function PHPSQLresolvePositionalArguments($sqlTree) { $returnTree = $sqlTree; //subqueries can be in FROM and WHERE if (!empty($returnTree['FROM'])) { foreach ($returnTree['FROM'] as &$fromNode) { if (isSubquery($fromNode)) { $fromNode['sub_tree'] = PHPSQLresolvePositionalArguments($fromNode['sub_tree']); $fromNode['base_expr'] = getBaseExpr($fromNode); } } } if (!empty($returnTree['WHERE'])) { foreach ($returnTree['WHERE'] as &$whereNode) { if (isSubquery($whereNode)) { $whereNode['sub_tree'] = PHPSQLresolvePositionalArguments($whereNode['sub_tree']); $whereNode['base_expr'] = getBaseExpr($whereNode); } } } //only do something if there is an ORDER BY if (!empty($returnTree['ORDER'])) { foreach ($returnTree['ORDER'] as &$orderNode) { if ($orderNode['expr_type'] === "pos") { $selNode = $returnTree['SELECT'][(int) $orderNode['base_expr'] - 1]; //rewrite things if (!isColref($selNode)) { $orderNode['expr_type'] = "colref"; if (hasAlias($selNode)) { $orderNode['base_expr'] = extractColumnAlias($selNode); } else { $orderNode['base_expr'] = buildEscapedString(array($selNode)); } $orderNode['no_quotes'] = array("delim" => ".", "parts" => array($orderNode['base_expr'])); } else { $orderNode['expr_type'] = $selNode['expr_type']; $orderNode['base_expr'] = $selNode['base_expr']; if (!empty($selNode['no_quotes'])) { $orderNode['no_quotes'] = $selNode['no_quotes']; } } } } } return $returnTree; }
/** * @brief Add all columns to the SELECT tree * @param sqlTree SQL parser tree node of complete query/subquery * @param mysqlConn a properly initialised MySQLI/MySQLII connection to the DB * @param zendAdapter a valid ZEND DB adapter * * This function will evaluate the all the tables that need SQL * attribute substitution. * The database is queried to retrieve a complete list of columns of each table and the * approperiate SELECT colref nodes are added to the SQL parser tree. The SQL * attribute * is removed from the sqlTree SELECT node. */ function _parseSqlAll_SELECT(&$sqlTree, $mysqlConn = false, $zendAdapter = false) { if (!is_array($sqlTree) || !array_key_exists('SELECT', $sqlTree)) { return; } $table = false; $selectCpy = $sqlTree['SELECT']; $sqlTree['SELECT'] = array(); foreach ($selectCpy as &$node) { if (strpos($node['base_expr'], "*") !== false && $node['sub_tree'] === false) { //we have found an all operator and need to find the corresponding //table to look things up $tableFullName = false; $dbName = extractDbName($node); $tableName = extractTableName($node); $colName = extractColumnName($node); if ($dbName !== false) { $tableFullName = "`" . $dbName . "`.`" . $tableName . "`"; } else { if ($tableName !== false) { $tableFullName = "`" . $tableName . "`"; } } $table = array(); $alias = array(); if ($tableFullName === false) { //add everything *ed from all tables to this query foreach ($sqlTree['FROM'] as $fromNode) { if (isTable($fromNode)) { $table[] = $fromNode['table']; if (!hasAlias($fromNode)) { $alias[] = $fromNode['table']; } else { $alias[] = $fromNode['alias']['name']; } } else { if (isSubquery($fromNode)) { //handle subqueries... _parseSqlAll_linkSubquerySELECT($fromNode['sub_tree'], $sqlTree, $fromNode['alias']['name']); } } } } else { foreach ($sqlTree['FROM'] as $fromNode) { //it could be, that the table here is actually another aliased table (which should //have been processed here already, since SELECT is called last) -> link to tree if (isTable($fromNode)) { if (hasAlias($fromNode)) { if (trim($fromNode['alias']['name'], "`") === $tableName) { $table[] = $fromNode['table']; break; } } else { if ($fromNode['table'] === $tableFullName) { $table[] = $fromNode['table']; break; } } } else { if (isSubquery($fromNode)) { if (trim($fromNode['alias']['name'], "`") === $tableName) { _parseSqlAll_linkSubquerySELECT($fromNode['sub_tree'], $sqlTree, $tableName); continue 2; } } } } $alias[] = $tableFullName; } if (empty($table)) { continue; } //now that we know the table, we need to look up what is in there foreach (array_keys($table) as $key) { if ($mysqlConn !== false) { _parseSqlAll_getColsMysqlii($sqlTree, $node, $mysqlConn, $table[$key], $alias[$key]); } if ($zendAdapter !== false) { _parseSqlAll_getColsZend($sqlTree, $node, $zendAdapter, $table[$key], $alias[$key]); } } } else { array_push($sqlTree['SELECT'], $node); } } }