X-Git-Url: https://git.mxchange.org/?p=mailer.git;a=blobdiff_plain;f=inc%2Fdb%2Flib-mysql3.php;h=f8eceec4b33efc69e89861f8fd5efbb7769e294b;hp=c0af2231674b1de36ea5a237807fb760a5ff26d9;hb=c45b1827a16928c65ecc1aea6a9d7a504c4874d4;hpb=52e8a0635bd0b7c653845685c55e4e5f251375fe diff --git a/inc/db/lib-mysql3.php b/inc/db/lib-mysql3.php index c0af223167..f8eceec4b3 100644 --- a/inc/db/lib-mysql3.php +++ b/inc/db/lib-mysql3.php @@ -32,70 +32,80 @@ ************************************************************************/ // Some security stuff... -if (ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) -{ +if (ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) { $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php"; require($INC); } // SQL queries -function SQL_QUERY($sql_string, $F, $L) -{ +function SQL_QUERY($sql_string, $F, $L) { global $link, $CSS, $_CONFIG, $OK; + // Remove \t, \n and \r from queries they may confuse some MySQL version I have heard + $sql_string = str_replace("\t", " ", str_replace("\n", " ", str_replace("\r", " ", $sql_string))); + + // Starting time + $querytimeBefore = array_sum(explode(' ', microtime())); + // Run SQL command $result = @mysql_query($sql_string, $link) or ADD_FATAL($F." (".$L."):".mysql_error()."
".MYSQL_QUERY_STRING."
".$sql_string); - // Count this query - if (!isset($_CONFIG['sql_count'])) $_CONFIG['sql_count'] = 0; - $_CONFIG['sql_count']++; + // Save last successfull query + $_CONFIG['db_last_query'] = $sql_string; + + // Ending time + $querytimeAfter = array_sum(explode(' ', microtime())); + + // Calculate query time + $queryTime = $querytimeAfter - $querytimeBefore; + + // Count this query + if (!isset($_CONFIG['sql_count'])) $_CONFIG['sql_count'] = 0; + $_CONFIG['sql_count']++; - // Debug output - //* DEBUG: */ print "Query=".$sql_string.", affected=".SQL_AFFECTEDROWS().", numrows=".SQL_NUMROWS($result)."
\n"; + // Debug output + //* DEBUG: */ print "Query=
".$sql_string."
, affected=".SQL_AFFECTEDROWS().", numrows=".SQL_NUMROWS($result)."
\n"; - if (($CSS != "1") && ($CSS != "-1") && (DEBUG_MODE) && (DEBUG_SQL)) - { + if (($CSS != "1") && ($CSS != "-1") && (isBooleanConstantAndTrue('DEBUG_MODE')) && (isBooleanConstantAndTrue('DEBUG_SQL'))) { // // Debugging stuff... // - $fp = @fopen(PATH."debug.log", 'a') or mxchange_die("Cannot write debug.log!"); + $fp = @fopen(PATH."inc/cache/mysql.log", 'a') or mxchange_die("Cannot write mysql.log!"); if (!isset($OK)) { // Write first entry fwrite($fp, "Module=".$GLOBALS['module']."\n"); $OK = true; - } - fwrite($fp, $F."(LINE=".$L."|NUM=".SQL_NUMROWS($result)."|AFFECTED=".SQL_AFFECTEDROWS()."): ".str_replace('\r', '', str_replace('\n', " ", $sql_string))."\n"); + } // END - if + fwrite($fp, $F."(LINE=".$L."|NUM=".SQL_NUMROWS($result)."|AFFECTED=".SQL_AFFECTEDROWS()."|QUERYTIME:".$queryTime."): ".str_replace('\r', "", str_replace('\n', " ", $sql_string))."\n"); fclose($fp); - } + } // END - if // Count DB hits - if (!isset($_CONFIG['db_hits'])) - { + if (!isset($_CONFIG['db_hits'])) { // Count in dummy variable - $_CONFIG['db_hits'] = 0; - } - else - { + $_CONFIG['db_hits'] = 1; + } else { // Count to config array $_CONFIG['db_hits']++; } + + // Return the result return $result; } // SQL num rows -function SQL_NUMROWS($result) -{ - if ($result != false) - { +function SQL_NUMROWS($result) { + // Is the result a valid resource? + if (is_resource($result)) { + // Get the count of rows from database $lines = @mysql_num_rows($result); - if (empty($lines)) $lines = "0"; - } - else - { + // Is the result empty? Then we have an error! + if (empty($lines)) $lines = "0"; + } else { // No resource given, no lines found! $lines = "0"; } @@ -103,8 +113,7 @@ function SQL_NUMROWS($result) } // SQL affected rows -function SQL_AFFECTEDROWS($lnk="x", $F="dummy", $L="dummy") -{ +function SQL_AFFECTEDROWS($lnk="x", $F="dummy", $L="dummy") { global $link; // $lnk will be ignored for now! $lines = @mysql_affected_rows($link); @@ -112,16 +121,14 @@ function SQL_AFFECTEDROWS($lnk="x", $F="dummy", $L="dummy") } // SQL fetch row -function SQL_FETCHROW($result) -{ +function SQL_FETCHROW($result) { $DATA = array(); $DATA = @mysql_fetch_row($result); return $DATA; } // SQL fetch array -function SQL_FETCHARRAY($res=false, $nr=0, $remove_numerical=true) -{ +function SQL_FETCHARRAY($res=false, $nr=0, $remove_numerical=true) { // Is a result resource set? if (!$res) return false; @@ -132,15 +139,12 @@ function SQL_FETCHARRAY($res=false, $nr=0, $remove_numerical=true) $row = @mysql_fetch_array($res); // Return only arrays here - if (is_array($row)) - { + if (is_array($row)) { // Shall we remove numerical data here automatically? - if ($remove_numerical) - { - // So let's remove all numerical elements to save memory! + if ($remove_numerical) { + // So let's remove all numerical elements to save memory! $max = count($row); - for ($idx = 0; $idx < ($max / 2); $idx++) - { + for ($idx = 0; $idx < ($max / 2); $idx++) { // Remove entry unset($row[$idx]); } @@ -148,84 +152,66 @@ function SQL_FETCHARRAY($res=false, $nr=0, $remove_numerical=true) // Return row return $row; - } - else - { + } else { // Return a false here... return false; } } // SQL result -function SQL_RESULT($res, $row, $field) -{ +function SQL_RESULT($res, $row, $field) { $result = @mysql_result($res, $row, $field); return $result; } // SQL connect -function SQL_CONNECT($host, $login, $password, $F, $L) -{ +function SQL_CONNECT($host, $login, $password, $F, $L) { $connect = @mysql_connect($host, $login, $password) or ADD_FATAL($F." (".$L."):".mysql_error()); return $connect; } // SQL select database -function SQL_SELECT_DB($DB, $link, $F, $L) -{ +function SQL_SELECT_DB($dbName, $link, $F, $L) { $select = false; if (is_resource($link)) { - $select = @mysql_select_db($DB, $link) or ADD_FATAL($F." (".$L."):".mysql_error()); + $select = @mysql_select_db($dbName, $link) or ADD_FATAL($F." (".$L."):".mysql_error()); } return $select; } // SQL close link -function SQL_CLOSE($link, $F, $L) -{ +function SQL_CLOSE(&$link, $F, $L) { + // Is there still a valid link? + if (!is_resource($link)) { + // Skip double close + return false; + } // END - if + global $_CONFIG, $cacheInstance, $cacheArray; - if ((GET_EXT_VERSION("cache") >= "0.0.7") && (isset($_CONFIG['db_hits'])) && (isset($_CONFIG['cache_hits'])) && (is_object($cacheInstance))) - { + if ((GET_EXT_VERSION("cache") >= "0.0.7") && (isset($_CONFIG['db_hits'])) && (isset($_CONFIG['cache_hits'])) && (is_object($cacheInstance))) { // Update counter for db/cache - $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_config SET db_hits=%d, cache_hits=%d WHERE config=0 LIMIT 1", - array(bigintval($_CONFIG['db_hits']), bigintval($_CONFIG['cache_hits'])), __FILE__, __LINE__); - - // Update cache here - if (GET_EXT_VERSION("cache") >= "0.1.2") - { - if ($cacheInstance->cache_file("config", true)) - { - // Replace data - $cacheInstance->cache_replace("cache_hits", $_CONFIG['cache_hits'], "0", $cacheArray); - $cacheInstance->cache_replace("db_hits" , $_CONFIG['db_hits'] , "0", $cacheArray); - } - } - } + UPDATE_CONFIG(array("db_hits", "cache_hits"), array(bigintval($_CONFIG['db_hits']), bigintval($_CONFIG['cache_hits']))); + } // END - if - // Close database link + // Close database link and forget the link $close = @mysql_close($link) or ADD_FATAL($F." (".$L."):".mysql_error()); + $link = null; return $close; } // SQL free result -function SQL_FREERESULT($result) -{ +function SQL_FREERESULT($result) { $res = @mysql_free_result($result); return $res; } // SQL string escaping -function SQL_QUERY_ESC($qstring, $data, $file, $line, $run=true, $strip=true) -{ +function SQL_QUERY_ESC($qstring, $data, $file, $line, $run=true, $strip=true) { global $link; $eval = "\$query = sprintf(\"".$qstring."\""; - foreach ($data as $var) - { - if (!empty($var)) - { + foreach ($data as $var) { + if ((!empty($var)) || ($var === 0)) { if ($strip) { $eval .= ", SQL_ESCAPE(\"".strip_tags($var)."\")"; } else { $eval .= ", SQL_ESCAPE(\"".$var."\")"; } - } - else - { + } else { $eval .= ", ''"; } } @@ -234,33 +220,35 @@ function SQL_QUERY_ESC($qstring, $data, $file, $line, $run=true, $strip=true) // Debugging // //$fp = fopen(PATH."escape_debug.log", 'a') or mxchange_die("Cannot write debug.log!"); - //fwrite($fp, $file."(".$line."): ".str_replace('\r', '', str_replace('\n', " ", $eval))."\n"); + //fwrite($fp, $file."(".$line."): ".str_replace('\r', "", str_replace('\n', " ", $eval))."\n"); //fclose($fp); eval($eval); - if ($run) - { + if ($run) { // Run SQL query (default) return SQL_QUERY($query, $file, $line); - } - else - { + } else { // Return secured string return $query; } } // Get ID from last INSERT command -function SQL_INSERTID() -{ +function SQL_INSERTID() { return @mysql_insert_id(); } // Escape a string for the database -function SQL_ESCAPE($str) -{ +function SQL_ESCAPE($str, $secureString = true) { global $link; + + // Secure string first? (which is the default behaviour!) + if ($secureString) { + // Then do it here + $str = secureString($str); + } // END - if + if (!is_resource($link)) { // Fall-back to addslashes() when there is no link return addslashes($str); - } + } // END - if if (function_exists('mysql_real_escape_string')) { // The new and improved version @@ -276,10 +264,35 @@ function SQL_ESCAPE($str) // SELECT query string from table, columns and so on... ;-) function SQL_RESULT_FROM_ARRAY ($table, $columns, $idRow, $id) { // Prepare the SQL statement - $SQL = "SELECT ".implode(", ", $columns)." FROM "._MYSQL_PREFIX."_".$table." WHERE ".$idRow."=%d LIMIT 1"; + $SQL = "SELECT ".implode(", ", $columns)." FROM "._MYSQL_PREFIX."_".$table." WHERE ".$idRow."=%s LIMIT 1"; // Return the result return SQL_QUERY_ESC($SQL, array(bigintval($id)), __FILE__, __LINE__); } +// ALTER TABLE wrapper function +function SQL_ALTER_TABLE($sql, $F, $L) { + // Shall we add? + if (eregi("ADD", $sql) > 0) { + // Extract table name + $tableArray = explode(" ", $sql); + $tableName = str_replace("`", "", $tableArray[2]); + + // And column name as well + $columnName = str_replace("`", "", $tableArray[4]); + + // Get column information + $result = SQL_QUERY_ESC("SHOW COLUMNS FROM %s LIKE '%s'", + array($tableName, $columnName), __FILE__, __LINE__); + + // Do we have no entry? + if (SQL_NUMROWS($result) == 0) { + // Do the query + return SQL_QUERY($sql, $F, $L, false); + } // END - if + } else { + // Send it to the SQL_QUERY() function + return SQL_QUERY($sql, $F, $L, false); + } +} // ?>