api de gestion de ticket, basé sur php-crud-api. Le but est de décorrélé les outils de gestion des données, afin
選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

api.php 25KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784
  1. <?php
  2. class MySQL_CRUD_API extends REST_CRUD_API {
  3. protected $queries = array(
  4. 'reflect_table'=>'SELECT "TABLE_NAME" FROM "INFORMATION_SCHEMA"."TABLES" WHERE "TABLE_NAME" LIKE ? AND "TABLE_SCHEMA" = ?',
  5. 'reflect_pk'=>'SELECT "COLUMN_NAME" FROM "INFORMATION_SCHEMA"."COLUMNS" WHERE "COLUMN_KEY" = \'PRI\' AND "TABLE_NAME" = ? AND "TABLE_SCHEMA" = ?',
  6. 'reflect_belongs_to'=>'SELECT
  7. "TABLE_NAME","COLUMN_NAME",
  8. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  9. FROM
  10. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  11. WHERE
  12. "TABLE_NAME" = ? AND
  13. "REFERENCED_TABLE_NAME" IN ? AND
  14. "TABLE_SCHEMA" = ? AND
  15. "REFERENCED_TABLE_SCHEMA" = ?',
  16. 'reflect_has_many'=>'SELECT
  17. "TABLE_NAME","COLUMN_NAME",
  18. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  19. FROM
  20. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  21. WHERE
  22. "TABLE_NAME" IN ? AND
  23. "REFERENCED_TABLE_NAME" = ? AND
  24. "TABLE_SCHEMA" = ? AND
  25. "REFERENCED_TABLE_SCHEMA" = ?',
  26. 'reflect_habtm'=>'SELECT
  27. k1."TABLE_NAME", k1."COLUMN_NAME",
  28. k1."REFERENCED_TABLE_NAME", k1."REFERENCED_COLUMN_NAME",
  29. k2."TABLE_NAME", k2."COLUMN_NAME",
  30. k2."REFERENCED_TABLE_NAME", k2."REFERENCED_COLUMN_NAME"
  31. FROM
  32. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k1, "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k2
  33. WHERE
  34. k1."TABLE_SCHEMA" = ? AND
  35. k2."TABLE_SCHEMA" = ? AND
  36. k1."REFERENCED_TABLE_SCHEMA" = ? AND
  37. k2."REFERENCED_TABLE_SCHEMA" = ? AND
  38. k1."TABLE_NAME" = k2."TABLE_NAME" AND
  39. k1."REFERENCED_TABLE_NAME" = ? AND
  40. k2."REFERENCED_TABLE_NAME" IN ?'
  41. );
  42. protected function connectDatabase($hostname,$username,$password,$database,$port,$socket,$charset) {
  43. $db = mysqli_connect($hostname,$username,$password,$database,$port,$socket);
  44. if (mysqli_connect_errno()) {
  45. throw new \Exception('Connect failed. '.mysqli_connect_error());
  46. }
  47. if (!mysqli_set_charset($db,$charset)) {
  48. throw new \Exception('Error setting charset. '.mysqli_error($db));
  49. }
  50. if (!mysqli_query($db,'SET SESSION sql_mode = \'ANSI_QUOTES\';')) {
  51. throw new \Exception('Error setting ANSI quotes. '.mysqli_error($db));
  52. }
  53. return $db;
  54. }
  55. protected function query($db,$sql,$params) {
  56. $sql = preg_replace_callback('/\!|\?/', function ($matches) use (&$db,&$params) {
  57. $param = array_shift($params);
  58. if ($matches[0]=='!') return preg_replace('/[^a-zA-Z0-9\-_=<>]/','',$param);
  59. if (is_array($param)) return '('.implode(',',array_map(function($v) use (&$db) {
  60. return "'".mysqli_real_escape_string($db,$v)."'";
  61. },$param)).')';
  62. return "'".mysqli_real_escape_string($db,$param)."'";
  63. }, $sql);
  64. //echo "\n$sql\n";
  65. return mysqli_query($db,$sql);
  66. }
  67. protected function fetch_assoc($result) {
  68. return mysqli_fetch_assoc($result);
  69. }
  70. protected function fetch_row($result) {
  71. return mysqli_fetch_row($result);
  72. }
  73. protected function insert_id($db,$result) {
  74. return mysqli_insert_id($db);
  75. }
  76. protected function affected_rows($db,$result) {
  77. return mysqli_affected_rows($db);
  78. }
  79. protected function close($result) {
  80. return mysqli_free_result($result);
  81. }
  82. protected function fetch_fields($result) {
  83. return mysqli_fetch_fields($result);
  84. }
  85. protected function add_limit_to_sql($sql,$limit,$offset) {
  86. return "$sql LIMIT $limit OFFSET $offset";
  87. }
  88. protected function likeEscape($string) {
  89. return addcslashes($string,'%_');
  90. }
  91. protected function is_binary_type($field) {
  92. //echo "$field->name: $field->type ($field->flags)\n";
  93. return (($field->flags & 128) && ($field->type==252));
  94. }
  95. }
  96. class SQLSRV_CRUD_API extends REST_CRUD_API {
  97. protected $queries = array(
  98. 'reflect_table'=>'SELECT "TABLE_NAME" FROM "INFORMATION_SCHEMA"."TABLES" WHERE "TABLE_NAME" LIKE ? AND "TABLE_CATALOG" = ?',
  99. 'reflect_pk'=>'SELECT "COLUMN_NAME" FROM "INFORMATION_SCHEMA"."COLUMNS" WHERE "COLUMN_KEY" = \'PRI\' AND "TABLE_NAME" = ? AND "TABLE_CATALOG" = ?',
  100. 'reflect_belongs_to'=>'SELECT
  101. "TABLE_NAME","COLUMN_NAME",
  102. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  103. FROM
  104. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  105. WHERE
  106. "TABLE_NAME" = ? AND
  107. "REFERENCED_TABLE_NAME" IN ? AND
  108. "TABLE_CATALOG" = ? AND
  109. "REFERENCED_TABLE_CATALOG" = ?',
  110. 'reflect_has_many'=>'SELECT
  111. "TABLE_NAME","COLUMN_NAME",
  112. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  113. FROM
  114. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  115. WHERE
  116. "TABLE_NAME" IN ? AND
  117. "REFERENCED_TABLE_NAME" = ? AND
  118. "TABLE_CATALOG" = ? AND
  119. "REFERENCED_TABLE_CATALOG" = ?',
  120. 'reflect_habtm'=>'SELECT
  121. k1."TABLE_NAME", k1."COLUMN_NAME",
  122. k1."REFERENCED_TABLE_NAME", k1."REFERENCED_COLUMN_NAME",
  123. k2."TABLE_NAME", k2."COLUMN_NAME",
  124. k2."REFERENCED_TABLE_NAME", k2."REFERENCED_COLUMN_NAME"
  125. FROM
  126. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k1, "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k2
  127. WHERE
  128. k1."TABLE_CATALOG" = ? AND
  129. k2."TABLE_CATALOG" = ? AND
  130. k1."REFERENCED_TABLE_CATALOG" = ? AND
  131. k2."REFERENCED_TABLE_CATALOG" = ? AND
  132. k1."TABLE_NAME" = k2."TABLE_NAME" AND
  133. k1."REFERENCED_TABLE_NAME" = ? AND
  134. k2."REFERENCED_TABLE_NAME" IN ?'
  135. );
  136. protected function connectDatabase($hostname,$username,$password,$database,$port,$socket,$charset) {
  137. $connectionInfo = array();
  138. if ($port) $hostname.=','.$port;
  139. if ($username) $connectionInfo['UID']=$username;
  140. if ($password) $connectionInfo['PWD']=$password;
  141. if ($database) $connectionInfo['Database']=$database;
  142. if ($charset) $connectionInfo['CharacterSet']=$charset;
  143. $connectionInfo['QuotedId']=1;
  144. $db = sqlsrv_connect($hostname, $connectionInfo);
  145. if (!$db) {
  146. throw new \Exception('Connect failed. '.print_r( sqlsrv_errors(), true));
  147. }
  148. if ($socket) {
  149. throw new \Exception('Socket connection is not supported.');
  150. }
  151. return $db;
  152. }
  153. protected function query($db,$sql,$params) {
  154. $args = array();
  155. $sql = preg_replace_callback('/\!|\?/', function ($matches) use (&$db,&$params,&$args) {
  156. static $i=-1;
  157. $i++;
  158. $param = $params[$i];
  159. if ($matches[0]=='!') {
  160. return preg_replace('/[^a-zA-Z0-9\-_=<>]/','',$param);
  161. }
  162. if (is_array($param)) {
  163. $args = array_merge($args,$param);
  164. return '('.implode(',',str_split(str_repeat('?',count($param)))).')';
  165. }
  166. $args[] = $param;
  167. return '?';
  168. }, $sql);
  169. //echo "\n$sql\n";
  170. //var_dump($args);
  171. return sqlsrv_query($db,$sql,$args);
  172. }
  173. protected function fetch_assoc($result) {
  174. return sqlsrv_fetch_array($result, SQLSRV_FETCH_ASSOC);
  175. }
  176. protected function fetch_row($result) {
  177. return sqlsrv_fetch_array($result, SQLSRV_FETCH_NUMERIC);
  178. }
  179. protected function insert_id($db) {
  180. $result = sqlsrv_query($db, 'SELECT SCOPE_IDENTITY()');
  181. $data = sqlsrv_fetch_array($result, SQLSRV_FETCH_NUMERIC);
  182. return $data[0];
  183. }
  184. protected function affected_rows($db,$result) {
  185. return sqlsrv_rows_affected($result);
  186. }
  187. protected function close($result) {
  188. return sqlsrv_free_stmt($result);
  189. }
  190. protected function fetch_fields($result) {
  191. //var_dump(sqlsrv_field_metadata($result));
  192. return array_map(function($a){
  193. $p = array();
  194. foreach ($a as $k=>$v) {
  195. $p[strtolower($k)] = $v;
  196. }
  197. return (object)$p;
  198. },sqlsrv_field_metadata($result));
  199. }
  200. protected function add_limit_to_sql($sql,$limit,$offset) {
  201. return "$sql OFFSET $offset ROWS FETCH NEXT $limit ROWS ONLY";
  202. }
  203. protected function likeEscape($string) {
  204. return str_replace(array('%','_'),array('[%]','[_]'),$string);
  205. }
  206. protected function is_binary_type($field) {
  207. return ($field->type>=-4 && $field->type<=-2);
  208. }
  209. }
  210. class REST_CRUD_API {
  211. protected $config;
  212. protected function mapMethodToAction($method,$key) {
  213. switch ($method) {
  214. case 'GET': return $key?'read':'list';
  215. case 'PUT': return 'update';
  216. case 'POST': return 'create';
  217. case 'DELETE': return 'delete';
  218. default: $this->exitWith404('method');
  219. }
  220. }
  221. protected function parseRequestParameter(&$request,$characters,$default) {
  222. if (!count($request)) return $default;
  223. $value = array_shift($request);
  224. return $characters?preg_replace("/[^$characters]/",'',$value):$value;
  225. }
  226. protected function parseGetParameter($get,$name,$characters,$default) {
  227. $value = isset($get[$name])?$get[$name]:$default;
  228. return $characters?preg_replace("/[^$characters]/",'',$value):$value;
  229. }
  230. protected function parseGetParameterArray($get,$name,$characters,$default) {
  231. $values = isset($get[$name])?$get[$name]:$default;
  232. if (!is_array($values)) $values = array($values);
  233. if ($characters) {
  234. foreach ($values as &$value) {
  235. $value = preg_replace("/[^$characters]/",'',$value);
  236. }
  237. }
  238. return $values;
  239. }
  240. protected function applyPermissions($database, $tables, $action, $permissions, $multidb) {
  241. if (in_array(strtolower($database), array('information_schema','mysql','sys'))) return array();
  242. $results = array();
  243. $permissions = array_change_key_case($permissions,CASE_LOWER);
  244. foreach ($tables as $table) {
  245. $result = false;
  246. $options = $multidb?array("*.*","$database.*","$database.$table"):array("*","$table");
  247. $options = array_map('strtolower', $options);
  248. foreach ($options as $option) {
  249. if (isset($permissions[$option])) {
  250. $result = strpos($permissions[$option],$action[0])!==false;
  251. }
  252. }
  253. if ($result) $results[] = $table;
  254. }
  255. return $results;
  256. }
  257. protected function processTableParameter($database,$table,$db) {
  258. $tablelist = explode(',',$table);
  259. $tables = array();
  260. foreach ($tablelist as $table) {
  261. $table = str_replace('*','%',$table);
  262. if ($result = $this->query($db,$this->queries['reflect_table'],array($table,$database))) {
  263. while ($row = $this->fetch_row($result)) $tables[] = $row[0];
  264. $this->close($result);
  265. }
  266. }
  267. return $tables;
  268. }
  269. protected function findSinglePrimaryKey($table,$database,$db) {
  270. $keys = array();
  271. if ($result = $this->query($db,$this->queries['reflect_pk'],array($table[0],$database))) {
  272. while ($row = $this->fetch_row($result)) $keys[] = $row[0];
  273. $this->close($result);
  274. }
  275. return count($keys)==1?$keys[0]:false;
  276. }
  277. protected function exitWith404($type) {
  278. if (isset($_SERVER['REQUEST_METHOD'])) {
  279. header('Content-Type:',true,404);
  280. die("Not found ($type)");
  281. } else {
  282. throw new \Exception("Not found ($type)");
  283. }
  284. }
  285. protected function startOutput($callback) {
  286. if (isset($_SERVER['REQUEST_METHOD'])) {
  287. header('Access-Control-Allow-Origin: *');
  288. if ($callback) {
  289. header('Content-Type: application/javascript');
  290. echo $callback.'(';
  291. } else {
  292. header('Content-Type: application/json');
  293. }
  294. }
  295. }
  296. protected function endOutput($callback) {
  297. if ($callback) {
  298. echo ');';
  299. }
  300. }
  301. protected function processKeyParameter($key,$table,$database,$db) {
  302. if ($key) {
  303. $key = array($key,$this->findSinglePrimaryKey($table,$database,$db));
  304. if ($key[1]===false) $this->exitWith404('1pk');
  305. }
  306. return $key;
  307. }
  308. protected function processOrderParameter($order,$table,$database,$db) {
  309. if ($order) {
  310. $order = explode(',',$order,2);
  311. if (count($order)<2) $order[1]='ASC';
  312. $order[1] = strtoupper($order[1])=='DESC'?'DESC':'ASC';
  313. }
  314. return $order;
  315. }
  316. protected function processFilterParameter($filter,$db) {
  317. if ($filter) {
  318. $filter = explode(',',$filter,3);
  319. if (count($filter)==3) {
  320. $match = $filter[1];
  321. $filter[1] = 'LIKE';
  322. if ($match=='cs') $filter[2] = '%'.$this->likeEscape($filter[2]).'%';
  323. if ($match=='sw') $filter[2] = $this->likeEscape($filter[2]).'%';
  324. if ($match=='ew') $filter[2] = '%'.$this->likeEscape($filter[2]);
  325. if ($match=='eq') $filter[1] = '=';
  326. if ($match=='ne') $filter[1] = '<>';
  327. if ($match=='lt') $filter[1] = '<';
  328. if ($match=='le') $filter[1] = '<=';
  329. if ($match=='ge') $filter[1] = '>=';
  330. if ($match=='gt') $filter[1] = '>';
  331. if ($match=='in') {
  332. $filter[1] = 'IN';
  333. $filter[2] = explode(',',$filter[2]);
  334. }
  335. } else {
  336. $filter = false;
  337. }
  338. }
  339. return $filter;
  340. }
  341. protected function processPageParameter($page) {
  342. if ($page) {
  343. $page = explode(',',$page,2);
  344. if (count($page)<2) $page[1]=20;
  345. $page[0] = ($page[0]-1)*$page[1];
  346. }
  347. return $page;
  348. }
  349. protected function retrieveObject($key,$table,$db) {
  350. if (!$key) return false;
  351. if ($result = $this->query($db,'SELECT * FROM "!" WHERE "!" = ?',array($table[0],$key[1],$key[0]))) {
  352. $object = $this->fetch_assoc($result);
  353. $this->close($result);
  354. }
  355. return $object;
  356. }
  357. protected function createObject($input,$table,$db) {
  358. if (!$input) return false;
  359. $keys = implode('","',str_split(str_repeat('!', count($input))));
  360. $values = implode(',',str_split(str_repeat('?', count($input))));
  361. $params = array_merge(array_keys((array)$input),array_values((array)$input));
  362. array_unshift($params, $table[0]);
  363. $result = $this->query($db,'INSERT INTO "!" ("'.$keys.'") VALUES ('.$values.')',$params);
  364. return $this->insert_id($db,$result);
  365. }
  366. protected function updateObject($key,$input,$table,$db) {
  367. if (!$input) return false;
  368. $params = array();
  369. $sql = 'UPDATE "!" SET ';
  370. $params[] = $table[0];
  371. foreach (array_keys($input) as $i=>$k) {
  372. if ($i) $sql .= ',';
  373. $v = $input[$k];
  374. $sql .= '"!"=?';
  375. $params[] = $k;
  376. $params[] = $v;
  377. }
  378. $sql .= ' WHERE "!"=?';
  379. $params[] = $key[1];
  380. $params[] = $key[0];
  381. $result = $this->query($db,$sql,$params);
  382. return $this->affected_rows($db, $result);
  383. }
  384. protected function deleteObject($key,$table,$db) {
  385. $result = $this->query($db,'DELETE FROM "!" WHERE "!" = ?',array($table[0],$key[1],$key[0]));
  386. return $this->affected_rows($db, $result);
  387. }
  388. protected function findRelations($tables,$database,$db) {
  389. $collect = array();
  390. $select = array();
  391. if (count($tables)>1) {
  392. $table0 = array_shift($tables);
  393. $result = $this->query($db,$this->queries['reflect_belongs_to'],array($table0,$tables,$database,$database));
  394. while ($row = $this->fetch_row($result)) {
  395. $collect[$row[0]][$row[1]]=array();
  396. $select[$row[2]][$row[3]]=array($row[0],$row[1]);
  397. }
  398. $result = $this->query($db,$this->queries['reflect_has_many'],array($tables,$table0,$database,$database));
  399. while ($row = $this->fetch_row($result)) {
  400. $collect[$row[2]][$row[3]]=array();
  401. $select[$row[0]][$row[1]]=array($row[2],$row[3]);
  402. }
  403. $result = $this->query($db,$this->queries['reflect_habtm'],array($database,$database,$database,$database,$table0,$tables));
  404. while ($row = $this->fetch_row($result)) {
  405. $collect[$row[2]][$row[3]]=array();
  406. $select[$row[0]][$row[1]]=array($row[2],$row[3]);
  407. $collect[$row[4]][$row[5]]=array();
  408. $select[$row[6]][$row[7]]=array($row[4],$row[5]);
  409. }
  410. }
  411. return array($collect,$select);
  412. }
  413. protected function getParameters($config) {
  414. extract($config);
  415. $table = $this->parseRequestParameter($request, 'a-zA-Z0-9\-_*,', false);
  416. $key = $this->parseRequestParameter($request, 'a-zA-Z0-9\-,', false); // auto-increment or uuid
  417. $action = $this->mapMethodToAction($method,$key);
  418. $callback = $this->parseGetParameter($get, 'callback', 'a-zA-Z0-9\-_', false);
  419. $page = $this->parseGetParameter($get, 'page', '0-9,', false);
  420. $filters = $this->parseGetParameterArray($get, 'filter', false, false);
  421. $satisfy = $this->parseGetParameter($get, 'satisfy', 'a-z', 'all');
  422. $columns = $this->parseGetParameter($get, 'columns', 'a-zA-Z0-9\-_,', false);
  423. $order = $this->parseGetParameter($get, 'order', 'a-zA-Z0-9\-_*,', false);
  424. $transform = $this->parseGetParameter($get, 'transform', '1', false);
  425. $table = $this->processTableParameter($database,$table,$db);
  426. $key = $this->processKeyParameter($key,$table,$database,$db);
  427. foreach ($filters as &$filter) $filter = $this->processFilterParameter($filter,$db);
  428. if ($columns) $columns = explode(',',$columns);
  429. $page = $this->processPageParameter($page);
  430. $order = $this->processOrderParameter($order,$table,$database,$db);
  431. $table = $this->applyPermissions($database,$table,$action,$permissions,$multidb);
  432. if (empty($table)) $this->exitWith404('entity');
  433. $object = $this->retrieveObject($key,$table,$db);
  434. $input = json_decode(file_get_contents($post),true);
  435. list($collect,$select) = $this->findRelations($table,$database,$db);
  436. return compact('action','database','table','key','callback','page','filters','satisfy','columns','order','transform','db','object','input','collect','select');
  437. }
  438. protected function listCommand($parameters) {
  439. extract($parameters);
  440. $this->startOutput($callback);
  441. echo '{';
  442. $tables = $table;
  443. $table = array_shift($tables);
  444. // first table
  445. $count = false;
  446. echo '"'.$table.'":{';
  447. if (is_array($order) && is_array($page)) {
  448. $params = array();
  449. $sql = 'SELECT COUNT(*) FROM "!"';
  450. $params[] = $table;
  451. foreach ($filters as $i=>$filter) {
  452. if (is_array($filter)) {
  453. $sql .= $i==0?' WHERE ':($satisfy=='all'?' AND ':' OR ');
  454. $sql .= '"!" ! ?';
  455. $params[] = $filter[0];
  456. $params[] = $filter[1];
  457. $params[] = $filter[2];
  458. }
  459. }
  460. if ($result = $this->query($db,$sql,$params)) {
  461. while ($pages = $this->fetch_row($result)) {
  462. $count = $pages[0];
  463. }
  464. }
  465. }
  466. $params = array();
  467. $sql = 'SELECT ';
  468. if (is_array($columns)) {
  469. $sql .= '"'.implode('","',$columns).'"';
  470. } else {
  471. $sql .= '*';
  472. }
  473. $sql .= ' FROM "!"';
  474. $params[] = $table;
  475. foreach ($filters as $i=>$filter) {
  476. if (is_array($filter)) {
  477. $sql .= $i==0?' WHERE ':($satisfy=='all'?' AND ':' OR ');
  478. $sql .= '"!" ! ?';
  479. $params[] = $filter[0];
  480. $params[] = $filter[1];
  481. $params[] = $filter[2];
  482. }
  483. }
  484. if (is_array($order)) {
  485. $sql .= ' ORDER BY "!" !';
  486. $params[] = $order[0];
  487. $params[] = $order[1];
  488. }
  489. if (is_array($order) && is_array($page)) {
  490. $sql = $this->add_limit_to_sql($sql,$page[1],$page[0]);
  491. }
  492. if ($result = $this->query($db,$sql,$params)) {
  493. echo '"columns":';
  494. $fields = array();
  495. $base64 = array();
  496. foreach ($this->fetch_fields($result) as $field) {
  497. $base64[] = $this->is_binary_type($field);
  498. $fields[] = $field->name;
  499. }
  500. echo json_encode($fields);
  501. $fields = array_flip($fields);
  502. echo ',"records":[';
  503. $first_row = true;
  504. while ($row = $this->fetch_row($result)) {
  505. if ($first_row) $first_row = false;
  506. else echo ',';
  507. if (isset($collect[$table])) {
  508. foreach (array_keys($collect[$table]) as $field) {
  509. $collect[$table][$field][] = $row[$fields[$field]];
  510. }
  511. }
  512. foreach ($base64 as $k=>$v) {
  513. if ($v) {
  514. $row[$k] = base64_encode($row[$k]);
  515. }
  516. }
  517. echo json_encode($row);
  518. }
  519. $this->close($result);
  520. echo ']';
  521. if ($count) echo ',';
  522. }
  523. if ($count) echo '"results":'.$count;
  524. echo '}';
  525. // prepare for other tables
  526. foreach (array_keys($collect) as $t) {
  527. if ($t!=$table && !in_array($t,$tables)) {
  528. array_unshift($tables,$t);
  529. }
  530. }
  531. // other tables
  532. foreach ($tables as $t=>$table) {
  533. echo ',';
  534. echo '"'.$table.'":{';
  535. $params = array();
  536. $sql = 'SELECT * FROM "!"';
  537. $params[] = $table;
  538. if (isset($select[$table])) {
  539. $first_row = true;
  540. echo '"relations":{';
  541. foreach ($select[$table] as $field => $path) {
  542. $values = $collect[$path[0]][$path[1]];
  543. $sql .= $first_row?' WHERE ':' OR ';
  544. $sql .= '"!" IN ?';
  545. $params[] = $field;
  546. $params[] = $values;
  547. if ($first_row) $first_row = false;
  548. else echo ',';
  549. echo '"'.$field.'":"'.implode('.',$path).'"';
  550. }
  551. echo '}';
  552. }
  553. if ($result = $this->query($db,$sql,$params)) {
  554. echo ',"columns":';
  555. $fields = array();
  556. $base64 = array();
  557. foreach ($this->fetch_fields($result) as $field) {
  558. $base64[] = $this->is_binary_type($field);
  559. $fields[] = $field->name;
  560. }
  561. echo json_encode($fields);
  562. $fields = array_flip($fields);
  563. echo ',"records":[';
  564. $first_row = true;
  565. while ($row = $this->fetch_row($result)) {
  566. if ($first_row) $first_row = false;
  567. else echo ',';
  568. if (isset($collect[$table])) {
  569. foreach (array_keys($collect[$table]) as $field) {
  570. $collect[$table][$field][]=$row[$fields[$field]];
  571. }
  572. }
  573. foreach ($base64 as $k=>$v) {
  574. if ($v) {
  575. $row[$k] = base64_encode($row[$k]);
  576. }
  577. }
  578. echo json_encode($row);
  579. }
  580. $this->close($result);
  581. echo ']';
  582. }
  583. echo '}';
  584. }
  585. echo '}';
  586. $this->endOutput($callback);
  587. }
  588. protected function readCommand($parameters) {
  589. extract($parameters);
  590. if (!$object) $this->exitWith404('object');
  591. $this->startOutput($callback);
  592. echo json_encode($object);
  593. $this->endOutput($callback);
  594. }
  595. protected function createCommand($parameters) {
  596. extract($parameters);
  597. if (!$input) $this->exitWith404('input');
  598. $this->startOutput($callback);
  599. echo json_encode($this->createObject($input,$table,$db));
  600. $this->endOutput($callback);
  601. }
  602. protected function updateCommand($parameters) {
  603. extract($parameters);
  604. if (!$input) $this->exitWith404('subject');
  605. $this->startOutput($callback);
  606. echo json_encode($this->updateObject($key,$input,$table,$db));
  607. $this->endOutput($callback);
  608. }
  609. protected function deleteCommand($parameters) {
  610. extract($parameters);
  611. $this->startOutput($callback);
  612. echo json_encode($this->deleteObject($key,$table,$db));
  613. $this->endOutput($callback);
  614. }
  615. protected function listCommandTransform($parameters) {
  616. if ($parameters['transform']) {
  617. ob_start();
  618. }
  619. $this->listCommand($parameters);
  620. if ($parameters['transform']) {
  621. $content = ob_get_contents();
  622. ob_end_clean();
  623. $data = json_decode($content,true);
  624. echo json_encode(self::mysql_crud_api_transform($data));
  625. }
  626. }
  627. public function __construct($config) {
  628. extract($config);
  629. $hostname = isset($hostname)?$hostname:null;
  630. $username = isset($username)?$username:'root';
  631. $password = isset($password)?$password:null;
  632. $database = isset($database)?$database:false;
  633. $port = isset($port)?$port:null;
  634. $socket = isset($socket)?$socket:null;
  635. $charset = isset($charset)?$charset:'utf8';
  636. $permissions = isset($permissions)?$permissions:array('*'=>'crudl');
  637. $db = isset($db)?$db:null;
  638. $method = isset($method)?$method:$_SERVER['REQUEST_METHOD'];
  639. $request = isset($request)?$request:(isset($_SERVER['PATH_INFO'])?$_SERVER['PATH_INFO']:'');
  640. $get = isset($get)?$get:$_GET;
  641. $post = isset($post)?$post:'php://input';
  642. $request = explode('/', trim($request,'/'));
  643. $multidb = !$database;
  644. if ($multidb) {
  645. $database = $this->parseRequestParameter($request, 'a-zA-Z0-9\-_,', false);
  646. }
  647. if (!$db) {
  648. $db = $this->connectDatabase($hostname,$username,$password,$database,$port,$socket,$charset);
  649. }
  650. $this->config = compact('method', 'request', 'get', 'post', 'multidb', 'database', 'permissions', 'db');
  651. }
  652. public static function mysql_crud_api_transform(&$tables) {
  653. $get_objects = function (&$tables,$table_name,$where_index=false,$match_value=false) use (&$get_objects) {
  654. $objects = array();
  655. foreach ($tables[$table_name]['records'] as $record) {
  656. if ($where_index===false || $record[$where_index]==$match_value) {
  657. $object = array();
  658. foreach ($tables[$table_name]['columns'] as $index=>$column) {
  659. $object[$column] = $record[$index];
  660. foreach ($tables as $relation=>$reltable) {
  661. if (isset($reltable['relations'])) {
  662. foreach ($reltable['relations'] as $key=>$target) {
  663. if ($target == "$table_name.$column") {
  664. $column_indices = array_flip($reltable['columns']);
  665. $object[$relation] = $get_objects($tables,$relation,$column_indices[$key],$record[$index]);
  666. }
  667. }
  668. }
  669. }
  670. }
  671. $objects[] = $object;
  672. }
  673. }
  674. return $objects;
  675. };
  676. $tree = array();
  677. foreach ($tables as $name=>$table) {
  678. if (!isset($table['relations'])) {
  679. $tree[$name] = $get_objects($tables,$name);
  680. if (isset($table['results'])) {
  681. $tree['_results'] = $table['results'];
  682. }
  683. }
  684. }
  685. return $tree;
  686. }
  687. public function executeCommand() {
  688. $parameters = $this->getParameters($this->config);
  689. switch($parameters['action']){
  690. case 'list': $this->listCommandTransform($parameters); break;
  691. case 'read': $this->readCommand($parameters); break;
  692. case 'create': $this->createCommand($parameters); break;
  693. case 'update': $this->updateCommand($parameters); break;
  694. case 'delete': $this->deleteCommand($parameters); break;
  695. }
  696. }
  697. }
  698. // only execute this when running in stand-alone mode
  699. if(count(get_required_files())<2) {
  700. header('Access-Control-Allow-Origin: *');
  701. $api = new SQLSRV_CRUD_API(array(
  702. 'hostname'=>'(local)',
  703. 'username'=>'',
  704. 'password'=>'',
  705. 'database'=>'xxx',
  706. 'charset'=>'UTF-8'
  707. ));
  708. $api->executeCommand();
  709. }