api de gestion de ticket, basé sur php-crud-api. Le but est de décorrélé les outils de gestion des données, afin
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

api.php 24KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776
  1. <?php
  2. class MySQL_CRUD_API extends REST_CRUD_API {
  3. protected $queries = array(
  4. 'reflect_table'=>'SELECT "TABLE_NAME" FROM "INFORMATION_SCHEMA"."TABLES" WHERE "TABLE_NAME" LIKE ? AND "TABLE_SCHEMA" = ?',
  5. 'reflect_pk'=>'SELECT "COLUMN_NAME" FROM "INFORMATION_SCHEMA"."COLUMNS" WHERE "COLUMN_KEY" = \'PRI\' AND "TABLE_NAME" = ? AND "TABLE_SCHEMA" = ?',
  6. 'reflect_belongs_to'=>'SELECT
  7. "TABLE_NAME","COLUMN_NAME",
  8. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  9. FROM
  10. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  11. WHERE
  12. "TABLE_NAME" = ? AND
  13. "REFERENCED_TABLE_NAME" IN ? AND
  14. "TABLE_SCHEMA" = ? AND
  15. "REFERENCED_TABLE_SCHEMA" = ?',
  16. 'reflect_has_many'=>'SELECT
  17. "TABLE_NAME","COLUMN_NAME",
  18. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  19. FROM
  20. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  21. WHERE
  22. "TABLE_NAME" IN ? AND
  23. "REFERENCED_TABLE_NAME" = ? AND
  24. "TABLE_SCHEMA" = ? AND
  25. "REFERENCED_TABLE_SCHEMA" = ?',
  26. 'reflect_habtm'=>'SELECT
  27. k1."TABLE_NAME", k1."COLUMN_NAME",
  28. k1."REFERENCED_TABLE_NAME", k1."REFERENCED_COLUMN_NAME",
  29. k2."TABLE_NAME", k2."COLUMN_NAME",
  30. k2."REFERENCED_TABLE_NAME", k2."REFERENCED_COLUMN_NAME"
  31. FROM
  32. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k1, "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k2
  33. WHERE
  34. k1."TABLE_SCHEMA" = ? AND
  35. k2."TABLE_SCHEMA" = ? AND
  36. k1."REFERENCED_TABLE_SCHEMA" = ? AND
  37. k2."REFERENCED_TABLE_SCHEMA" = ? AND
  38. k1."TABLE_NAME" = k2."TABLE_NAME" AND
  39. k1."REFERENCED_TABLE_NAME" = ? AND
  40. k2."REFERENCED_TABLE_NAME" IN ?'
  41. );
  42. protected function connectDatabase($hostname,$username,$password,$database,$port,$socket,$charset) {
  43. $db = mysqli_connect($hostname,$username,$password,$database,$port,$socket);
  44. if (mysqli_connect_errno()) {
  45. throw new \Exception('Connect failed. '.mysqli_connect_error());
  46. }
  47. if (!mysqli_set_charset($db,$charset)) {
  48. throw new \Exception('Error setting charset. '.mysqli_error($db));
  49. }
  50. if (!mysqli_query($db,'SET SESSION sql_mode = \'ANSI_QUOTES\';')) {
  51. throw new \Exception('Error setting ANSI quotes. '.mysqli_error($db));
  52. }
  53. return $db;
  54. }
  55. protected function query($db,$sql,$params) {
  56. $sql = preg_replace_callback('/\!|\?/', function ($matches) use (&$db,&$params) {
  57. $param = array_shift($params);
  58. if ($matches[0]=='!') return preg_replace('/[^a-zA-Z0-9\-_=<>]/','',$param);
  59. if (is_array($param)) return '('.implode(',',array_map(function($v) use (&$db) {
  60. return "'".mysqli_real_escape_string($db,$v)."'";
  61. },$param)).')';
  62. return "'".mysqli_real_escape_string($db,$param)."'";
  63. }, $sql);
  64. //echo "\n$sql\n";
  65. return mysqli_query($db,$sql);
  66. }
  67. protected function fetch_assoc($result) {
  68. return mysqli_fetch_assoc($result);
  69. }
  70. protected function fetch_row($result) {
  71. return mysqli_fetch_row($result);
  72. }
  73. protected function insert_id($db,$result) {
  74. return mysqli_insert_id($db);
  75. }
  76. protected function affected_rows($db,$result) {
  77. return mysqli_affected_rows($db);
  78. }
  79. protected function close($result) {
  80. return mysqli_free_result($result);
  81. }
  82. protected function fetch_fields($result) {
  83. return mysqli_fetch_fields($result);
  84. }
  85. protected function add_limit_to_sql($sql,$limit,$offset) {
  86. return "$sql LIMIT $limit OFFSET $offset";
  87. }
  88. protected function is_binary_type($field) {
  89. //echo "$field->name: $field->type ($field->flags)\n";
  90. return (($field->flags & 128) && ($field->type==252));
  91. }
  92. }
  93. class SQLSRV_CRUD_API extends REST_CRUD_API {
  94. protected $queries = array(
  95. 'reflect_table'=>'SELECT "TABLE_NAME" FROM "INFORMATION_SCHEMA"."TABLES" WHERE "TABLE_NAME" LIKE ? AND "TABLE_CATALOG" = ?',
  96. 'reflect_pk'=>'SELECT "COLUMN_NAME" FROM "INFORMATION_SCHEMA"."COLUMNS" WHERE "COLUMN_KEY" = \'PRI\' AND "TABLE_NAME" = ? AND "TABLE_CATALOG" = ?',
  97. 'reflect_belongs_to'=>'SELECT
  98. "TABLE_NAME","COLUMN_NAME",
  99. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  100. FROM
  101. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  102. WHERE
  103. "TABLE_NAME" = ? AND
  104. "REFERENCED_TABLE_NAME" IN ? AND
  105. "TABLE_CATALOG" = ? AND
  106. "REFERENCED_TABLE_CATALOG" = ?',
  107. 'reflect_has_many'=>'SELECT
  108. "TABLE_NAME","COLUMN_NAME",
  109. "REFERENCED_TABLE_NAME","REFERENCED_COLUMN_NAME"
  110. FROM
  111. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE"
  112. WHERE
  113. "TABLE_NAME" IN ? AND
  114. "REFERENCED_TABLE_NAME" = ? AND
  115. "TABLE_CATALOG" = ? AND
  116. "REFERENCED_TABLE_CATALOG" = ?',
  117. 'reflect_habtm'=>'SELECT
  118. k1."TABLE_NAME", k1."COLUMN_NAME",
  119. k1."REFERENCED_TABLE_NAME", k1."REFERENCED_COLUMN_NAME",
  120. k2."TABLE_NAME", k2."COLUMN_NAME",
  121. k2."REFERENCED_TABLE_NAME", k2."REFERENCED_COLUMN_NAME"
  122. FROM
  123. "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k1, "INFORMATION_SCHEMA"."KEY_COLUMN_USAGE" k2
  124. WHERE
  125. k1."TABLE_CATALOG" = ? AND
  126. k2."TABLE_CATALOG" = ? AND
  127. k1."REFERENCED_TABLE_CATALOG" = ? AND
  128. k2."REFERENCED_TABLE_CATALOG" = ? AND
  129. k1."TABLE_NAME" = k2."TABLE_NAME" AND
  130. k1."REFERENCED_TABLE_NAME" = ? AND
  131. k2."REFERENCED_TABLE_NAME" IN ?'
  132. );
  133. protected function connectDatabase($hostname,$username,$password,$database,$port,$socket,$charset) {
  134. $connectionInfo = array();
  135. if ($port) $hostname.=','.$port;
  136. if ($username) $connectionInfo['UID']=$username;
  137. if ($password) $connectionInfo['PWD']=$password;
  138. if ($database) $connectionInfo['Database']=$database;
  139. if ($charset) $connectionInfo['CharacterSet']=$charset;
  140. $connectionInfo['QuotedId']=1;
  141. $db = sqlsrv_connect($hostname, $connectionInfo);
  142. if (!$db) {
  143. throw new \Exception('Connect failed. '.print_r( sqlsrv_errors(), true));
  144. }
  145. if ($socket) {
  146. throw new \Exception('Socket connection is not supported.');
  147. }
  148. return $db;
  149. }
  150. protected function query($db,$sql,$params) {
  151. $args = array();
  152. $sql = preg_replace_callback('/\!|\?/', function ($matches) use (&$db,&$params,&$args) {
  153. static $i=-1;
  154. $i++;
  155. $param = $params[$i];
  156. if ($matches[0]=='!') {
  157. return preg_replace('/[^a-zA-Z0-9\-_=<>]/','',$param);
  158. }
  159. if (is_array($param)) {
  160. $args = array_merge($args,$param);
  161. return '('.implode(',',str_split(str_repeat('?',count($param)))).')';
  162. }
  163. $args[] = $param;
  164. return '?';
  165. }, $sql);
  166. //echo "\n$sql\n";
  167. //var_dump($args);
  168. return sqlsrv_query($db,$sql,$args);
  169. }
  170. protected function fetch_assoc($result) {
  171. return sqlsrv_fetch_array($result, SQLSRV_FETCH_ASSOC);
  172. }
  173. protected function fetch_row($result) {
  174. return sqlsrv_fetch_array($result, SQLSRV_FETCH_NUMERIC);
  175. }
  176. protected function insert_id($db) {
  177. $result = sqlsrv_query($db, 'SELECT SCOPE_IDENTITY()');
  178. $data = sqlsrv_fetch_array($result, SQLSRV_FETCH_NUMERIC);
  179. return $data[0];
  180. }
  181. protected function affected_rows($db,$result) {
  182. return sqlsrv_rows_affected($result);
  183. }
  184. protected function close($result) {
  185. return sqlsrv_free_stmt($result);
  186. }
  187. protected function fetch_fields($result) {
  188. //var_dump(sqlsrv_field_metadata($result));
  189. return array_map(function($a){
  190. $p = array();
  191. foreach ($a as $k=>$v) {
  192. $p[strtolower($k)] = $v;
  193. }
  194. return (object)$p;
  195. },sqlsrv_field_metadata($result));
  196. }
  197. protected function add_limit_to_sql($sql,$limit,$offset) {
  198. return "$sql OFFSET $offset ROWS FETCH NEXT $limit ROWS ONLY";
  199. }
  200. protected function is_binary_type($field) {
  201. return ($field->type>=-4 && $field->type<=-2);
  202. }
  203. }
  204. class REST_CRUD_API {
  205. protected $config;
  206. protected function mapMethodToAction($method,$key) {
  207. switch ($method) {
  208. case 'GET': return $key?'read':'list';
  209. case 'PUT': return 'update';
  210. case 'POST': return 'create';
  211. case 'DELETE': return 'delete';
  212. default: $this->exitWith404('method');
  213. }
  214. }
  215. protected function parseRequestParameter(&$request,$characters,$default) {
  216. if (!count($request)) return $default;
  217. $value = array_shift($request);
  218. return $characters?preg_replace("/[^$characters]/",'',$value):$value;
  219. }
  220. protected function parseGetParameter($get,$name,$characters,$default) {
  221. $value = isset($get[$name])?$get[$name]:$default;
  222. return $characters?preg_replace("/[^$characters]/",'',$value):$value;
  223. }
  224. protected function parseGetParameterArray($get,$name,$characters,$default) {
  225. $values = isset($get[$name])?$get[$name]:$default;
  226. if (!is_array($values)) $values = array($values);
  227. if ($characters) {
  228. foreach ($values as &$value) {
  229. $value = preg_replace("/[^$characters]/",'',$value);
  230. }
  231. }
  232. return $values;
  233. }
  234. protected function applyPermissions($database, $tables, $action, $permissions, $multidb) {
  235. if (in_array(strtolower($database), array('information_schema','mysql','sys'))) return array();
  236. $results = array();
  237. $permissions = array_change_key_case($permissions,CASE_LOWER);
  238. foreach ($tables as $table) {
  239. $result = false;
  240. $options = $multidb?array("*.*","$database.*","$database.$table"):array("*","$table");
  241. $options = array_map('strtolower', $options);
  242. foreach ($options as $option) {
  243. if (isset($permissions[$option])) {
  244. $result = strpos($permissions[$option],$action[0])!==false;
  245. }
  246. }
  247. if ($result) $results[] = $table;
  248. }
  249. return $results;
  250. }
  251. protected function processTableParameter($database,$table,$db) {
  252. $tablelist = explode(',',$table);
  253. $tables = array();
  254. foreach ($tablelist as $table) {
  255. $table = str_replace('*','%',$table);
  256. if ($result = $this->query($db,$this->queries['reflect_table'],array($table,$database))) {
  257. while ($row = $this->fetch_row($result)) $tables[] = $row[0];
  258. $this->close($result);
  259. }
  260. }
  261. return $tables;
  262. }
  263. protected function findSinglePrimaryKey($table,$database,$db) {
  264. $keys = array();
  265. if ($result = $this->query($db,$this->queries['reflect_pk'],array($table[0],$database))) {
  266. while ($row = $this->fetch_row($result)) $keys[] = $row[0];
  267. $this->close($result);
  268. }
  269. return count($keys)==1?$keys[0]:false;
  270. }
  271. protected function exitWith404($type) {
  272. if (isset($_SERVER['REQUEST_METHOD'])) {
  273. header('Content-Type:',true,404);
  274. die("Not found ($type)");
  275. } else {
  276. throw new \Exception("Not found ($type)");
  277. }
  278. }
  279. protected function startOutput($callback) {
  280. if (isset($_SERVER['REQUEST_METHOD'])) {
  281. header('Access-Control-Allow-Origin: *');
  282. if ($callback) {
  283. header('Content-Type: application/javascript');
  284. echo $callback.'(';
  285. } else {
  286. header('Content-Type: application/json');
  287. }
  288. }
  289. }
  290. protected function endOutput($callback) {
  291. if ($callback) {
  292. echo ');';
  293. }
  294. }
  295. protected function processKeyParameter($key,$table,$database,$db) {
  296. if ($key) {
  297. $key = array($key,$this->findSinglePrimaryKey($table,$database,$db));
  298. if ($key[1]===false) $this->exitWith404('1pk');
  299. }
  300. return $key;
  301. }
  302. protected function processOrderParameter($order,$table,$database,$db) {
  303. if ($order) {
  304. $order = explode(',',$order,2);
  305. if (count($order)<2) $order[1]='ASC';
  306. $order[1] = strtoupper($order[1])=='DESC'?'DESC':'ASC';
  307. }
  308. return $order;
  309. }
  310. protected function processFilterParameter($filter,$db) {
  311. if ($filter) {
  312. $filter = explode(',',$filter,3);
  313. if (count($filter)==3) {
  314. $match = $filter[1];
  315. $filter[1] = 'LIKE';
  316. if ($match=='cs') $filter[2] = '%'.addcslashes($filter[2], '%_').'%';
  317. if ($match=='sw') $filter[2] = addcslashes($filter[2], '%_').'%';
  318. if ($match=='ew') $filter[2] = '%'.addcslashes($filter[2], '%_');
  319. if ($match=='eq') $filter[1] = '=';
  320. if ($match=='ne') $filter[1] = '<>';
  321. if ($match=='lt') $filter[1] = '<';
  322. if ($match=='le') $filter[1] = '<=';
  323. if ($match=='ge') $filter[1] = '>=';
  324. if ($match=='gt') $filter[1] = '>';
  325. if ($match=='in') {
  326. $filter[1] = 'IN';
  327. $filter[2] = explode(',',$filter[2]);
  328. }
  329. } else {
  330. $filter = false;
  331. }
  332. }
  333. return $filter;
  334. }
  335. protected function processPageParameter($page) {
  336. if ($page) {
  337. $page = explode(',',$page,2);
  338. if (count($page)<2) $page[1]=20;
  339. $page[0] = ($page[0]-1)*$page[1];
  340. }
  341. return $page;
  342. }
  343. protected function retrieveObject($key,$table,$db) {
  344. if (!$key) return false;
  345. if ($result = $this->query($db,'SELECT * FROM "!" WHERE "!" = ?',array($table[0],$key[1],$key[0]))) {
  346. $object = $this->fetch_assoc($result);
  347. $this->close($result);
  348. }
  349. return $object;
  350. }
  351. protected function createObject($input,$table,$db) {
  352. if (!$input) return false;
  353. $keys = implode('","',str_split(str_repeat('!', count($input))));
  354. $values = implode(',',str_split(str_repeat('?', count($input))));
  355. $params = array_merge(array_keys((array)$input),array_values((array)$input));
  356. array_unshift($params, $table[0]);
  357. $result = $this->query($db,'INSERT INTO "!" ("'.$keys.'") VALUES ('.$values.')',$params);
  358. return $this->insert_id($db,$result);
  359. }
  360. protected function updateObject($key,$input,$table,$db) {
  361. if (!$input) return false;
  362. $params = array();
  363. $sql = 'UPDATE "!" SET ';
  364. $params[] = $table[0];
  365. foreach (array_keys($input) as $i=>$k) {
  366. if ($i) $sql .= ',';
  367. $v = $input[$k];
  368. $sql .= '"!"=?';
  369. $params[] = $k;
  370. $params[] = $v;
  371. }
  372. $sql .= ' WHERE "!"=?';
  373. $params[] = $key[1];
  374. $params[] = $key[0];
  375. $result = $this->query($db,$sql,$params);
  376. return $this->affected_rows($db, $result);
  377. }
  378. protected function deleteObject($key,$table,$db) {
  379. $result = $this->query($db,'DELETE FROM "!" WHERE "!" = ?',array($table[0],$key[1],$key[0]));
  380. return $this->affected_rows($db, $result);
  381. }
  382. protected function findRelations($tables,$database,$db) {
  383. $collect = array();
  384. $select = array();
  385. if (count($tables)>1) {
  386. $table0 = array_shift($tables);
  387. $result = $this->query($db,$this->queries['reflect_belongs_to'],array($table0,$tables,$database,$database));
  388. while ($row = $this->fetch_row($result)) {
  389. $collect[$row[0]][$row[1]]=array();
  390. $select[$row[2]][$row[3]]=array($row[0],$row[1]);
  391. }
  392. $result = $this->query($db,$this->queries['reflect_has_many'],array($tables,$table0,$database,$database));
  393. while ($row = $this->fetch_row($result)) {
  394. $collect[$row[2]][$row[3]]=array();
  395. $select[$row[0]][$row[1]]=array($row[2],$row[3]);
  396. }
  397. $result = $this->query($db,$this->queries['reflect_habtm'],array($database,$database,$database,$database,$table0,$tables));
  398. while ($row = $this->fetch_row($result)) {
  399. $collect[$row[2]][$row[3]]=array();
  400. $select[$row[0]][$row[1]]=array($row[2],$row[3]);
  401. $collect[$row[4]][$row[5]]=array();
  402. $select[$row[6]][$row[7]]=array($row[4],$row[5]);
  403. }
  404. }
  405. return array($collect,$select);
  406. }
  407. protected function getParameters($config) {
  408. extract($config);
  409. $table = $this->parseRequestParameter($request, 'a-zA-Z0-9\-_*,', false);
  410. $key = $this->parseRequestParameter($request, 'a-zA-Z0-9\-,', false); // auto-increment or uuid
  411. $action = $this->mapMethodToAction($method,$key);
  412. $callback = $this->parseGetParameter($get, 'callback', 'a-zA-Z0-9\-_', false);
  413. $page = $this->parseGetParameter($get, 'page', '0-9,', false);
  414. $filters = $this->parseGetParameterArray($get, 'filter', false, false);
  415. $satisfy = $this->parseGetParameter($get, 'satisfy', 'a-z', 'all');
  416. $columns = $this->parseGetParameter($get, 'columns', 'a-zA-Z0-9\-_,', false);
  417. $order = $this->parseGetParameter($get, 'order', 'a-zA-Z0-9\-_*,', false);
  418. $transform = $this->parseGetParameter($get, 'transform', '1', false);
  419. $table = $this->processTableParameter($database,$table,$db);
  420. $key = $this->processKeyParameter($key,$table,$database,$db);
  421. foreach ($filters as &$filter) $filter = $this->processFilterParameter($filter,$db);
  422. if ($columns) $columns = explode(',',$columns);
  423. $page = $this->processPageParameter($page);
  424. $order = $this->processOrderParameter($order,$table,$database,$db);
  425. $table = $this->applyPermissions($database,$table,$action,$permissions,$multidb);
  426. if (empty($table)) $this->exitWith404('entity');
  427. $object = $this->retrieveObject($key,$table,$db);
  428. $input = json_decode(file_get_contents($post),true);
  429. list($collect,$select) = $this->findRelations($table,$database,$db);
  430. return compact('action','database','table','key','callback','page','filters','satisfy','columns','order','transform','db','object','input','collect','select');
  431. }
  432. protected function listCommand($parameters) {
  433. extract($parameters);
  434. $this->startOutput($callback);
  435. echo '{';
  436. $tables = $table;
  437. $table = array_shift($tables);
  438. // first table
  439. $count = false;
  440. echo '"'.$table.'":{';
  441. if (is_array($order) && is_array($page)) {
  442. $params = array();
  443. $sql = 'SELECT COUNT(*) FROM "!"';
  444. $params[] = $table;
  445. foreach ($filters as $i=>$filter) {
  446. if (is_array($filter)) {
  447. $sql .= $i==0?' WHERE ':($satisfy=='all'?' AND ':' OR ');
  448. $sql .= '"!" ! ?';
  449. $params[] = $filter[0];
  450. $params[] = $filter[1];
  451. $params[] = $filter[2];
  452. }
  453. }
  454. if ($result = $this->query($db,$sql,$params)) {
  455. while ($pages = $this->fetch_row($result)) {
  456. $count = $pages[0];
  457. }
  458. }
  459. }
  460. $params = array();
  461. $sql = 'SELECT ';
  462. if (is_array($columns)) {
  463. $sql .= '"'.implode('","',$columns).'"';
  464. } else {
  465. $sql .= '*';
  466. }
  467. $sql .= ' FROM "!"';
  468. $params[] = $table;
  469. foreach ($filters as $i=>$filter) {
  470. if (is_array($filter)) {
  471. $sql .= $i==0?' WHERE ':($satisfy=='all'?' AND ':' OR ');
  472. $sql .= '"!" ! ?';
  473. $params[] = $filter[0];
  474. $params[] = $filter[1];
  475. $params[] = $filter[2];
  476. }
  477. }
  478. if (is_array($order)) {
  479. $sql .= ' ORDER BY "!" !';
  480. $params[] = $order[0];
  481. $params[] = $order[1];
  482. }
  483. if (is_array($order) && is_array($page)) {
  484. $sql = $this->add_limit_to_sql($sql,$page[1],$page[0]);
  485. }
  486. if ($result = $this->query($db,$sql,$params)) {
  487. echo '"columns":';
  488. $fields = array();
  489. $base64 = array();
  490. foreach ($this->fetch_fields($result) as $field) {
  491. $base64[] = $this->is_binary_type($field);
  492. $fields[] = $field->name;
  493. }
  494. echo json_encode($fields);
  495. $fields = array_flip($fields);
  496. echo ',"records":[';
  497. $first_row = true;
  498. while ($row = $this->fetch_row($result)) {
  499. if ($first_row) $first_row = false;
  500. else echo ',';
  501. if (isset($collect[$table])) {
  502. foreach (array_keys($collect[$table]) as $field) {
  503. $collect[$table][$field][] = $row[$fields[$field]];
  504. }
  505. }
  506. foreach ($base64 as $k=>$v) {
  507. if ($v) {
  508. $row[$k] = base64_encode($row[$k]);
  509. }
  510. }
  511. echo json_encode($row);
  512. }
  513. $this->close($result);
  514. echo ']';
  515. if ($count) echo ',';
  516. }
  517. if ($count) echo '"results":'.$count;
  518. echo '}';
  519. // prepare for other tables
  520. foreach (array_keys($collect) as $t) {
  521. if ($t!=$table && !in_array($t,$tables)) {
  522. array_unshift($tables,$t);
  523. }
  524. }
  525. // other tables
  526. foreach ($tables as $t=>$table) {
  527. echo ',';
  528. echo '"'.$table.'":{';
  529. $params = array();
  530. $sql = 'SELECT * FROM "!"';
  531. $params[] = $table;
  532. if (isset($select[$table])) {
  533. $first_row = true;
  534. echo '"relations":{';
  535. foreach ($select[$table] as $field => $path) {
  536. $values = $collect[$path[0]][$path[1]];
  537. $sql .= $first_row?' WHERE ':' OR ';
  538. $sql .= '"!" IN ?';
  539. $params[] = $field;
  540. $params[] = $values;
  541. if ($first_row) $first_row = false;
  542. else echo ',';
  543. echo '"'.$field.'":"'.implode('.',$path).'"';
  544. }
  545. echo '}';
  546. }
  547. if ($result = $this->query($db,$sql,$params)) {
  548. echo ',"columns":';
  549. $fields = array();
  550. $base64 = array();
  551. foreach ($this->fetch_fields($result) as $field) {
  552. $base64[] = $this->is_binary_type($field);
  553. $fields[] = $field->name;
  554. }
  555. echo json_encode($fields);
  556. $fields = array_flip($fields);
  557. echo ',"records":[';
  558. $first_row = true;
  559. while ($row = $this->fetch_row($result)) {
  560. if ($first_row) $first_row = false;
  561. else echo ',';
  562. if (isset($collect[$table])) {
  563. foreach (array_keys($collect[$table]) as $field) {
  564. $collect[$table][$field][]=$row[$fields[$field]];
  565. }
  566. }
  567. foreach ($base64 as $k=>$v) {
  568. if ($v) {
  569. $row[$k] = base64_encode($row[$k]);
  570. }
  571. }
  572. echo json_encode($row);
  573. }
  574. $this->close($result);
  575. echo ']';
  576. }
  577. echo '}';
  578. }
  579. echo '}';
  580. $this->endOutput($callback);
  581. }
  582. protected function readCommand($parameters) {
  583. extract($parameters);
  584. if (!$object) $this->exitWith404('object');
  585. $this->startOutput($callback);
  586. echo json_encode($object);
  587. $this->endOutput($callback);
  588. }
  589. protected function createCommand($parameters) {
  590. extract($parameters);
  591. if (!$input) $this->exitWith404('input');
  592. $this->startOutput($callback);
  593. echo json_encode($this->createObject($input,$table,$db));
  594. $this->endOutput($callback);
  595. }
  596. protected function updateCommand($parameters) {
  597. extract($parameters);
  598. if (!$input) $this->exitWith404('subject');
  599. $this->startOutput($callback);
  600. echo json_encode($this->updateObject($key,$input,$table,$db));
  601. $this->endOutput($callback);
  602. }
  603. protected function deleteCommand($parameters) {
  604. extract($parameters);
  605. $this->startOutput($callback);
  606. echo json_encode($this->deleteObject($key,$table,$db));
  607. $this->endOutput($callback);
  608. }
  609. protected function listCommandTransform($parameters) {
  610. if ($parameters['transform']) {
  611. ob_start();
  612. }
  613. $this->listCommand($parameters);
  614. if ($parameters['transform']) {
  615. $content = ob_get_contents();
  616. ob_end_clean();
  617. $data = json_decode($content,true);
  618. echo json_encode(self::mysql_crud_api_transform($data));
  619. }
  620. }
  621. public function __construct($config) {
  622. extract($config);
  623. $hostname = isset($hostname)?$hostname:null;
  624. $username = isset($username)?$username:'root';
  625. $password = isset($password)?$password:null;
  626. $database = isset($database)?$database:false;
  627. $port = isset($port)?$port:null;
  628. $socket = isset($socket)?$socket:null;
  629. $charset = isset($charset)?$charset:'utf8';
  630. $permissions = isset($permissions)?$permissions:array('*'=>'crudl');
  631. $db = isset($db)?$db:null;
  632. $method = isset($method)?$method:$_SERVER['REQUEST_METHOD'];
  633. $request = isset($request)?$request:(isset($_SERVER['PATH_INFO'])?$_SERVER['PATH_INFO']:'');
  634. $get = isset($get)?$get:$_GET;
  635. $post = isset($post)?$post:'php://input';
  636. $request = explode('/', trim($request,'/'));
  637. $multidb = !$database;
  638. if ($multidb) {
  639. $database = $this->parseRequestParameter($request, 'a-zA-Z0-9\-_,', false);
  640. }
  641. if (!$db) {
  642. $db = $this->connectDatabase($hostname,$username,$password,$database,$port,$socket,$charset);
  643. }
  644. $this->config = compact('method', 'request', 'get', 'post', 'multidb', 'database', 'permissions', 'db');
  645. }
  646. public static function mysql_crud_api_transform(&$tables) {
  647. $get_objects = function (&$tables,$table_name,$where_index=false,$match_value=false) use (&$get_objects) {
  648. $objects = array();
  649. foreach ($tables[$table_name]['records'] as $record) {
  650. if ($where_index===false || $record[$where_index]==$match_value) {
  651. $object = array();
  652. foreach ($tables[$table_name]['columns'] as $index=>$column) {
  653. $object[$column] = $record[$index];
  654. foreach ($tables as $relation=>$reltable) {
  655. if (isset($reltable['relations'])) {
  656. foreach ($reltable['relations'] as $key=>$target) {
  657. if ($target == "$table_name.$column") {
  658. $column_indices = array_flip($reltable['columns']);
  659. $object[$relation] = $get_objects($tables,$relation,$column_indices[$key],$record[$index]);
  660. }
  661. }
  662. }
  663. }
  664. }
  665. $objects[] = $object;
  666. }
  667. }
  668. return $objects;
  669. };
  670. $tree = array();
  671. foreach ($tables as $name=>$table) {
  672. if (!isset($table['relations'])) {
  673. $tree[$name] = $get_objects($tables,$name);
  674. if (isset($table['results'])) {
  675. $tree['_results'] = $table['results'];
  676. }
  677. }
  678. }
  679. return $tree;
  680. }
  681. public function executeCommand() {
  682. $parameters = $this->getParameters($this->config);
  683. switch($parameters['action']){
  684. case 'list': $this->listCommandTransform($parameters); break;
  685. case 'read': $this->readCommand($parameters); break;
  686. case 'create': $this->createCommand($parameters); break;
  687. case 'update': $this->updateCommand($parameters); break;
  688. case 'delete': $this->deleteCommand($parameters); break;
  689. }
  690. }
  691. }
  692. // only execute this when running in stand-alone mode
  693. if(count(get_required_files())<2) {
  694. header('Access-Control-Allow-Origin: *');
  695. $api = new SQLSRV_CRUD_API(array(
  696. 'hostname'=>'(local)',
  697. 'username'=>'',
  698. 'password'=>'',
  699. 'database'=>'xxx',
  700. 'charset'=>'UTF-8'
  701. ));
  702. $api->executeCommand();
  703. }