Database.php 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339
  1. <?php
  2. ###
  3. # @name Database Module
  4. # @copyright 2015 by Tobias Reich
  5. ###
  6. if (!defined('LYCHEE')) exit('Error: Direct access is not allowed!');
  7. final class Database extends Module {
  8. private static $versions = array(
  9. '020500', #2.5
  10. '020505', #2.5.5
  11. '020601', #2.6.1
  12. '020602', #2.6.2
  13. '020700', #2.7.0
  14. '030000', #3.0.0
  15. '030001', #3.0.1
  16. '030003' #3.0.3
  17. );
  18. public static function connect($host = 'localhost', $user, $password, $name = 'lychee') {
  19. # Check dependencies
  20. Module::dependencies(isset($host, $user, $password, $name));
  21. $database = new mysqli($host, $user, $password);
  22. # Check connection
  23. if ($database->connect_errno) exit('Error: ' . $database->connect_error);
  24. # Avoid sql injection on older MySQL versions by using GBK
  25. if ($database->server_version<50500) @$database->set_charset('GBK');
  26. else @$database->set_charset('utf8');
  27. # Set unicode
  28. $database->query('SET NAMES utf8;');
  29. # Create database
  30. if (!self::createDatabase($database, $name)) exit('Error: Could not create database!');
  31. # Create tables
  32. if (!self::createTables($database)) exit('Error: Could not create tables!');
  33. # Update database
  34. if (!self::update($database, $name)) exit('Error: Could not update database and tables!');
  35. return $database;
  36. }
  37. private static function update($database, $dbName) {
  38. # Check dependencies
  39. Module::dependencies(isset($database, $dbName));
  40. # Get current version
  41. $query = self::prepare($database, "SELECT * FROM ? WHERE `key` = 'version'", array(LYCHEE_TABLE_SETTINGS));
  42. $results = $database->query($query);
  43. $current = $results->fetch_object()->value;
  44. # For each update
  45. foreach (self::$versions as $version) {
  46. # Only update when newer version available
  47. if ($version<=$current) continue;
  48. # Load update
  49. include(__DIR__ . '/../database/update_' . $update . '.php');
  50. }
  51. return true;
  52. }
  53. public static function createConfig($host = 'localhost', $user, $password, $name = 'lychee', $prefix = '') {
  54. # Check dependencies
  55. Module::dependencies(isset($host, $user, $password, $name));
  56. $database = new mysqli($host, $user, $password);
  57. if ($database->connect_errno) return 'Warning: Connection failed!';
  58. # Check if user can create the database before saving the configuration
  59. if (!self::createDatabase($database, $name)) return 'Warning: Creation failed!';
  60. # Escape data
  61. $host = mysqli_real_escape_string($database, $host);
  62. $user = mysqli_real_escape_string($database, $user);
  63. $password = mysqli_real_escape_string($database, $password);
  64. $name = mysqli_real_escape_string($database, $name);
  65. $prefix = mysqli_real_escape_string($database, $prefix);
  66. # Save config.php
  67. $config = "<?php
  68. ###
  69. # @name Configuration
  70. # @author Tobias Reich
  71. # @copyright 2015 Tobias Reich
  72. ###
  73. if(!defined('LYCHEE')) exit('Error: Direct access is not allowed!');
  74. # Database configuration
  75. \$dbHost = '$host'; # Host of the database
  76. \$dbUser = '$user'; # Username of the database
  77. \$dbPassword = '$password'; # Password of the database
  78. \$dbName = '$name'; # Database name
  79. \$dbTablePrefix = '$prefix'; # Table prefix
  80. ?>";
  81. # Save file
  82. if (file_put_contents(LYCHEE_CONFIG_FILE, $config)===false) return 'Warning: Could not create file!';
  83. return true;
  84. }
  85. private static function createDatabase($database, $name = 'lychee') {
  86. # Check dependencies
  87. Module::dependencies(isset($database, $name));
  88. # Check if database exists
  89. if ($database->select_db($name)) return true;
  90. # Create database
  91. $query = self::prepare($database, 'CREATE DATABASE IF NOT EXISTS ?', array($name));
  92. $result = $database->query($query);
  93. if (!$database->select_db($name)||!$result) return false;
  94. return true;
  95. }
  96. private static function createTables($database) {
  97. # Check dependencies
  98. Module::dependencies(isset($database));
  99. # Check if tables exist
  100. $query = self::prepare($database, 'SELECT * FROM ?, ?, ?, ? LIMIT 0', array(LYCHEE_TABLE_PHOTOS, LYCHEE_TABLE_ALBUMS, LYCHEE_TABLE_SETTINGS, LYCHEE_TABLE_LOG));
  101. if ($database->query($query)) return true;
  102. # Create log
  103. $exist = self::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_LOG));
  104. if (!$database->query($exist)) {
  105. # Read file
  106. $file = __DIR__ . '/../database/log_table.sql';
  107. $query = @file_get_contents($file);
  108. if (!isset($query)||$query===false) return false;
  109. # Create table
  110. $query = self::prepare($database, $query, array(LYCHEE_TABLE_LOG));
  111. if (!$database->query($query)) return false;
  112. }
  113. # Create settings
  114. $exist = self::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_SETTINGS));
  115. if (!$database->query($exist)) {
  116. # Read file
  117. $file = __DIR__ . '/../database/settings_table.sql';
  118. $query = @file_get_contents($file);
  119. if (!isset($query)||$query===false) {
  120. Log::error($database, __METHOD__, __LINE__, 'Could not load query for lychee_settings');
  121. return false;
  122. }
  123. # Create table
  124. $query = self::prepare($database, $query, array(LYCHEE_TABLE_SETTINGS));
  125. if (!$database->query($query)) {
  126. Log::error($database, __METHOD__, __LINE__, $database->error);
  127. return false;
  128. }
  129. # Read file
  130. $file = __DIR__ . '/../database/settings_content.sql';
  131. $query = @file_get_contents($file);
  132. if (!isset($query)||$query===false) {
  133. Log::error($database, __METHOD__, __LINE__, 'Could not load content-query for lychee_settings');
  134. return false;
  135. }
  136. # Add content
  137. $query = self::prepare($database, $query, array(LYCHEE_TABLE_SETTINGS));
  138. if (!$database->query($query)) {
  139. Log::error($database, __METHOD__, __LINE__, $database->error);
  140. return false;
  141. }
  142. # Generate identifier
  143. $identifier = md5(microtime(true));
  144. $query = self::prepare($database, "UPDATE `?` SET `value` = '?' WHERE `key` = 'identifier' LIMIT 1", array(LYCHEE_TABLE_SETTINGS, $identifier));
  145. if (!$database->query($query)) {
  146. Log::error($database, __METHOD__, __LINE__, $database->error);
  147. return false;
  148. }
  149. }
  150. # Create albums
  151. $exist = self::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_ALBUMS));
  152. if (!$database->query($exist)) {
  153. # Read file
  154. $file = __DIR__ . '/../database/albums_table.sql';
  155. $query = @file_get_contents($file);
  156. if (!isset($query)||$query===false) {
  157. Log::error($database, __METHOD__, __LINE__, 'Could not load query for lychee_albums');
  158. return false;
  159. }
  160. # Create table
  161. $query = self::prepare($database, $query, array(LYCHEE_TABLE_ALBUMS));
  162. if (!$database->query($query)) {
  163. Log::error($database, __METHOD__, __LINE__, $database->error);
  164. return false;
  165. }
  166. }
  167. # Create photos
  168. $exist = self::prepare($database, 'SELECT * FROM ? LIMIT 0', array(LYCHEE_TABLE_PHOTOS));
  169. if (!$database->query($exist)) {
  170. # Read file
  171. $file = __DIR__ . '/../database/photos_table.sql';
  172. $query = @file_get_contents($file);
  173. if (!isset($query)||$query===false) {
  174. Log::error($database, __METHOD__, __LINE__, 'Could not load query for lychee_photos');
  175. return false;
  176. }
  177. # Create table
  178. $query = self::prepare($database, $query, array(LYCHEE_TABLE_PHOTOS));
  179. if (!$database->query($query)) {
  180. Log::error($database, __METHOD__, __LINE__, $database->error);
  181. return false;
  182. }
  183. }
  184. return true;
  185. }
  186. public static function setVersion($database, $version) {
  187. $query = self::prepare($database, "UPDATE ? SET value = '?' WHERE `key` = 'version'", array(LYCHEE_TABLE_SETTINGS, $version));
  188. $result = $database->query($query);
  189. if (!$result) {
  190. Log::error($database, __METHOD__, __LINE__, 'Could not update database (' . $database->error . ')');
  191. return false;
  192. }
  193. }
  194. public static function prepare($database, $query, $data) {
  195. # Check dependencies
  196. Module::dependencies(isset($database, $query, $data));
  197. # Count the number of placeholders and compare it with the number of arguments
  198. # If it doesn't match, calculate the difference and skip this number of placeholders before starting the replacement
  199. # This avoids problems with placeholders in user-input
  200. # $skip = Number of placeholders which need to be skipped
  201. $skip = 0;
  202. $temp = '';
  203. $num = array(
  204. 'placeholder' => substr_count($query, '?'),
  205. 'data' => count($data)
  206. );
  207. if (($num['data']-$num['placeholder'])<0) Log::notice($database, __METHOD__, __LINE__, 'Could not completely prepare query. Query has more placeholders than values.');
  208. foreach ($data as $value) {
  209. # Escape
  210. $value = mysqli_real_escape_string($database, $value);
  211. # Recalculate number of placeholders
  212. $num['placeholder'] = substr_count($query, '?');
  213. # Calculate number of skips
  214. if ($num['placeholder']>$num['data']) $skip = $num['placeholder'] - $num['data'];
  215. if ($skip>0) {
  216. # Need to skip $skip placeholders, because the user input contained placeholders
  217. # Calculate a substring which does not contain the user placeholders
  218. # 1 or -1 is the length of the placeholder (placeholder = ?)
  219. $pos = -1;
  220. for ($i=$skip; $i>0; $i--) $pos = strpos($query, '?', $pos + 1);
  221. $pos++;
  222. $temp = substr($query, 0, $pos); # First part of $query
  223. $query = substr($query, $pos); # Last part of $query
  224. }
  225. # Replace
  226. $query = preg_replace('/\?/', $value, $query, 1);
  227. if ($skip>0) {
  228. # Reassemble the parts of $query
  229. $query = $temp . $query;
  230. }
  231. # Reset skip
  232. $skip = 0;
  233. # Decrease number of data elements
  234. $num['data']--;
  235. }
  236. return $query;
  237. }
  238. }
  239. ?>