rte_triggers.lib.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492
  1. <?php
  2. /* vim: set expandtab sw=4 ts=4 sts=4: */
  3. /**
  4. * Functions for trigger management.
  5. *
  6. * @package PhpMyAdmin
  7. */
  8. if (! defined('PHPMYADMIN')) {
  9. exit;
  10. }
  11. /**
  12. * Sets required globals
  13. *
  14. * @return void
  15. */
  16. function PMA_TRI_setGlobals()
  17. {
  18. global $action_timings, $event_manipulations;
  19. // Some definitions for triggers
  20. $action_timings = array('BEFORE',
  21. 'AFTER');
  22. $event_manipulations = array('INSERT',
  23. 'UPDATE',
  24. 'DELETE');
  25. }
  26. /**
  27. * Main function for the triggers functionality
  28. *
  29. * @return void
  30. */
  31. function PMA_TRI_main()
  32. {
  33. global $db, $table;
  34. PMA_TRI_setGlobals();
  35. /**
  36. * Process all requests
  37. */
  38. PMA_TRI_handleEditor();
  39. PMA_TRI_handleExport();
  40. /**
  41. * Display a list of available triggers
  42. */
  43. $items = $GLOBALS['dbi']->getTriggers($db, $table);
  44. echo PMA_RTE_getList('trigger', $items);
  45. /**
  46. * Display a link for adding a new trigger,
  47. * if the user has the necessary privileges
  48. */
  49. echo PMA_TRI_getFooterLinks();
  50. } // end PMA_TRI_main()
  51. /**
  52. * Handles editor requests for adding or editing an item
  53. *
  54. * @return void
  55. */
  56. function PMA_TRI_handleEditor()
  57. {
  58. global $_REQUEST, $_POST, $errors, $db, $table;
  59. if (! empty($_REQUEST['editor_process_add'])
  60. || ! empty($_REQUEST['editor_process_edit'])
  61. ) {
  62. $sql_query = '';
  63. $item_query = PMA_TRI_getQueryFromRequest();
  64. if (! count($errors)) { // set by PMA_RTN_getQueryFromRequest()
  65. // Execute the created query
  66. if (! empty($_REQUEST['editor_process_edit'])) {
  67. // Backup the old trigger, in case something goes wrong
  68. $trigger = PMA_TRI_getDataFromName($_REQUEST['item_original_name']);
  69. $create_item = $trigger['create'];
  70. $drop_item = $trigger['drop'] . ';';
  71. $result = $GLOBALS['dbi']->tryQuery($drop_item);
  72. if (! $result) {
  73. $errors[] = sprintf(
  74. __('The following query has failed: "%s"'),
  75. htmlspecialchars($drop_item)
  76. )
  77. . '<br />'
  78. . __('MySQL said: ') . $GLOBALS['dbi']->getError(null);
  79. } else {
  80. $result = $GLOBALS['dbi']->tryQuery($item_query);
  81. if (! $result) {
  82. $errors[] = sprintf(
  83. __('The following query has failed: "%s"'),
  84. htmlspecialchars($item_query)
  85. )
  86. . '<br />'
  87. . __('MySQL said: ') . $GLOBALS['dbi']->getError(null);
  88. // We dropped the old item, but were unable to create the
  89. // new one. Try to restore the backup query.
  90. $result = $GLOBALS['dbi']->tryQuery($create_item);
  91. if (! $result) {
  92. // OMG, this is really bad! We dropped the query,
  93. // failed to create a new one
  94. // and now even the backup query does not execute!
  95. // This should not happen, but we better handle
  96. // this just in case.
  97. $errors[] = __(
  98. 'Sorry, we failed to restore the dropped trigger.'
  99. )
  100. . '<br />'
  101. . __('The backed up query was:')
  102. . "\"" . htmlspecialchars($create_item) . "\""
  103. . '<br />'
  104. . __('MySQL said: ') . $GLOBALS['dbi']->getError(null);
  105. }
  106. } else {
  107. $message = PMA_Message::success(
  108. __('Trigger %1$s has been modified.')
  109. );
  110. $message->addParam(
  111. PMA_Util::backquote($_REQUEST['item_name'])
  112. );
  113. $sql_query = $drop_item . $item_query;
  114. }
  115. }
  116. } else {
  117. // 'Add a new item' mode
  118. $result = $GLOBALS['dbi']->tryQuery($item_query);
  119. if (! $result) {
  120. $errors[] = sprintf(
  121. __('The following query has failed: "%s"'),
  122. htmlspecialchars($item_query)
  123. )
  124. . '<br /><br />'
  125. . __('MySQL said: ') . $GLOBALS['dbi']->getError(null);
  126. } else {
  127. $message = PMA_Message::success(
  128. __('Trigger %1$s has been created.')
  129. );
  130. $message->addParam(
  131. PMA_Util::backquote($_REQUEST['item_name'])
  132. );
  133. $sql_query = $item_query;
  134. }
  135. }
  136. }
  137. if (count($errors)) {
  138. $message = PMA_Message::error(
  139. '<b>'
  140. . __(
  141. 'One or more errors have occurred while processing your request:'
  142. )
  143. . '</b>'
  144. );
  145. $message->addString('<ul>');
  146. foreach ($errors as $string) {
  147. $message->addString('<li>' . $string . '</li>');
  148. }
  149. $message->addString('</ul>');
  150. }
  151. $output = PMA_Util::getMessage($message, $sql_query);
  152. if ($GLOBALS['is_ajax_request']) {
  153. $response = PMA_Response::getInstance();
  154. if ($message->isSuccess()) {
  155. $items = $GLOBALS['dbi']->getTriggers($db, $table, '');
  156. $trigger = false;
  157. foreach ($items as $value) {
  158. if ($value['name'] == $_REQUEST['item_name']) {
  159. $trigger = $value;
  160. }
  161. }
  162. $insert = false;
  163. if (empty($table)
  164. || ($trigger !== false && $table == $trigger['table'])
  165. ) {
  166. $insert = true;
  167. $response->addJSON('new_row', PMA_TRI_getRowForList($trigger));
  168. $response->addJSON(
  169. 'name',
  170. htmlspecialchars(
  171. strtoupper($_REQUEST['item_name'])
  172. )
  173. );
  174. }
  175. $response->addJSON('insert', $insert);
  176. $response->addJSON('message', $output);
  177. } else {
  178. $response->addJSON('message', $message);
  179. $response->isSuccess(false);
  180. }
  181. exit;
  182. }
  183. }
  184. /**
  185. * Display a form used to add/edit a trigger, if necessary
  186. */
  187. if (count($errors)
  188. || (empty($_REQUEST['editor_process_add'])
  189. && empty($_REQUEST['editor_process_edit'])
  190. && (! empty($_REQUEST['add_item'])
  191. || ! empty($_REQUEST['edit_item']))) // FIXME: this must be simpler than that
  192. ) {
  193. // Get the data for the form (if any)
  194. if (! empty($_REQUEST['add_item'])) {
  195. $title = PMA_RTE_getWord('add');
  196. $item = PMA_TRI_getDataFromRequest();
  197. $mode = 'add';
  198. } else if (! empty($_REQUEST['edit_item'])) {
  199. $title = __("Edit trigger");
  200. if (! empty($_REQUEST['item_name'])
  201. && empty($_REQUEST['editor_process_edit'])
  202. ) {
  203. $item = PMA_TRI_getDataFromName($_REQUEST['item_name']);
  204. if ($item !== false) {
  205. $item['item_original_name'] = $item['item_name'];
  206. }
  207. } else {
  208. $item = PMA_TRI_getDataFromRequest();
  209. }
  210. $mode = 'edit';
  211. }
  212. if ($item !== false) {
  213. // Show form
  214. $editor = PMA_TRI_getEditorForm($mode, $item);
  215. if ($GLOBALS['is_ajax_request']) {
  216. $response = PMA_Response::getInstance();
  217. $response->addJSON('message', $editor);
  218. $response->addJSON('title', $title);
  219. } else {
  220. echo "\n\n<h2>$title</h2>\n\n$editor";
  221. unset($_POST);
  222. }
  223. exit;
  224. } else {
  225. $message = __('Error in processing request:') . ' ';
  226. $message .= sprintf(
  227. PMA_RTE_getWord('not_found'),
  228. htmlspecialchars(PMA_Util::backquote($_REQUEST['item_name'])),
  229. htmlspecialchars(PMA_Util::backquote($db))
  230. );
  231. $message = PMA_message::error($message);
  232. if ($GLOBALS['is_ajax_request']) {
  233. $response = PMA_Response::getInstance();
  234. $response->isSuccess(false);
  235. $response->addJSON('message', $message);
  236. exit;
  237. } else {
  238. $message->display();
  239. }
  240. }
  241. }
  242. } // end PMA_TRI_handleEditor()
  243. /**
  244. * This function will generate the values that are required to for the editor
  245. *
  246. * @return array Data necessary to create the editor.
  247. */
  248. function PMA_TRI_getDataFromRequest()
  249. {
  250. $retval = array();
  251. $indices = array('item_name',
  252. 'item_table',
  253. 'item_original_name',
  254. 'item_action_timing',
  255. 'item_event_manipulation',
  256. 'item_definition',
  257. 'item_definer');
  258. foreach ($indices as $index) {
  259. $retval[$index] = isset($_REQUEST[$index]) ? $_REQUEST[$index] : '';
  260. }
  261. return $retval;
  262. } // end PMA_TRI_getDataFromRequest()
  263. /**
  264. * This function will generate the values that are required to complete
  265. * the "Edit trigger" form given the name of a trigger.
  266. *
  267. * @param string $name The name of the trigger.
  268. *
  269. * @return array Data necessary to create the editor.
  270. */
  271. function PMA_TRI_getDataFromName($name)
  272. {
  273. global $db, $table, $_REQUEST;
  274. $temp = array();
  275. $items = $GLOBALS['dbi']->getTriggers($db, $table, '');
  276. foreach ($items as $value) {
  277. if ($value['name'] == $name) {
  278. $temp = $value;
  279. }
  280. }
  281. if (empty($temp)) {
  282. return false;
  283. } else {
  284. $retval = array();
  285. $retval['create'] = $temp['create'];
  286. $retval['drop'] = $temp['drop'];
  287. $retval['item_name'] = $temp['name'];
  288. $retval['item_table'] = $temp['table'];
  289. $retval['item_action_timing'] = $temp['action_timing'];
  290. $retval['item_event_manipulation'] = $temp['event_manipulation'];
  291. $retval['item_definition'] = $temp['definition'];
  292. $retval['item_definer'] = $temp['definer'];
  293. return $retval;
  294. }
  295. } // end PMA_TRI_getDataFromName()
  296. /**
  297. * Displays a form used to add/edit a trigger
  298. *
  299. * @param string $mode If the editor will be used edit a trigger
  300. * or add a new one: 'edit' or 'add'.
  301. * @param array $item Data for the trigger returned by PMA_TRI_getDataFromRequest()
  302. * or PMA_TRI_getDataFromName()
  303. *
  304. * @return string HTML code for the editor.
  305. */
  306. function PMA_TRI_getEditorForm($mode, $item)
  307. {
  308. global $db, $table, $event_manipulations, $action_timings;
  309. // Escape special characters
  310. $need_escape = array(
  311. 'item_original_name',
  312. 'item_name',
  313. 'item_definition',
  314. 'item_definer'
  315. );
  316. foreach ($need_escape as $key => $index) {
  317. $item[$index] = htmlentities($item[$index], ENT_QUOTES, 'UTF-8');
  318. }
  319. $original_data = '';
  320. if ($mode == 'edit') {
  321. $original_data = "<input name='item_original_name' "
  322. . "type='hidden' value='{$item['item_original_name']}'/>\n";
  323. }
  324. $query = "SELECT `TABLE_NAME` FROM `INFORMATION_SCHEMA`.`TABLES` ";
  325. $query .= "WHERE `TABLE_SCHEMA`='" . PMA_Util::sqlAddSlashes($db) . "' ";
  326. $query .= "AND `TABLE_TYPE`='BASE TABLE'";
  327. $tables = $GLOBALS['dbi']->fetchResult($query);
  328. // Create the output
  329. $retval = "";
  330. $retval .= "<!-- START " . strtoupper($mode) . " TRIGGER FORM -->\n\n";
  331. $retval .= "<form class='rte_form' action='db_triggers.php' method='post'>\n";
  332. $retval .= "<input name='{$mode}_item' type='hidden' value='1' />\n";
  333. $retval .= $original_data;
  334. $retval .= PMA_URL_getHiddenInputs($db, $table) . "\n";
  335. $retval .= "<fieldset>\n";
  336. $retval .= "<legend>" . __('Details') . "</legend>\n";
  337. $retval .= "<table class='rte_table' style='width: 100%'>\n";
  338. $retval .= "<tr>\n";
  339. $retval .= " <td style='width: 20%;'>" . __('Trigger name') . "</td>\n";
  340. $retval .= " <td><input type='text' name='item_name' maxlength='64'\n";
  341. $retval .= " value='{$item['item_name']}' /></td>\n";
  342. $retval .= "</tr>\n";
  343. $retval .= "<tr>\n";
  344. $retval .= " <td>" . __('Table') . "</td>\n";
  345. $retval .= " <td>\n";
  346. $retval .= " <select name='item_table'>\n";
  347. foreach ($tables as $key => $value) {
  348. $selected = "";
  349. if ($mode == 'add' && $value == $table) {
  350. $selected = " selected='selected'";
  351. } else if ($mode == 'edit' && $value == $item['item_table']) {
  352. $selected = " selected='selected'";
  353. }
  354. $retval .= "<option$selected>";
  355. $retval .= htmlspecialchars($value);
  356. $retval .= "</option>\n";
  357. }
  358. $retval .= " </select>\n";
  359. $retval .= " </td>\n";
  360. $retval .= "</tr>\n";
  361. $retval .= "<tr>\n";
  362. $retval .= " <td>" . _pgettext('Trigger action time', 'Time') . "</td>\n";
  363. $retval .= " <td><select name='item_timing'>\n";
  364. foreach ($action_timings as $key => $value) {
  365. $selected = "";
  366. if (! empty($item['item_action_timing'])
  367. && $item['item_action_timing'] == $value
  368. ) {
  369. $selected = " selected='selected'";
  370. }
  371. $retval .= "<option$selected>$value</option>";
  372. }
  373. $retval .= " </select></td>\n";
  374. $retval .= "</tr>\n";
  375. $retval .= "<tr>\n";
  376. $retval .= " <td>" . __('Event') . "</td>\n";
  377. $retval .= " <td><select name='item_event'>\n";
  378. foreach ($event_manipulations as $key => $value) {
  379. $selected = "";
  380. if (! empty($item['item_event_manipulation'])
  381. && $item['item_event_manipulation'] == $value
  382. ) {
  383. $selected = " selected='selected'";
  384. }
  385. $retval .= "<option$selected>$value</option>";
  386. }
  387. $retval .= " </select></td>\n";
  388. $retval .= "</tr>\n";
  389. $retval .= "<tr>\n";
  390. $retval .= " <td>" . __('Definition') . "</td>\n";
  391. $retval .= " <td><textarea name='item_definition' rows='15' cols='40'>";
  392. $retval .= $item['item_definition'];
  393. $retval .= "</textarea></td>\n";
  394. $retval .= "</tr>\n";
  395. $retval .= "<tr>\n";
  396. $retval .= " <td>" . __('Definer') . "</td>\n";
  397. $retval .= " <td><input type='text' name='item_definer'\n";
  398. $retval .= " value='{$item['item_definer']}' /></td>\n";
  399. $retval .= "</tr>\n";
  400. $retval .= "</table>\n";
  401. $retval .= "</fieldset>\n";
  402. if ($GLOBALS['is_ajax_request']) {
  403. $retval .= "<input type='hidden' name='editor_process_{$mode}'\n";
  404. $retval .= " value='true' />\n";
  405. $retval .= "<input type='hidden' name='ajax_request' value='true' />\n";
  406. } else {
  407. $retval .= "<fieldset class='tblFooters'>\n";
  408. $retval .= " <input type='submit' name='editor_process_{$mode}'\n";
  409. $retval .= " value='" . __('Go') . "' />\n";
  410. $retval .= "</fieldset>\n";
  411. }
  412. $retval .= "</form>\n\n";
  413. $retval .= "<!-- END " . strtoupper($mode) . " TRIGGER FORM -->\n\n";
  414. return $retval;
  415. } // end PMA_TRI_getEditorForm()
  416. /**
  417. * Composes the query necessary to create a trigger from an HTTP request.
  418. *
  419. * @return string The CREATE TRIGGER query.
  420. */
  421. function PMA_TRI_getQueryFromRequest()
  422. {
  423. global $_REQUEST, $db, $errors, $action_timings, $event_manipulations;
  424. $query = 'CREATE ';
  425. if (! empty($_REQUEST['item_definer'])) {
  426. if (strpos($_REQUEST['item_definer'], '@') !== false) {
  427. $arr = explode('@', $_REQUEST['item_definer']);
  428. $query .= 'DEFINER=' . PMA_Util::backquote($arr[0]);
  429. $query .= '@' . PMA_Util::backquote($arr[1]) . ' ';
  430. } else {
  431. $errors[] = __('The definer must be in the "username@hostname" format!');
  432. }
  433. }
  434. $query .= 'TRIGGER ';
  435. if (! empty($_REQUEST['item_name'])) {
  436. $query .= PMA_Util::backquote($_REQUEST['item_name']) . ' ';
  437. } else {
  438. $errors[] = __('You must provide a trigger name!');
  439. }
  440. if (! empty($_REQUEST['item_timing'])
  441. && in_array($_REQUEST['item_timing'], $action_timings)
  442. ) {
  443. $query .= $_REQUEST['item_timing'] . ' ';
  444. } else {
  445. $errors[] = __('You must provide a valid timing for the trigger!');
  446. }
  447. if (! empty($_REQUEST['item_event'])
  448. && in_array($_REQUEST['item_event'], $event_manipulations)
  449. ) {
  450. $query .= $_REQUEST['item_event'] . ' ';
  451. } else {
  452. $errors[] = __('You must provide a valid event for the trigger!');
  453. }
  454. $query .= 'ON ';
  455. if (! empty($_REQUEST['item_table'])
  456. && in_array($_REQUEST['item_table'], $GLOBALS['dbi']->getTables($db))
  457. ) {
  458. $query .= PMA_Util::backquote($_REQUEST['item_table']);
  459. } else {
  460. $errors[] = __('You must provide a valid table name!');
  461. }
  462. $query .= ' FOR EACH ROW ';
  463. if (! empty($_REQUEST['item_definition'])) {
  464. $query .= $_REQUEST['item_definition'];
  465. } else {
  466. $errors[] = __('You must provide a trigger definition.');
  467. }
  468. return $query;
  469. } // end PMA_TRI_getQueryFromRequest()
  470. ?>