Database.php 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323
  1. <?php
  2. ###
  3. # @name Database Module
  4. # @author Tobias Reich
  5. # @copyright 2014 by Tobias Reich
  6. ###
  7. if (!defined('LYCHEE')) exit('Error: Direct access is not allowed!');
  8. class Database extends Module {
  9. static function connect($host = 'localhost', $user, $password, $name = 'lychee') {
  10. # Check dependencies
  11. Module::dependencies(isset($host, $user, $password, $name));
  12. $database = new mysqli($host, $user, $password);
  13. # Check connection
  14. if ($database->connect_errno) exit('Error: ' . $database->connect_error);
  15. # Avoid sql injection on older MySQL versions by using GBK
  16. if ($database->server_version<50500) $database->set_charset('GBK');
  17. else $database->set_charset("utf8");
  18. # Check database
  19. if (!$database->select_db($name))
  20. if (!Database::createDatabase($database, $name)) exit('Error: Could not create database!');
  21. # Check tables
  22. $query = Database::prepare($database, 'SELECT * FROM ?, ?, ?, ? LIMIT 0', array(LYCHEE_TABLE_PHOTOS, LYCHEE_TABLE_ALBUMS, LYCHEE_TABLE_SETTINGS, LYCHEE_TABLE_LOG));
  23. if (!$database->query($query))
  24. if (!Database::createTables($database)) exit('Error: Could not create tables!');
  25. return $database;
  26. }
  27. static function update($database, $dbName, $version = 0) {
  28. # Check dependencies
  29. Module::dependencies(isset($database, $dbName));
  30. # List of updates
  31. $updates = array(
  32. '020100', #2.1
  33. '020101', #2.1.1
  34. '020200', #2.2
  35. '020500', #2.5
  36. '020505', #2.5.5
  37. '020601', #2.6.1
  38. '020602' #2.6.2
  39. );
  40. # For each update
  41. foreach ($updates as $update) {
  42. if (isset($version)&&$update<=$version) continue;
  43. # Load update
  44. include(__DIR__ . '/../database/update_' . $update . '.php');
  45. }
  46. return true;
  47. }
  48. static function createConfig($host = 'localhost', $user, $password, $name = 'lychee', $prefix = '') {
  49. # Check dependencies
  50. Module::dependencies(isset($host, $user, $password, $name));
  51. $database = new mysqli($host, $user, $password);
  52. if ($database->connect_errno) return 'Warning: Connection failed!';
  53. # Check if database exists
  54. if (!$database->select_db($name)) {
  55. # Database doesn't exist
  56. # Check if user can create a database
  57. $result = $database->query('CREATE DATABASE lychee_dbcheck');
  58. if (!$result) return 'Warning: Creation failed!';
  59. else $database->query('DROP DATABASE lychee_dbcheck');
  60. }
  61. # Escape data
  62. $host = mysqli_real_escape_string($database, $host);
  63. $user = mysqli_real_escape_string($database, $user);
  64. $password = mysqli_real_escape_string($database, $password);
  65. $name = mysqli_real_escape_string($database, $name);
  66. $prefix = mysqli_real_escape_string($database, $prefix);
  67. # Save config.php
  68. $config = "<?php
  69. ###
  70. # @name Configuration
  71. # @author Tobias Reich
  72. # @copyright 2014 Tobias Reich
  73. ###
  74. if(!defined('LYCHEE')) exit('Error: Direct access is not allowed!');
  75. # Database configuration
  76. \$dbHost = '$host'; # Host of the database
  77. \$dbUser = '$user'; # Username of the database
  78. \$dbPassword = '$password'; # Password of the database
  79. \$dbName = '$name'; # Database name
  80. \$dbTablePrefix = '$prefix'; # Table prefix
  81. ?>";
  82. # Save file
  83. if (file_put_contents(LYCHEE_CONFIG_FILE, $config)===false) return 'Warning: Could not create file!';
  84. return true;
  85. }
  86. static function createDatabase($database, $name = 'lychee') {
  87. # Check dependencies
  88. Module::dependencies(isset($database, $name));
  89. # Create database
  90. $result = $database->query("CREATE DATABASE IF NOT EXISTS $name;");
  91. $database->select_db($name);
  92. if (!$database->select_db($name)||!$result) return false;
  93. return true;
  94. }
  95. static function createTables($database) {
  96. # Check dependencies
  97. Module::dependencies(isset($database));
  98. # Create log
  99. $exist = Database::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_LOG));
  100. if (!$database->query($exist)) {
  101. # Read file
  102. $file = __DIR__ . '/../database/log_table.sql';
  103. $query = @file_get_contents($file);
  104. if (!isset($query)||$query===false) return false;
  105. # Create table
  106. $query = Database::prepare($database, $query, array(LYCHEE_TABLE_LOG));
  107. if (!$database->query($query)) return false;
  108. }
  109. # Create settings
  110. $exist = Database::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_SETTINGS));
  111. if (!$database->query($exist)) {
  112. # Read file
  113. $file = __DIR__ . '/../database/settings_table.sql';
  114. $query = @file_get_contents($file);
  115. if (!isset($query)||$query===false) {
  116. Log::error($database, __METHOD__, __LINE__, 'Could not load query for lychee_settings');
  117. return false;
  118. }
  119. # Create table
  120. $query = Database::prepare($database, $query, array(LYCHEE_TABLE_SETTINGS));
  121. if (!$database->query($query)) {
  122. Log::error($database, __METHOD__, __LINE__, $database->error);
  123. return false;
  124. }
  125. # Read file
  126. $file = __DIR__ . '/../database/settings_content.sql';
  127. $query = @file_get_contents($file);
  128. if (!isset($query)||$query===false) {
  129. Log::error($database, __METHOD__, __LINE__, 'Could not load content-query for lychee_settings');
  130. return false;
  131. }
  132. # Add content
  133. $query = Database::prepare($database, $query, array(LYCHEE_TABLE_SETTINGS));
  134. if (!$database->query($query)) {
  135. Log::error($database, __METHOD__, __LINE__, $database->error);
  136. return false;
  137. }
  138. }
  139. # Create albums
  140. $exist = Database::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_ALBUMS));
  141. if (!$database->query($exist)) {
  142. # Read file
  143. $file = __DIR__ . '/../database/albums_table.sql';
  144. $query = @file_get_contents($file);
  145. if (!isset($query)||$query===false) {
  146. Log::error($database, __METHOD__, __LINE__, 'Could not load query for lychee_albums');
  147. return false;
  148. }
  149. # Create table
  150. $query = Database::prepare($database, $query, array(LYCHEE_TABLE_ALBUMS));
  151. if (!$database->query($query)) {
  152. Log::error($database, __METHOD__, __LINE__, $database->error);
  153. return false;
  154. }
  155. }
  156. # Create photos
  157. $exist = Database::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_PHOTOS));
  158. if (!$database->query($exist)) {
  159. # Read file
  160. $file = __DIR__ . '/../database/photos_table.sql';
  161. $query = @file_get_contents($file);
  162. if (!isset($query)||$query===false) {
  163. Log::error($database, __METHOD__, __LINE__, 'Could not load query for lychee_photos');
  164. return false;
  165. }
  166. # Create table
  167. $query = Database::prepare($database, $query, array(LYCHEE_TABLE_PHOTOS));
  168. if (!$database->query($query)) {
  169. Log::error($database, __METHOD__, __LINE__, $database->error);
  170. return false;
  171. }
  172. }
  173. return true;
  174. }
  175. static function setVersion($database, $version) {
  176. $query = Database::prepare($database, "UPDATE ? SET value = '?' WHERE `key` = 'version'", array(LYCHEE_TABLE_SETTINGS, $version));
  177. $result = $database->query($query);
  178. if (!$result) {
  179. Log::error($database, __METHOD__, __LINE__, 'Could not update database (' . $database->error . ')');
  180. return false;
  181. }
  182. }
  183. static function prepare($database, $query, $data) {
  184. # Check dependencies
  185. Module::dependencies(isset($database, $query, $data));
  186. # Count the number of placeholders and compare it with the number of arguments
  187. # If it doesn't match, calculate the difference and skip this number of placeholders before starting the replacement
  188. # This avoids problems with placeholders in user-input
  189. # $skip = Number of placeholders which need to be skipped
  190. $skip = 0;
  191. $num = array(
  192. 'placeholder' => substr_count($query, '?'),
  193. 'data' => count($data)
  194. );
  195. if (($num['data']-$num['placeholder'])<0) Log::notice($database, __METHOD__, __LINE__, 'Could not completely prepare query. Query has more placeholders than values.');
  196. foreach ($data as $value) {
  197. # Escape
  198. $value = mysqli_real_escape_string($database, $value);
  199. # Recalculate number of placeholders
  200. $num['placeholder'] = substr_count($query, '?');
  201. # Calculate number of skips
  202. if ($num['placeholder']>$num['data']) $skip = $num['placeholder'] - $num['data'];
  203. if ($skip>0) {
  204. # Need to skip $skip placeholders, because the user input contained placeholders
  205. # Calculate a substring which does not contain the user placeholders
  206. # 1 or -1 is the length of the placeholder (placeholder = ?)
  207. $pos = -1;
  208. for ($i=$skip; $i>0; $i--) $pos = strpos($query, '?', $pos + 1);
  209. $pos++;
  210. $temp = substr($query, 0, $pos); # First part of $query
  211. $query = substr($query, $pos); # Last part of $query
  212. }
  213. # Replace
  214. $query = preg_replace('/\?/', $value, $query, 1);
  215. if ($skip>0) {
  216. # Reassemble the parts of $query
  217. $query = $temp . $query;
  218. }
  219. # Reset skip
  220. $skip = 0;
  221. # Decrease number of data elements
  222. $num['data']--;
  223. }
  224. return $query;
  225. }
  226. }
  227. ?>