Skip to content

Commit 547e4d8

Browse files
Merge pull request #20022 from MauricioFauth/sql-request
Replace request globals with ServerRequest object in Sql and Display\Results classes
2 parents edf7b02 + 190de2a commit 547e4d8

14 files changed

Lines changed: 133 additions & 145 deletions

File tree

‎phpstan-baseline.neon‎

Lines changed: 6 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -12231,13 +12231,13 @@ parameters:
1223112231
-
1223212232
message: '#^Cannot cast mixed to int\.$#'
1223312233
identifier: cast.int
12234-
count: 1
12234+
count: 3
1223512235
path: src/Sql.php
1223612236

1223712237
-
1223812238
message: '#^Construct empty\(\) is not allowed\. Use more strict comparison\.$#'
1223912239
identifier: empty.notAllowed
12240-
count: 10
12240+
count: 4
1224112241
path: src/Sql.php
1224212242

1224312243
-
@@ -12264,12 +12264,6 @@ parameters:
1226412264
count: 1
1226512265
path: src/Sql.php
1226612266

12267-
-
12268-
message: '#^Only booleans are allowed in &&, mixed given on the right side\.$#'
12269-
identifier: booleanAnd.rightNotBoolean
12270-
count: 3
12271-
path: src/Sql.php
12272-
1227312267
-
1227412268
message: '#^Only booleans are allowed in &&, string given on the left side\.$#'
1227512269
identifier: booleanAnd.leftNotBoolean
@@ -12295,14 +12289,14 @@ parameters:
1229512289
path: src/Sql.php
1229612290

1229712291
-
12298-
message: '#^Only booleans are allowed in a negated boolean, mixed given\.$#'
12299-
identifier: booleanNot.exprNotBoolean
12292+
message: '#^Only booleans are allowed in an if condition, PhpMyAdmin\\Dbal\\ResultInterface\|false given\.$#'
12293+
identifier: if.condNotBoolean
1230012294
count: 1
1230112295
path: src/Sql.php
1230212296

1230312297
-
12304-
message: '#^Only booleans are allowed in an if condition, PhpMyAdmin\\Dbal\\ResultInterface\|false given\.$#'
12305-
identifier: if.condNotBoolean
12298+
message: '#^Parameter \#1 \$label of method PhpMyAdmin\\Sql\:\:getBookmarkCreatedMessage\(\) expects string\|null, mixed given\.$#'
12299+
identifier: argument.type
1230612300
count: 1
1230712301
path: src/Sql.php
1230812302

@@ -12348,24 +12342,12 @@ parameters:
1234812342
count: 2
1234912343
path: src/Sql.php
1235012344

12351-
-
12352-
message: '#^Parameter \#3 \$column of method PhpMyAdmin\\Sql\:\:cleanupRelations\(\) expects string, mixed given\.$#'
12353-
identifier: argument.type
12354-
count: 1
12355-
path: src/Sql.php
12356-
1235712345
-
1235812346
message: '#^Parameter \#3 \$subject of function str_replace expects array\<string\>\|string, mixed given\.$#'
1235912347
identifier: argument.type
1236012348
count: 1
1236112349
path: src/Sql.php
1236212350

12363-
-
12364-
message: '#^Parameter \#4 \$bookmarkLabel of method PhpMyAdmin\\Sql\:\:storeTheQueryAsBookmark\(\) expects string, mixed given\.$#'
12365-
identifier: argument.type
12366-
count: 1
12367-
path: src/Sql.php
12368-
1236912351
-
1237012352
message: '''
1237112353
#^Call to deprecated method getInstance\(\) of class PhpMyAdmin\\Config\:

‎psalm-baseline.xml‎

Lines changed: 6 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -3848,13 +3848,18 @@
38483848
<code><![CDATA[$expr]]></code>
38493849
<code><![CDATA[$expr]]></code>
38503850
<code><![CDATA[$field]]></code>
3851+
<code><![CDATA[$geoOption]]></code>
38513852
<code><![CDATA[$hiddenFields['session_max_rows']]]></code>
38523853
<code><![CDATA[$i]]></code>
38533854
<code><![CDATA[$i]]></code>
38543855
<code><![CDATA[$identifier]]></code>
38553856
<code><![CDATA[$meta->name]]></code>
3857+
<code><![CDATA[$pftext]]></code>
3858+
<code><![CDATA[$pos]]></code>
38563859
<code><![CDATA[$query]]></code>
38573860
<code><![CDATA[$relationalDisplay]]></code>
3861+
<code><![CDATA[$relationalDisplay]]></code>
3862+
<code><![CDATA[$sessionMaxRows]]></code>
38583863
<code><![CDATA[$value]]></code>
38593864
</MixedAssignment>
38603865
<MixedOperand>
@@ -8004,6 +8009,7 @@
80048009
</InvalidNullableReturnType>
80058010
<MixedArgument>
80068011
<code><![CDATA[$numberOfLine / $maxRows]]></code>
8012+
<code><![CDATA[$request->getQueryParam('label')]]></code>
80078013
<code><![CDATA[$sortCol]]></code>
80088014
</MixedArgument>
80098015
<MixedArrayAccess>
@@ -8046,17 +8052,11 @@
80468052
<code><![CDATA[$row[$column]]]></code>
80478053
</NullableReturnStatement>
80488054
<PossiblyInvalidArgument>
8049-
<code><![CDATA[$_POST['bkm_label']]]></code>
8050-
<code><![CDATA[$_POST['dropped_column'] ?? '']]></code>
80518055
<code><![CDATA[$numRows]]></code>
80528056
<code><![CDATA[$numRows]]></code>
80538057
<code><![CDATA[$numRows]]></code>
80548058
<code><![CDATA[$numRows]]></code>
80558059
</PossiblyInvalidArgument>
8056-
<PossiblyInvalidCast>
8057-
<code><![CDATA[$_POST['bkm_label']]]></code>
8058-
<code><![CDATA[$_POST['dropped_column'] ?? '']]></code>
8059-
</PossiblyInvalidCast>
80608060
<PossiblyInvalidOperand>
80618061
<code><![CDATA[$numRows]]></code>
80628062
<code><![CDATA[$sortCol]]></code>
@@ -8081,16 +8081,7 @@
80818081
</RedundantCondition>
80828082
<RiskyTruthyFalsyComparison>
80838083
<code><![CDATA[! $index->isUnique()]]></code>
8084-
<code><![CDATA[$_POST['grid_edit']]]></code>
8085-
<code><![CDATA[$_POST['printview']]]></code>
8086-
<code><![CDATA[$_POST['printview']]]></code>
80878084
<code><![CDATA[$table]]></code>
8088-
<code><![CDATA[empty($_GET['id_bookmark'])]]></code>
8089-
<code><![CDATA[empty($_GET['id_bookmark'])]]></code>
8090-
<code><![CDATA[empty($_POST['bkm_label'])]]></code>
8091-
<code><![CDATA[empty($_POST['is_browse_distinct'])]]></code>
8092-
<code><![CDATA[empty($_POST['purge'])]]></code>
8093-
<code><![CDATA[empty($_REQUEST['ajax_page_request'])]]></code>
80948085
<code><![CDATA[empty($statement->altered[0]->field->column)]]></code>
80958086
</RiskyTruthyFalsyComparison>
80968087
</file>
@@ -10185,7 +10176,6 @@
1018510176
<code><![CDATA[testSetConfigParamsForDisplayTable]]></code>
1018610177
<code><![CDATA[testSetConfigParamsForDisplayTable]]></code>
1018710178
<code><![CDATA[testSetConfigParamsForDisplayTable]]></code>
10188-
<code><![CDATA[testSetConfigParamsForDisplayTable]]></code>
1018910179
</PossiblyInvalidArgument>
1019010180
<PropertyTypeCoercion>
1019110181
<code><![CDATA[$config->settings]]></code>

‎src/Controllers/Database/MultiTableQuery/QueryController.php‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ public function __invoke(ServerRequest $request): Response
3232
$goto = Url::getFromRoute('/database/multi-table-query');
3333

3434
$this->response->addHTML($this->sql->executeQueryAndSendQueryResponse(
35+
$request,
3536
null,
3637
false, // is_gotofile
3738
$db, // db

‎src/Controllers/Import/ImportController.php‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -632,6 +632,7 @@ public function __invoke(ServerRequest $request): Response
632632
}
633633

634634
$htmlOutput .= $this->sql->executeQueryAndGetQueryResponse(
635+
$request,
635636
$statementInfo,
636637
false, // is_gotofile
637638
Current::$database, // db
@@ -656,6 +657,7 @@ public function __invoke(ServerRequest $request): Response
656657
$request->getParsedBodyParamAsString('sql_query'),
657658
$request->getParsedBodyParamAsString('bkm_label'),
658659
$request->hasBodyParam('bkm_replace'),
660+
$request->hasBodyParam('bkm_all_users'),
659661
);
660662
}
661663

@@ -683,6 +685,7 @@ public function __invoke(ServerRequest $request): Response
683685
$request->getParsedBodyParamAsString('sql_query'),
684686
$request->getParsedBodyParamAsString('bkm_label'),
685687
$request->hasBodyParam('bkm_replace'),
688+
$request->hasBodyParam('bkm_all_users'),
686689
);
687690
}
688691

‎src/Controllers/Sql/RelationalValuesController.php‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,17 +29,19 @@ public function __invoke(ServerRequest $request): Response
2929
$column = $request->getParsedBodyParamAsString('column', '');
3030
$relationKeyOrDisplayColumn = $request->getParsedBodyParamAsStringOrNull('relation_key_or_display_column');
3131

32+
$currentValueParam = $request->getParsedBodyParamAsString('curr_value', '');
3233
if ($_SESSION['tmpval']['relational_display'] === 'D' && $relationKeyOrDisplayColumn !== null) {
3334
$currValue = $relationKeyOrDisplayColumn;
3435
} else {
35-
$currValue = $request->getParsedBodyParamAsString('curr_value', '');
36+
$currValue = $currentValueParam;
3637
}
3738

3839
$dropdown = $this->sql->getHtmlForRelationalColumnDropdown(
3940
Current::$database,
4041
Current::$table,
4142
$column,
4243
$currValue,
44+
$currentValueParam,
4345
);
4446
$this->response->addJSON('dropdown', $dropdown);
4547

‎src/Controllers/Sql/SqlController.php‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -164,6 +164,7 @@ public function __invoke(ServerRequest $request): Response
164164

165165
Current::$messageToShow = $request->getParsedBodyParamAsString('message_to_show', '');
166166
$this->response->addHTML($this->sql->executeQueryAndSendQueryResponse(
167+
$request,
167168
$statementInfo,
168169
$isGotofile,
169170
Current::$database,

‎src/Controllers/Table/DeleteRowsController.php‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,7 @@ public function __invoke(ServerRequest $request): Response
6666
}
6767

6868
$this->response->addHTML($this->sql->executeQueryAndSendQueryResponse(
69+
$request,
6970
null,
7071
false,
7172
Current::$database,

‎src/Controllers/Table/SearchController.php‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -211,7 +211,7 @@ public function __invoke(ServerRequest $request): Response
211211
if (! isset($_POST['columnsToDisplay']) && ! isset($_POST['displayAllColumns'])) {
212212
$this->displaySelectionFormAction();
213213
} else {
214-
$this->doSelectionAction();
214+
$this->doSelectionAction($request);
215215
}
216216

217217
return $this->response->response();
@@ -220,7 +220,7 @@ public function __invoke(ServerRequest $request): Response
220220
/**
221221
* Do selection action
222222
*/
223-
private function doSelectionAction(): void
223+
private function doSelectionAction(ServerRequest $request): void
224224
{
225225
/**
226226
* Selection criteria have been submitted -> do the work
@@ -231,6 +231,7 @@ private function doSelectionAction(): void
231231
* Add this to ensure following procedures included running correctly.
232232
*/
233233
$this->response->addHTML($this->sql->executeQueryAndSendQueryResponse(
234+
$request,
234235
null,
235236
false, // is_gotofile
236237
Current::$database, // db

‎src/Controllers/Table/Structure/BrowseController.php‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ public function __invoke(ServerRequest $request): Response
3535
return $this->response->response();
3636
}
3737

38-
$this->displayTableBrowseForSelectedColumns(UrlParams::$goto);
38+
$this->displayTableBrowseForSelectedColumns($request, UrlParams::$goto);
3939

4040
return $this->response->response();
4141
}
@@ -45,7 +45,7 @@ public function __invoke(ServerRequest $request): Response
4545
*
4646
* @param string $goto goto page url
4747
*/
48-
private function displayTableBrowseForSelectedColumns(string $goto): void
48+
private function displayTableBrowseForSelectedColumns(ServerRequest $request, string $goto): void
4949
{
5050
$fields = [];
5151
foreach ($_POST['selected_fld'] as $sval) {
@@ -64,6 +64,7 @@ private function displayTableBrowseForSelectedColumns(string $goto): void
6464

6565
$this->response->addHTML(
6666
$this->sql->executeQueryAndGetQueryResponse(
67+
$request,
6768
$statementInfo,
6869
false, // is_gotofile
6970
Current::$database, // db

‎src/Display/Results.php‎

Lines changed: 22 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
use PhpMyAdmin\Dbal\ResultInterface;
1515
use PhpMyAdmin\FieldMetadata;
1616
use PhpMyAdmin\Html\Generator;
17+
use PhpMyAdmin\Http\ServerRequest;
1718
use PhpMyAdmin\Indexes\Index;
1819
use PhpMyAdmin\Indexes\IndexColumn;
1920
use PhpMyAdmin\Message;
@@ -2789,7 +2790,7 @@ private function getDataCellForNonNumericColumns(
27892790
* @todo currently this is called twice unnecessary
27902791
* @todo ignore LIMIT and ORDER in query!?
27912792
*/
2792-
public function setConfigParamsForDisplayTable(StatementInfo $statementInfo): void
2793+
public function setConfigParamsForDisplayTable(ServerRequest $request, StatementInfo $statementInfo): void
27932794
{
27942795
$sqlMd5 = md5($this->server . $this->db . $this->sqlQuery);
27952796
$query = $_SESSION['tmpval']['query'][$sqlMd5] ?? [];
@@ -2801,97 +2802,74 @@ public function setConfigParamsForDisplayTable(StatementInfo $statementInfo): vo
28012802
}
28022803

28032804
// The value can also be from _GET as described on issue #16146 when sorting results
2804-
$sessionMaxRows = $_GET['session_max_rows'] ?? $_POST['session_max_rows'] ?? '';
2805+
$sessionMaxRows = $request->getParam('session_max_rows');
28052806

28062807
if (is_numeric($sessionMaxRows)) {
28072808
$query['max_rows'] = (int) $sessionMaxRows;
2808-
unset($_GET['session_max_rows'], $_POST['session_max_rows']);
28092809
} elseif ($sessionMaxRows === self::ALL_ROWS) {
28102810
$query['max_rows'] = self::ALL_ROWS;
2811-
unset($_GET['session_max_rows'], $_POST['session_max_rows']);
28122811
} elseif (empty($query['max_rows'])) {
28132812
$query['max_rows'] = $this->config->config->maxRows;
28142813
}
28152814

2816-
if (isset($_REQUEST['pos']) && is_numeric($_REQUEST['pos'])) {
2817-
$query['pos'] = (int) $_REQUEST['pos'];
2818-
unset($_REQUEST['pos']);
2815+
$pos = $request->getParam('pos');
2816+
if (is_numeric($pos)) {
2817+
$query['pos'] = (int) $pos;
28192818
} elseif (empty($query['pos'])) {
28202819
$query['pos'] = 0;
28212820
}
28222821

28232822
// Full text is needed in case of explain statements, if not specified.
28242823
$fullText = $statementInfo->flags->queryType === StatementType::Explain;
28252824

2826-
if (
2827-
isset($_REQUEST['pftext']) && in_array(
2828-
$_REQUEST['pftext'],
2829-
[self::DISPLAY_PARTIAL_TEXT, self::DISPLAY_FULL_TEXT],
2830-
true,
2831-
)
2832-
) {
2833-
$query['pftext'] = $_REQUEST['pftext'];
2834-
unset($_REQUEST['pftext']);
2825+
$pftext = $request->getParam('pftext');
2826+
if (in_array($pftext, [self::DISPLAY_PARTIAL_TEXT, self::DISPLAY_FULL_TEXT], true)) {
2827+
$query['pftext'] = $pftext;
28352828
} elseif ($fullText) {
28362829
$query['pftext'] = self::DISPLAY_FULL_TEXT;
28372830
} elseif (empty($query['pftext'])) {
28382831
$query['pftext'] = self::DISPLAY_PARTIAL_TEXT;
28392832
}
28402833

2841-
if (
2842-
isset($_REQUEST['relational_display']) && in_array(
2843-
$_REQUEST['relational_display'],
2844-
[self::RELATIONAL_KEY, self::RELATIONAL_DISPLAY_COLUMN],
2845-
true,
2846-
)
2847-
) {
2848-
$query['relational_display'] = $_REQUEST['relational_display'];
2849-
unset($_REQUEST['relational_display']);
2834+
$relationalDisplay = $request->getParam('relational_display');
2835+
if (in_array($relationalDisplay, [self::RELATIONAL_KEY, self::RELATIONAL_DISPLAY_COLUMN], true)) {
2836+
$query['relational_display'] = $relationalDisplay;
28502837
} elseif (empty($query['relational_display'])) {
28512838
// The current session value has priority over a
28522839
// change via Settings; this change will be apparent
28532840
// starting from the next session
28542841
$query['relational_display'] = $this->config->settings['RelationalDisplay'];
28552842
}
28562843

2857-
if (
2858-
isset($_REQUEST['geoOption']) && in_array(
2859-
$_REQUEST['geoOption'],
2860-
[self::GEOMETRY_DISP_WKT, self::GEOMETRY_DISP_WKB, self::GEOMETRY_DISP_GEOM],
2861-
true,
2862-
)
2863-
) {
2864-
$query['geoOption'] = $_REQUEST['geoOption'];
2865-
unset($_REQUEST['geoOption']);
2844+
$geoOption = $request->getParam('geoOption');
2845+
if (in_array($geoOption, [self::GEOMETRY_DISP_WKT, self::GEOMETRY_DISP_WKB, self::GEOMETRY_DISP_GEOM], true)) {
2846+
$query['geoOption'] = $geoOption;
28662847
} elseif (empty($query['geoOption'])) {
28672848
$query['geoOption'] = self::GEOMETRY_DISP_GEOM;
28682849
}
28692850

2870-
if (isset($_REQUEST['display_binary'])) {
2851+
if ($request->has('display_binary')) {
28712852
$query['display_binary'] = true;
2872-
unset($_REQUEST['display_binary']);
2873-
} elseif (isset($_REQUEST['display_options_form'])) {
2853+
} elseif ($request->has('display_options_form')) {
28742854
// we know that the checkbox was unchecked
28752855
unset($query['display_binary']);
2876-
} elseif (! isset($_REQUEST['full_text_button'])) {
2856+
} elseif (! $request->has('full_text_button')) {
28772857
// selected by default because some operations like OPTIMIZE TABLE
28782858
// and all queries involving functions return "binary" contents,
28792859
// according to low-level field flags
28802860
$query['display_binary'] = true;
28812861
}
28822862

2883-
if (isset($_REQUEST['display_blob'])) {
2863+
if ($request->has('display_blob')) {
28842864
$query['display_blob'] = true;
2885-
unset($_REQUEST['display_blob']);
2886-
} elseif (isset($_REQUEST['display_options_form'])) {
2865+
} elseif ($request->has('display_options_form')) {
28872866
// we know that the checkbox was unchecked
28882867
unset($query['display_blob']);
28892868
}
28902869

2891-
if (isset($_REQUEST['hide_transformation'])) {
2870+
if ($request->has('hide_transformation')) {
28922871
$query['hide_transformation'] = true;
2893-
unset($_REQUEST['hide_transformation']);
2894-
} elseif (isset($_REQUEST['display_options_form'])) {
2872+
} elseif ($request->has('display_options_form')) {
28952873
// we know that the checkbox was unchecked
28962874
unset($query['hide_transformation']);
28972875
}

0 commit comments

Comments
 (0)