clause is all
635 + // literals, so there is nothing to bind — and prepare() on a
636 + // placeholder-free query is exactly what WordPress warns about. The data
637 + // query below always binds its LIMIT/OFFSET, so only this one needs the
638 + // guard.
605 639 $countQuery = "SELECT COUNT(*) FROM {$table} WHERE {$whereClause}";
606 - $total = (int) $wpdb->get_var($wpdb->prepare($countQuery, $params));
640 + $total = (int) (empty($params)
641 + ? $wpdb->get_var($countQuery)
642 + : $wpdb->get_var($wpdb->prepare($countQuery, $params)));
607 643
608 644 // Get data
609 645 $orderBy = sanitize_sql_orderby($args['orderby'] ?? 'created_at') ?: 'created_at';
610 646 $order = strtoupper($args['order'] ?? 'DESC') === 'ASC' ? 'ASC' : 'DESC';