Skip to content

Commit 12a54b4

Browse files
Merge pull request #18700 from kamil-tekiela/escapeString-in-Search
Replace escapeString in Search
2 parents 94ed296 + bb279f6 commit 12a54b4

3 files changed

Lines changed: 15 additions & 25 deletions

File tree

‎phpstan-baseline.neon‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18816,7 +18816,7 @@ parameters:
1881618816
path: src/Table/Search.php
1881718817

1881818818
-
18819-
message: "#^Parameter \\#1 \\$str of method PhpMyAdmin\\\\DatabaseInterface\\:\\:escapeString\\(\\) expects string, mixed given\\.$#"
18819+
message: "#^Parameter \\#1 \\$str of method PhpMyAdmin\\\\DatabaseInterface\\:\\:quoteString\\(\\) expects string, mixed given\\.$#"
1882018820
count: 3
1882118821
path: src/Table/Search.php
1882218822

‎psalm-baseline.xml‎

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -12307,12 +12307,6 @@
1230712307
</PossiblyUndefinedArrayOffset>
1230812308
</file>
1230912309
<file src="src/Table/Search.php">
12310-
<DeprecatedMethod>
12311-
<code>escapeString</code>
12312-
<code>escapeString</code>
12313-
<code>escapeString</code>
12314-
<code>escapeString</code>
12315-
</DeprecatedMethod>
1231612310
<MixedArgument>
1231712311
<code><![CDATA[$_POST['criteriaColumnNames'][$columnIndex]]]></code>
1231812312
<code><![CDATA[$_POST['criteriaColumnTypes'][$columnIndex]]]></code>
@@ -12342,6 +12336,7 @@
1234212336
<code>$criteriaValues</code>
1234312337
<code>$criteriaValues</code>
1234412338
<code>$criteriaValues</code>
12339+
<code><![CDATA[$needsQuoting ? $this->dbi->quoteString($criteriaValues) : $criteriaValues]]></code>
1234512340
<code><![CDATA[$values[0] ?? '']]></code>
1234612341
<code><![CDATA[$values[1] ?? '']]></code>
1234712342
</MixedOperand>

‎src/Table/Search.php‎

Lines changed: 13 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -162,14 +162,8 @@ private function getWhereClause(
162162
// (like INT), for a LIKE we always quote the value. MySQL converts
163163
// strings to numbers and numbers to strings as necessary
164164
// during the comparison
165-
if (
166-
preg_match('@char|binary|blob|text|set|date|time|year|uuid@i', $types)
167-
|| mb_strpos(' ' . $funcType, 'LIKE')
168-
) {
169-
$quot = '\'';
170-
} else {
171-
$quot = '';
172-
}
165+
$needsQuoting = preg_match('@char|binary|blob|text|set|date|time|year|uuid@i', $types)
166+
|| mb_strpos(' ' . $funcType, 'LIKE');
173167

174168
// LIKE %...%
175169
if ($funcType === 'LIKE %...%') {
@@ -193,8 +187,8 @@ private function getWhereClause(
193187
&& $funcType !== 'BETWEEN'
194188
&& $funcType !== 'NOT BETWEEN'
195189
) {
196-
return $backquotedName . ' ' . $funcType . ' ' . $quot
197-
. $this->dbi->escapeString($criteriaValues) . $quot;
190+
return $backquotedName . ' ' . $funcType . ' '
191+
. ($needsQuoting ? $this->dbi->quoteString($criteriaValues) : $criteriaValues);
198192
}
199193

200194
$funcType = str_replace(' (...)', '', $funcType);
@@ -209,15 +203,18 @@ private function getWhereClause(
209203

210204
// quote values one by one
211205
$emptyKey = false;
212-
foreach ($values as $key => &$value) {
206+
foreach ($values as $key => $value) {
213207
if ($value === '') {
214208
$emptyKey = $key;
215-
$value = 'NULL';
209+
$values[$key] = 'NULL';
210+
continue;
211+
}
212+
213+
if (! $needsQuoting) {
216214
continue;
217215
}
218216

219-
$value = $quot . $this->dbi->escapeString(trim($value))
220-
. $quot;
217+
$values[$key] = $this->dbi->quoteString(trim($value));
221218
}
222219

223220
if ($funcType === 'BETWEEN' || $funcType === 'NOT BETWEEN') {
@@ -334,11 +331,9 @@ private function getEnumWhereClause(mixed $criteriaValues, string $funcType): st
334331
$parensClose = '';
335332
}
336333

337-
$enumWhere = '\''
338-
. $this->dbi->escapeString($criteriaValues[0]) . '\'';
334+
$enumWhere = $this->dbi->quoteString($criteriaValues[0]);
339335
for ($e = 1; $e < $enumSelectedCount; $e++) {
340-
$enumWhere .= ', \''
341-
. $this->dbi->escapeString($criteriaValues[$e]) . '\'';
336+
$enumWhere .= ', ' . $this->dbi->quoteString($criteriaValues[$e]);
342337
}
343338

344339
return ' ' . $funcType . ' ' . $parensOpen

0 commit comments

Comments
 (0)