class salva { public $debug; public $errore; public $nome_tabella; public $codice_operatore; public $operazione; public $oggetto; public $return; public $duplicateKey; public $expect; public $ignore; public $ignore_versione = false; // public $disablePostSave; private $db; private $codice; private $versione = false; /** * Stabilisco la connesione al database * quando istanzio la classe */ function __construct($db_instance="") { if (empty($db_instance)) { global $pdo; $db_instance = $pdo; } $this->db = $db_instance; $this->debug = false; $this->expect = array(); $this->ignore = array(); $this->disablePostSave = false; } /** * Chiudo la connessione al database * quando la classe finisce tutte le operazioni */ function __destruct() { $this->db = null; } /** * Metodo init() * @return Se presente un errore ritorna un messaggio */ private function init() { $error = false; $message = ''; $this->db->debug = $this->debug; $notCodicePrimaryTables = []; $notCodicePrimaryTables[] = "b_check_sessions"; $notCodicePrimaryTables[] = "r_cpv_albi_commissione"; $notCodicePrimaryTables[] = "r_cpv_bandi_albo"; $notCodicePrimaryTables[] = "r_cpv_bandi_dialogo"; $notCodicePrimaryTables[] = "r_cpv_bandi_mercato"; $notCodicePrimaryTables[] = "r_cpv_bandi_sda"; $notCodicePrimaryTables[] = "r_cpv_concorsi"; $notCodicePrimaryTables[] = "r_cpv_fabbisogno"; $notCodicePrimaryTables[] = "r_cpv_gare"; $notCodicePrimaryTables[] = "r_hub_cpv"; $notCodicePrimaryTables[] = "r_cpv_operatori"; $notCodicePrimaryTables[] = "r_cpv_operatori_me"; $notCodicePrimaryTables[] = "r_cpv_operatori_sda"; $notCodicePrimaryTables[] = "r_cpv_progetti"; $notCodicePrimaryTables[] = "b_cpv"; if (!empty($this->expect) && !empty($this->ignore)) { $error = true; $message .= "Errore di Inizializzazione. Impossibile definire EXPECT e IGNORE contemporaneamente" . "
" . PHP_EOL; } if (!empty($this->expect)) { $this->expect[] = "utente_modifica"; } if (is_null($this->codice_operatore)) { $this->codice_operatore = isset($_SESSION["utente"]->codice) ? $_SESSION["utente"]->codice : -1; } if (is_null($this->nome_tabella) || $this->nome_tabella == "") { $error = true; $message .= "Errore di Inizializzazione. Tabella non definita" . "" . PHP_EOL; } if (!in_array($this->operazione, array("UPDATE","INSERT","REPLACE"))) { $error = true; $message .= "Errore di Inizializzazione. Operazione non riconosciuta" . "" . PHP_EOL; } if ($this->operazione == "UPDATE" && ( !isset($this->oggetto["codice"]) || $this->oggetto["codice"] == 0 || $this->oggetto["codice"] == "" ) ) { $error = true; $message .= "Errore di Inizializzazione. Codice non valido" . "" . PHP_EOL; } if (!is_array($this->oggetto)) { $error = true; $message .= "Errore di Inizializzazione. Oggetto non valido" . "" . PHP_EOL; } if ($this->operazione == "INSERT" && isset($this->oggetto["codice"])) { if (in_array($this->nome_tabella,$notCodicePrimaryTables) === false) { unset($this->oggetto["codice"]); } } else if ($this->operazione == "UPDATE") { $this->codice = $this->oggetto["codice"]; } if ($this->debug) { var_dump($this->oggetto); } if ($error && $message != "") { if ($this->debug) { echo $message; return false; } else { return false; } } return true; } private function purify($text) { $config = HTMLPurifier_Config::createDefault(); $config->set('Core.Encoding', 'UTF-8'); // replace with your encoding $config->set('Core.EscapeNonASCIICharacters', true); $config->set('CSS.Trusted', true); // allow any css $config->set('CSS.Proprietary', true); // allow any css $config->set('AutoFormat.RemoveEmpty', true); $config->set('CSS.AllowedProperties', ['width', 'color', 'background-color', 'margin-left', 'margin-right', 'text-align']); $config->set('HTML.AllowedElements', ['table','tbody','thead','tr','th','td','div', 'span', 'p', 's', 'br', 'a', 'h1', 'h2', 'h3', 'h4', 'h5', 'strong', 'em', 'u', 'ul', 'li', 'ol', 'hr', 'blockquote', 'sub', 'sup', 'img','figure']); $config->set('HTML.AllowedAttributes', '*.style,*.title,*.href,*.src,*.border,*.alt,*.width,*.height,*.title,*.class,*.colspan,*.rowspan'); $config->set('HTML.DefinitionID', 'enduser-customize.html tutorial'); $config->set('HTML.DefinitionRev', 1); if ($def = $config->maybeGetRawHTMLDefinition()) { $def->addElement('figure', 'Block', 'Optional: (figcaption, Flow) | (Flow, figcaption) | Flow', 'Common'); } if ($css = $config->getCSSDefinition()) { $css->info["width"] = new HTMLPurifier_AttrDef_CSS_Percentage(); } // $config->set('Core', 'Encoding', 'ISO-8859-1'); // replace with your encoding // $config->set('HTML', 'Doctype', 'HTML 4.01 Transitional'); // replace with your doctype $purifier = new HTMLPurifier($config); return $purifier->purify($text); } private function setPost() { $data = array(); $this->oggetto["utente_modifica"] = $this->codice_operatore; $sql_field = "SHOW FIELDS FROM `$this->nome_tabella` WHERE `Field` = :field_name"; $sth_field = $this->db->prepare($sql_field); $check_versione = true; $intTypes = array("integer", "int", "smallint", "tinyint", "mediumint", "bigint"); $decTypes = array("decimal", "numeric", "float", "double"); foreach ($this->oggetto as $field => $value) { $continue = true; if (!empty($this->expect) && is_array($this->expect)) { $continue = false; if (in_array($field,$this->expect)!==false) { $continue = true; } } if (!empty($this->ignore) && is_array($this->ignore)) { $continue = false; if (in_array($field,$this->ignore)===false) { $continue = true; } } if ($continue) { try { $sth_field->execute(array(":field_name" => $field)); $rec_field = $sth_field->fetch(PDO::FETCH_ASSOC); if (is_array($rec_field)) { if ($field == "versione") { $check_versione = false; } if (strpos($rec_field["Type"],"(")!==false) { $rec_field["Type"] = explode("(", $rec_field["Type"]); $rec_field["Type"] = $rec_field["Type"][0]; } switch ($rec_field["Type"]) { case 'date': if (!empty($value)) { $data[$field] = date2mysql($value); } else { $data[$field] = NULL; } break; case 'datetime': if (!empty($value)) { $data[$field] = dateTime2mysql($value); } else { $data[$field] = NULL; } break; case 'time': if (!empty($value)) { $data[$field] = $value; } else { $data[$field] = NULL; } break; default: if (stripos($rec_field["Type"],"BLOB")!==FALSE) { $data[$field] = $value; } else { if (stripos($rec_field["Type"],"TEXT")===FALSE) { if($value !== null) { if (in_array($rec_field["Type"],$intTypes)!==FALSE) { if (!is_numeric($value) || strpos($value,".")!==false) { $value = 0; } if (empty($value) ) { $value = 0; } } else if (in_array($rec_field["Type"],$decTypes)!==FALSE) { if (!is_numeric($value)) { $value = 0; } if (empty($value) ) { $value = 0; } } $value = $this->purify($value); $value = html_entity_decode($value, ENT_QUOTES, 'UTF-8'); $data[$field] = htmlspecialchars($value, ENT_QUOTES, 'UTF-8'); } else { $data[$field] = $value; } } else { $data[$field] = $this->purify($value); } } break; } } } catch (PDOException $error) { if ($this->debug) { echo str_replace(":field_name", $field, $sql_field); exit("PDOEXCEPTION: UNABLE TO FIND FIELDS IN TABLE $this->nome_tabella" . "" . PHP_EOL . $error->getMessage()); } else { exit(); } } } } if ($check_versione) { $sql_field = "SHOW FIELDS FROM `$this->nome_tabella` WHERE `Field` = :field_name"; $sth_field = $this->db->prepare($sql_field); $sth_field->execute(array(":field_name" => "versione")); $rec_field = $sth_field->fetch(PDO::FETCH_ASSOC); if (is_array($rec_field)) { $this->versione = !$this->ignore_versione; } } return $data; } public function prepareQuery($data) { $prepared_query = ""; if (!empty($data)) { if ($this->operazione == "INSERT" || $this->operazione == "REPLACE") { $prepared_query = $this->operazione . " INTO " . $this->nome_tabella . " (`".implode('`, `',array_keys($data)).'`) VALUES (:'.implode(', :',array_keys($data)).')'; if($this->duplicateKey) { $prepared_query .= " ON DUPLICATE KEY UPDATE timestamp = NOW() "; } } else if ($this->operazione == "UPDATE") { $update_stmt = ""; unset($data["codice"], $data[":codice"]); foreach ($data as $key => $value) { $update_stmt .= '`'.$key.'`' . ' = :' . $key . ', '; } $prepared_query = "UPDATE " . $this->nome_tabella . " SET " . substr($update_stmt,0,-2); if ($this->versione) { $prepared_query.= " ,`versione` = `versione` + 1"; } $prepared_query.= " WHERE codice = :codice"; } if ($prepared_query != "") { if ($this->debug) { echo "PREPAREDQUERY: " . $prepared_query . "
" . PHP_EOL; } return $prepared_query; } else { if ($this->debug) { echo "ERRORE DI CREAZIONE SQL QUERY" . "
" . PHP_EOL; } $this->errore = "SQL ERROR"; $this->return = false; } } else { if ($this->debug) { echo "OGGETTO VUOTO" . "
" . PHP_EOL; } $this->errore = "DATA ERROR"; $this->return = false; } } public function save() { if ($this->init()) { $this->return = false; $data = $this->setPost(); $prepared_query = $this->prepareQuery($data); $result = $this->db->go($prepared_query, $data); if ($result) { $strsql = $this->db->getSQL(); if($this->debug) { echo "QUERY: " . $strsql . "
" . PHP_EOL; } if ($this->operazione == "INSERT" || $this->operazione == "REPLACE") { $this->codice = $this->db->lastInsertId(); } scriviLog($this->nome_tabella,$this->operazione,$strsql,$this->codice); $this->return = $this->codice; if($this->operazione == "UPDATE" && $result->errorInfo()[0] !== "00000") { $this->errore = "SQL UPDATE ERROR {$result->errorInfo()[0]}".PHP_EOL; $this->return = false; } } else { $this->errore = "SQL STATEMENT ERROR".PHP_EOL; $this->return = false; } if ($this->debug) { echo $this->errore; } $this->postSave(); return $this->return; } } public function postSave() { if (isset($_SESSION["ente"]) && empty($this->disablePostSave)) { $postSaveClass = $_SESSION["ente"]->getExtensionPath() . DIRECTORY_SEPARATOR . "postSave.class.php"; if (file_exists($postSaveClass)) { require_once $postSaveClass; $postSave = new postSave($this); $postSave->execute(); } } } } ?>