Database.php 8.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. <?php
  2. ###
  3. # @name Database Module
  4. # @copyright 2015 by Tobias Reich
  5. ###
  6. if (!defined('LYCHEE')) exit('Error: Direct access is not allowed!');
  7. final class Database extends Module {
  8. private $connection = null;
  9. private static $instance = null;
  10. private static $versions = array(
  11. '020700', #2.7.0
  12. '030000', #3.0.0
  13. '030001', #3.0.1
  14. '030003' #3.0.3
  15. );
  16. public static function get() {
  17. if (!self::$instance) {
  18. $credentials = Config::get();
  19. self::$instance = new self(
  20. $credentials['host'],
  21. $credentials['user'],
  22. $credentials['password'],
  23. $credentials['name'],
  24. $credentials['prefix']
  25. );
  26. }
  27. return self::$instance->connection;
  28. }
  29. private function __construct($host, $user, $password, $name = 'lychee', $dbTablePrefix) {
  30. # Check dependencies
  31. Module::dependencies(isset($host, $user, $password, $name));
  32. # Define the table prefix
  33. defineTablePrefix($dbTablePrefix);
  34. # Open a new connection to the MySQL server
  35. $connection = self::connect($host, $user, $password);
  36. # Check if the connection was successful
  37. if ($connection===false) exit('Error: ' . $connection->connect_error);
  38. if (!self::setCharset($connection)) exit('Error: Could not set database charset!');
  39. # Create database
  40. if (!self::createDatabase($connection, $name)) exit('Error: Could not create database!');
  41. # Create tables
  42. if (!self::createTables($connection)) exit('Error: Could not create tables!');
  43. # Update database
  44. if (!self::update($connection, $name)) exit('Error: Could not update database and tables!');
  45. $this->connection = $connection;
  46. }
  47. public static function connect($host = 'localhost', $user, $password) {
  48. # Open a new connection to the MySQL server
  49. $connection = new mysqli($host, $user, $password);
  50. # Check if the connection was successful
  51. if ($connection->connect_errno) return false;
  52. return $connection;
  53. }
  54. private static function setCharset($connection) {
  55. # Avoid sql injection on older MySQL versions by using GBK
  56. if ($connection->server_version<50500) @$connection->set_charset('GBK');
  57. else @$connection->set_charset('utf8');
  58. # Set unicode
  59. $connection->query('SET NAMES utf8;');
  60. return true;
  61. }
  62. public static function createDatabase($connection, $name = 'lychee') {
  63. # Check dependencies
  64. Module::dependencies(isset($connection, $name));
  65. # Check if database exists
  66. if ($connection->select_db($name)) return true;
  67. # Create database
  68. $query = self::prepare($connection, 'CREATE DATABASE IF NOT EXISTS ?', array($name));
  69. $result = $connection->query($query);
  70. if (!$connection->select_db($name)) return false;
  71. return true;
  72. }
  73. private static function createTables($connection) {
  74. # Check dependencies
  75. Module::dependencies(isset($connection));
  76. # Check if tables exist
  77. $query = self::prepare($connection, 'SELECT * FROM ?, ?, ?, ? LIMIT 0', array(LYCHEE_TABLE_PHOTOS, LYCHEE_TABLE_ALBUMS, LYCHEE_TABLE_SETTINGS, LYCHEE_TABLE_LOG));
  78. if ($connection->query($query)) return true;
  79. # Create log
  80. $exist = self::prepare($connection, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_LOG));
  81. if (!$connection->query($exist)) {
  82. # Read file
  83. $file = __DIR__ . '/../database/log_table.sql';
  84. $query = @file_get_contents($file);
  85. if (!isset($query)||$query===false) return false;
  86. # Create table
  87. $query = self::prepare($connection, $query, array(LYCHEE_TABLE_LOG));
  88. if (!$connection->query($query)) return false;
  89. }
  90. # Create settings
  91. $exist = self::prepare($connection, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_SETTINGS));
  92. if (!$connection->query($exist)) {
  93. # Read file
  94. $file = __DIR__ . '/../database/settings_table.sql';
  95. $query = @file_get_contents($file);
  96. if (!isset($query)||$query===false) {
  97. Log::error(__METHOD__, __LINE__, 'Could not load query for lychee_settings');
  98. return false;
  99. }
  100. # Create table
  101. $query = self::prepare($connection, $query, array(LYCHEE_TABLE_SETTINGS));
  102. if (!$connection->query($query)) {
  103. Log::error(__METHOD__, __LINE__, $connection->error);
  104. return false;
  105. }
  106. # Read file
  107. $file = __DIR__ . '/../database/settings_content.sql';
  108. $query = @file_get_contents($file);
  109. if (!isset($query)||$query===false) {
  110. Log::error(__METHOD__, __LINE__, 'Could not load content-query for lychee_settings');
  111. return false;
  112. }
  113. # Add content
  114. $query = self::prepare($connection, $query, array(LYCHEE_TABLE_SETTINGS));
  115. if (!$connection->query($query)) {
  116. Log::error(__METHOD__, __LINE__, $connection->error);
  117. return false;
  118. }
  119. # Generate identifier
  120. $identifier = md5(microtime(true));
  121. $query = self::prepare($connection, "UPDATE `?` SET `value` = '?' WHERE `key` = 'identifier' LIMIT 1", array(LYCHEE_TABLE_SETTINGS, $identifier));
  122. if (!$connection->query($query)) {
  123. Log::error(__METHOD__, __LINE__, $connection->error);
  124. return false;
  125. }
  126. }
  127. # Create albums
  128. $exist = self::prepare($connection, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_ALBUMS));
  129. if (!$connection->query($exist)) {
  130. # Read file
  131. $file = __DIR__ . '/../database/albums_table.sql';
  132. $query = @file_get_contents($file);
  133. if (!isset($query)||$query===false) {
  134. Log::error(__METHOD__, __LINE__, 'Could not load query for lychee_albums');
  135. return false;
  136. }
  137. # Create table
  138. $query = self::prepare($connection, $query, array(LYCHEE_TABLE_ALBUMS));
  139. if (!$connection->query($query)) {
  140. Log::error(__METHOD__, __LINE__, $connection->error);
  141. return false;
  142. }
  143. }
  144. # Create photos
  145. $exist = self::prepare($connection, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_PHOTOS));
  146. if (!$connection->query($exist)) {
  147. # Read file
  148. $file = __DIR__ . '/../database/photos_table.sql';
  149. $query = @file_get_contents($file);
  150. if (!isset($query)||$query===false) {
  151. Log::error(__METHOD__, __LINE__, 'Could not load query for lychee_photos');
  152. return false;
  153. }
  154. # Create table
  155. $query = self::prepare($connection, $query, array(LYCHEE_TABLE_PHOTOS));
  156. if (!$connection->query($query)) {
  157. Log::error(__METHOD__, __LINE__, $connection->error);
  158. return false;
  159. }
  160. }
  161. return true;
  162. }
  163. private static function update($connection, $dbName) {
  164. # Check dependencies
  165. Module::dependencies(isset($connection));
  166. # Get current version
  167. $query = self::prepare($connection, "SELECT * FROM ? WHERE `key` = 'version'", array(LYCHEE_TABLE_SETTINGS));
  168. $results = $connection->query($query);
  169. $current = $results->fetch_object()->value;
  170. # For each update
  171. foreach (self::$versions as $version) {
  172. # Only update when newer version available
  173. if ($version<=$current) continue;
  174. # Load update
  175. include(__DIR__ . '/../database/update_' . $version . '.php');
  176. }
  177. return true;
  178. }
  179. public static function setVersion($connection, $version) {
  180. $query = self::prepare($connection, "UPDATE ? SET value = '?' WHERE `key` = 'version'", array(LYCHEE_TABLE_SETTINGS, $version));
  181. $result = $connection->query($query);
  182. if (!$result) {
  183. Log::error(__METHOD__, __LINE__, 'Could not update database (' . $connection->error . ')');
  184. return false;
  185. }
  186. }
  187. public static function prepare($connection, $query, $data) {
  188. # Check dependencies
  189. Module::dependencies(isset($connection, $query, $data));
  190. # Count the number of placeholders and compare it with the number of arguments
  191. # If it doesn't match, calculate the difference and skip this number of placeholders before starting the replacement
  192. # This avoids problems with placeholders in user-input
  193. # $skip = Number of placeholders which need to be skipped
  194. $skip = 0;
  195. $temp = '';
  196. $num = array(
  197. 'placeholder' => substr_count($query, '?'),
  198. 'data' => count($data)
  199. );
  200. if (($num['data']-$num['placeholder'])<0) Log::notice(__METHOD__, __LINE__, 'Could not completely prepare query. Query has more placeholders than values.');
  201. foreach ($data as $value) {
  202. # Escape
  203. $value = mysqli_real_escape_string($connection, $value);
  204. # Recalculate number of placeholders
  205. $num['placeholder'] = substr_count($query, '?');
  206. # Calculate number of skips
  207. if ($num['placeholder']>$num['data']) $skip = $num['placeholder'] - $num['data'];
  208. if ($skip>0) {
  209. # Need to skip $skip placeholders, because the user input contained placeholders
  210. # Calculate a substring which does not contain the user placeholders
  211. # 1 or -1 is the length of the placeholder (placeholder = ?)
  212. $pos = -1;
  213. for ($i=$skip; $i>0; $i--) $pos = strpos($query, '?', $pos + 1);
  214. $pos++;
  215. $temp = substr($query, 0, $pos); # First part of $query
  216. $query = substr($query, $pos); # Last part of $query
  217. }
  218. # Replace
  219. $query = preg_replace('/\?/', $value, $query, 1);
  220. if ($skip>0) {
  221. # Reassemble the parts of $query
  222. $query = $temp . $query;
  223. }
  224. # Reset skip
  225. $skip = 0;
  226. # Decrease number of data elements
  227. $num['data']--;
  228. }
  229. return $query;
  230. }
  231. }
  232. ?>