Merge pull request #18321 from kamil-tekiela/quoteString-in-Tracking

Use quoteString in Tracking
This commit is contained in:
Maurício Meneghini Fauth 2023-04-03 15:57:54 -03:00 committed by GitHub
commit abff85941b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 12 additions and 20 deletions

View File

@ -11,6 +11,7 @@ use DateTimeImmutable;
use PhpMyAdmin\ConfigStorage\Relation;
use PhpMyAdmin\Core;
use PhpMyAdmin\DatabaseInterface;
use PhpMyAdmin\Dbal\Connection;
use PhpMyAdmin\Dbal\ResultInterface;
use PhpMyAdmin\Html\Generator;
use PhpMyAdmin\Message;
@ -99,11 +100,11 @@ class Tracking
}
$query = sprintf(
'SELECT * FROM %s.%s WHERE db_name = \'%s\' AND table_name = \'%s\' ORDER BY version DESC',
'SELECT * FROM %s.%s WHERE db_name = %s AND table_name = %s ORDER BY version DESC',
Util::backquote($trackingFeature->database),
Util::backquote($trackingFeature->tracking),
$this->dbi->escapeString($db),
$this->dbi->escapeString($table),
$this->dbi->quoteString($db, Connection::TYPE_CONTROL),
$this->dbi->quoteString($table, Connection::TYPE_CONTROL),
);
return $this->dbi->queryAsControlUser($query);
@ -1026,8 +1027,8 @@ class Tracking
// Prepare statement to get HEAD version
$allTablesQuery = ' SELECT table_name, MAX(version) as version FROM '
. Util::backquote($trackingFeature->database) . '.' . Util::backquote($trackingFeature->tracking)
. ' WHERE db_name = \'' . $this->dbi->escapeString($db)
. '\' GROUP BY table_name ORDER BY table_name ASC';
. ' WHERE db_name = ' . $this->dbi->quoteString($db, Connection::TYPE_CONTROL)
. ' GROUP BY table_name ORDER BY table_name ASC';
$allTablesResult = $this->dbi->queryAsControlUser($allTablesQuery);
$untrackedTables = $this->trackingChecker->getUntrackedTableNames($db);
@ -1038,9 +1039,9 @@ class Tracking
[$tableName, $versionNumber] = $oneResult;
$tableQuery = ' SELECT * FROM '
. Util::backquote($trackingFeature->database) . '.' . Util::backquote($trackingFeature->tracking)
. ' WHERE `db_name` = \'' . $this->dbi->escapeString($db)
. '\' AND `table_name` = \'' . $this->dbi->escapeString($tableName)
. '\' AND `version` = \'' . $versionNumber . '\'';
. ' WHERE `db_name` = ' . $this->dbi->quoteString($db, Connection::TYPE_CONTROL)
. ' AND `table_name` = ' . $this->dbi->quoteString($tableName, Connection::TYPE_CONTROL)
. ' AND `version` = ' . $this->dbi->quoteString($versionNumber, Connection::TYPE_CONTROL);
$versions[] = $this->dbi->queryAsControlUser($tableQuery)->fetchAssoc();
}

View File

@ -8826,8 +8826,8 @@ parameters:
path: libraries/classes/Tracking/Tracking.php
-
message: "#^Parameter \\#1 \\$str of method PhpMyAdmin\\\\DatabaseInterface\\:\\:escapeString\\(\\) expects string, string\\|null given\\.$#"
count: 1
message: "#^Parameter \\#1 \\$str of method PhpMyAdmin\\\\DatabaseInterface\\:\\:quoteString\\(\\) expects string, string\\|null given\\.$#"
count: 2
path: libraries/classes/Tracking/Tracking.php
-

View File

@ -13657,13 +13657,6 @@
</PossiblyUnusedMethod>
</file>
<file src="libraries/classes/Tracking/Tracking.php">
<DeprecatedMethod>
<code>escapeString</code>
<code>escapeString</code>
<code>escapeString</code>
<code>escapeString</code>
<code>escapeString</code>
</DeprecatedMethod>
<MixedArgument>
<code>$columns</code>
<code>$data[$whichLog]</code>
@ -13743,10 +13736,8 @@
<PossiblyNullArgument>
<code><![CDATA[$data['schema_snapshot']]]></code>
<code>$tableName</code>
</PossiblyNullArgument>
<PossiblyNullOperand>
<code>$versionNumber</code>
</PossiblyNullOperand>
</PossiblyNullArgument>
<PossiblyUndefinedArrayOffset>
<code><![CDATA[$data['ddlog']]]></code>
<code><![CDATA[$data['schema_snapshot']]]></code>