]> git.wh0rd.org - tt-rss.git/blobdiff - include/controls.php
force-cast some variables used in queries to integer
[tt-rss.git] / include / controls.php
index 0129db50115a1913483faaf54a8e41fd8c29e02b..931ccdd52ed690fd6c311e1206e994ebe75dbe13 100644 (file)
@@ -72,7 +72,9 @@ function print_radio($id, $default, $true_is, $values, $attributes = "") {
 
 function print_feed_multi_select($id, $default_ids = [],
                            $attributes = "", $include_all_feeds = true,
-                           $root_id = false, $nest_level = 0) {
+                           $root_id = null, $nest_level = 0) {
+
+    $pdo = DB::pdo();
 
     print_r(in_array("CAT:6",$default_ids));
 
@@ -86,18 +88,18 @@ function print_feed_multi_select($id, $default_ids = [],
 
     if (get_pref('ENABLE_FEED_CATS')) {
 
-        if ($root_id)
-            $parent_qpart = "parent_cat = '$root_id'";
-        else
-            $parent_qpart = "parent_cat IS NULL";
+        if (!$root_id) $root_id = null;
 
-        $result = db_query("SELECT id,title,
+        $sth = $pdo->prepare("SELECT id,title,
                                (SELECT COUNT(id) FROM ttrss_feed_categories AS c2 WHERE
                                        c2.parent_cat = ttrss_feed_categories.id) AS num_children
                                FROM ttrss_feed_categories
-                               WHERE owner_uid = ".$_SESSION["uid"]." AND $parent_qpart ORDER BY title");
+                               WHERE owner_uid = :uid AND 
+                               (parent_cat = :root_id OR (:root_id IS NULL AND parent_cat IS NULL)) ORDER BY title");
+
+        $sth->execute([":uid" => $_SESSION['uid'], ":root_id" => $root_id]);
 
-        while ($line = db_fetch_assoc($result)) {
+        while ($line = $sth->fetch()) {
 
             for ($i = 0; $i < $nest_level; $i++)
                 $line["title"] = " - " . $line["title"];
@@ -111,10 +113,12 @@ function print_feed_multi_select($id, $default_ids = [],
                 print_feed_multi_select($id, $default_ids, $attributes,
                     $include_all_feeds, $line["id"], $nest_level+1);
 
-            $feed_result = db_query("SELECT id,title FROM ttrss_feeds
-                                       WHERE cat_id = '".$line["id"]."' AND owner_uid = ".$_SESSION["uid"] . " ORDER BY title");
+            $f_sth = $pdo->prepare("SELECT id,title FROM ttrss_feeds
+                                       WHERE cat_id = ? AND owner_uid = ? ORDER BY title");
 
-            while ($fline = db_fetch_assoc($feed_result)) {
+            $f_sth->execute([$line['id'], $_SESSION['uid']]);
+
+            while ($fline = $f_sth->fetch()) {
                 $is_selected = (in_array($fline["id"], $default_ids)) ? "selected=\"1\"" : "";
 
                 $fline["title"] = " + " . $fline["title"];
@@ -133,10 +137,11 @@ function print_feed_multi_select($id, $default_ids = [],
             printf("<option $is_selected value='CAT:0'>%s</option>",
                 __("Uncategorized"));
 
-            $feed_result = db_query("SELECT id,title FROM ttrss_feeds
-                                       WHERE cat_id IS NULL AND owner_uid = ".$_SESSION["uid"] . " ORDER BY title");
+            $f_sth = $pdo->prepare("SELECT id,title FROM ttrss_feeds
+                                       WHERE cat_id IS NULL AND owner_uid = ? ORDER BY title");
+            $f_sth->execute([$_SESSION['uid']]);
 
-            while ($fline = db_fetch_assoc($feed_result)) {
+            while ($fline = $f_sth->fetch()) {
                 $is_selected = in_array($fline["id"], $default_ids) ? "selected=\"1\"" : "";
 
                 $fline["title"] = " + " . $fline["title"];
@@ -150,10 +155,11 @@ function print_feed_multi_select($id, $default_ids = [],
         }
 
     } else {
-        $result = db_query("SELECT id,title FROM ttrss_feeds
-                               WHERE owner_uid = ".$_SESSION["uid"]." ORDER BY title");
+        $sth = $pdo->prepare("SELECT id,title FROM ttrss_feeds
+                               WHERE owner_uid = ? ORDER BY title");
+        $sth->execute([$_SESSION['uid']]);
 
-        while ($line = db_fetch_assoc($result)) {
+        while ($line = $sth->fetch()) {
 
             $is_selected = (in_array($line["id"], $default_ids)) ? "selected=\"1\"" : "";
 
@@ -167,122 +173,30 @@ function print_feed_multi_select($id, $default_ids = [],
     }
 }
 
-
-function print_feed_select($id, $default_id = "",
-                                                  $attributes = "", $include_all_feeds = true,
-                                                  $root_id = false, $nest_level = 0) {
+function print_feed_cat_select($id, $default_id,
+                                                          $attributes, $include_all_cats = true, $root_id = null, $nest_level = 0) {
 
        if (!$root_id) {
-               print "<select id=\"$id\" name=\"$id\" $attributes>";
-               if ($include_all_feeds) {
-                       $is_selected = ("0" == $default_id) ? "selected=\"1\"" : "";
-                       print "<option $is_selected value=\"0\">".__('All feeds')."</option>";
-               }
+               print "<select id=\"$id\" name=\"$id\" default=\"$default_id\" $attributes>";
        }
 
-       if (get_pref('ENABLE_FEED_CATS')) {
+       $pdo = DB::pdo();
 
-               if ($root_id)
-                       $parent_qpart = "parent_cat = '$root_id'";
-               else
-                       $parent_qpart = "parent_cat IS NULL";
+       if (!$root_id) $root_id = null;
 
-               $result = db_query("SELECT id,title,
+       $sth = $pdo->prepare("SELECT id,title,
                                (SELECT COUNT(id) FROM ttrss_feed_categories AS c2 WHERE
                                        c2.parent_cat = ttrss_feed_categories.id) AS num_children
                                FROM ttrss_feed_categories
-                               WHERE owner_uid = ".$_SESSION["uid"]." AND $parent_qpart ORDER BY title");
-
-               while ($line = db_fetch_assoc($result)) {
-
-                       for ($i = 0; $i < $nest_level; $i++)
-                               $line["title"] = " - " . $line["title"];
-
-                       $is_selected = ("CAT:".$line["id"] == $default_id) ? "selected=\"1\"" : "";
-
-                       printf("<option $is_selected value='CAT:%d'>%s</option>",
-                               $line["id"], htmlspecialchars($line["title"]));
-
-                       if ($line["num_children"] > 0)
-                               print_feed_select($id, $default_id, $attributes,
-                                       $include_all_feeds, $line["id"], $nest_level+1);
+                               WHERE owner_uid = :uid AND 
+                                 (parent_cat = :root_id OR (:root_id IS NULL AND parent_cat IS NULL)) ORDER BY title");
+       $sth->execute([":uid" => $_SESSION['uid'], ":root_id" => $root_id]);
 
-                       $feed_result = db_query("SELECT id,title FROM ttrss_feeds
-                                       WHERE cat_id = '".$line["id"]."' AND owner_uid = ".$_SESSION["uid"] . " ORDER BY title");
+       $found = 0;
 
-                       while ($fline = db_fetch_assoc($feed_result)) {
-                               $is_selected = ($fline["id"] == $default_id) ? "selected=\"1\"" : "";
-
-                               $fline["title"] = " + " . $fline["title"];
-
-                               for ($i = 0; $i < $nest_level; $i++)
-                                       $fline["title"] = " - " . $fline["title"];
-
-                               printf("<option $is_selected value='%d'>%s</option>",
-                                       $fline["id"], htmlspecialchars($fline["title"]));
-                       }
-               }
-
-               if (!$root_id) {
-                       $default_is_cat = ($default_id == "CAT:0");
-                       $is_selected = $default_is_cat ? "selected=\"1\"" : "";
-
-                       printf("<option $is_selected value='CAT:0'>%s</option>",
-                               __("Uncategorized"));
-
-                       $feed_result = db_query("SELECT id,title FROM ttrss_feeds
-                                       WHERE cat_id IS NULL AND owner_uid = ".$_SESSION["uid"] . " ORDER BY title");
-
-                       while ($fline = db_fetch_assoc($feed_result)) {
-                               $is_selected = ($fline["id"] == $default_id && !$default_is_cat) ? "selected=\"1\"" : "";
-
-                               $fline["title"] = " + " . $fline["title"];
-
-                               for ($i = 0; $i < $nest_level; $i++)
-                                       $fline["title"] = " - " . $fline["title"];
-
-                               printf("<option $is_selected value='%d'>%s</option>",
-                                       $fline["id"], htmlspecialchars($fline["title"]));
-                       }
-               }
+       while ($line = $sth->fetch()) {
+        ++$found;
 
-       } else {
-               $result = db_query("SELECT id,title FROM ttrss_feeds
-                               WHERE owner_uid = ".$_SESSION["uid"]." ORDER BY title");
-
-               while ($line = db_fetch_assoc($result)) {
-
-                       $is_selected = ($line["id"] == $default_id) ? "selected=\"1\"" : "";
-
-                       printf("<option $is_selected value='%d'>%s</option>",
-                               $line["id"], htmlspecialchars($line["title"]));
-               }
-       }
-
-       if (!$root_id) {
-               print "</select>";
-       }
-}
-
-function print_feed_cat_select($id, $default_id,
-                                                          $attributes, $include_all_cats = true, $root_id = false, $nest_level = 0) {
-
-       if (!$root_id) {
-               print "<select id=\"$id\" name=\"$id\" default=\"$default_id\" $attributes>";
-       }
-
-       if ($root_id)
-               $parent_qpart = "parent_cat = '$root_id'";
-       else
-               $parent_qpart = "parent_cat IS NULL";
-
-       $result = db_query("SELECT id,title,
-                               (SELECT COUNT(id) FROM ttrss_feed_categories AS c2 WHERE
-                                       c2.parent_cat = ttrss_feed_categories.id) AS num_children
-                               FROM ttrss_feed_categories
-                               WHERE owner_uid = ".$_SESSION["uid"]." AND $parent_qpart ORDER BY title");
-
-       while ($line = db_fetch_assoc($result)) {
                if ($line["id"] == $default_id) {
                        $is_selected = "selected=\"1\"";
                } else {
@@ -303,7 +217,7 @@ function print_feed_cat_select($id, $default_id,
 
        if (!$root_id) {
                if ($include_all_cats) {
-                       if (db_num_rows($result) > 0) {
+                       if ($found > 0) {
                                print "<option disabled=\"1\">--------</option>";
                        }
 
@@ -401,13 +315,16 @@ function format_inline_player($url, $ctype) {
 
 function print_label_select($name, $value, $attributes = "") {
 
-       $result = db_query("SELECT caption FROM ttrss_labels2
-                       WHERE owner_uid = '".$_SESSION["uid"]."' ORDER BY caption");
+    $pdo = Db::pdo();
+
+       $sth = $pdo->prepare("SELECT caption FROM ttrss_labels2
+                       WHERE owner_uid = ? ORDER BY caption");
+       $sth->execute([$_SESSION['uid']]);
 
        print "<select default=\"$value\" name=\"" . htmlspecialchars($name) .
                "\" $attributes>";
 
-       while ($line = db_fetch_assoc($result)) {
+       while ($line = $sth->fetch()) {
 
                $issel = ($line["caption"] == $value) ? "selected=\"1\"" : "";
 
@@ -421,5 +338,4 @@ function print_label_select($name, $value, $attributes = "") {
        print "</select>";
 
 
-}
-
+}
\ No newline at end of file